Skip to content
Tech News
← Back to articles

CISA shares advice on isolating vital systems during cyberattacks

read original more articles
Why This Matters

This guidance underscores the importance of isolating critical operational technology systems during cyberattacks to prevent widespread disruption and protect essential services. As cyber threats from state-sponsored actors and cybercriminals continue to target critical infrastructure, such proactive measures are vital for safeguarding public safety and national security. Implementing these strategies can help organizations mitigate damage and maintain operational resilience during crises.

Key Takeaways

The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.

The guidance, titled "CI Fortify – Advice for isolating vital systems," was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners.

It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period.

Operational technology includes the hardware and software used to monitor or control processes, such as water treatment equipment, electrical systems, manufacturing machinery, transportation systems, and telecommunications infrastructure.

The agencies say state-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict.

"Cybercriminals continue to opportunistically target CI operators," reads the advisory.

"The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes."

In February 2024, CISA, the FBI, NSA, and other Five Eyes agencies warned that the Chinese Volt Typhoon hacking group had breached organizations in the communications, energy, transportation, and water sectors.

The hackers remained undetected in at least one critical infrastructure network for five years, with U.S. officials warning that they were positioning themselves for potentially disruptive attacks during a future crisis or conflict.

Chinese state-sponsored hackers tracked as Salt Typhoon have also breached government, telecommunications, transportation, lodging, and military networks worldwide since at least 2021.

... continue reading