The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
The guidance, titled "CI Fortify – Advice for isolating vital systems," was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners.
It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period.
Operational technology includes the hardware and software used to monitor or control processes, such as water treatment equipment, electrical systems, manufacturing machinery, transportation systems, and telecommunications infrastructure.
The agencies say state-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict.
"Cybercriminals continue to opportunistically target CI operators," reads the advisory.
"The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes."
In February 2024, CISA, the FBI, NSA, and other Five Eyes agencies warned that the Chinese Volt Typhoon hacking group had breached organizations in the communications, energy, transportation, and water sectors.
The hackers remained undetected in at least one critical infrastructure network for five years, with U.S. officials warning that they were positioning themselves for potentially disruptive attacks during a future crisis or conflict.
Chinese state-sponsored hackers tracked as Salt Typhoon have also breached government, telecommunications, transportation, lodging, and military networks worldwide since at least 2021.
... continue reading