CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators
CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation (TL-2026-1932), also tracked as CI Fortify – Advice for Isolating Vital Systems, is a info-severity ICS/SCADA threat, first published 2026-08-07. It has no confirmed attribution, affects N/A — cross-sector guidance OT and OT-enabling systems across critical, maps to 13 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-1932
- Threat ID
- TL-2026-1932
- Also known as
- CI Fortify – Advice for Isolating Vital Systems
- Severity
- INFO
- Status
- ACTIVE
- Category
- ICS_SCADA
- First published
- 2026-08-07
- Last reviewed
- 2026-08-07
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- energy, water and wastewater, transport, manufacturing, telecoms, government administration
- Target regions
- united states of america, australia, united kingdom, canada
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation
Malware and tooling: BlackBerry AtHoc, BlackBerry SecuSUITE, BlackBerry UEM, Mimikatz, certutil - S0160, ntdsutil
CISA, Australia's ASD (ACSC), the UK's NCSC, and Canada's CCCS jointly published 'CI Fortify – Advice for Isolating Vital Systems' on July 28, 2026, directing critical infrastructure operators to build tested capability to disconnect vital OT and OT-enabling systems (HMIs, PLCs, SCADA, engineering workstations) from IT/enterprise and external networks during a cyber incident. BlackBerry's August 4, 2026 analysis argues the guidance leaves a coordination gap: isolation plans without a paired, out-of-band communications-continuity plan only delay disruption rather than prevent it.
How CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation works
On July 28, 2026, CISA, the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), the UK National Cyber Security Centre (NCSC-UK), and the Canadian Centre for Cyber Security (CCCS) jointly published 'CI Fortify – Advice for Isolating Vital Systems.' The FBI/IC3 issued a corresponding Cybersecurity Advisory (CSA #260728) the same day. The guidance directs operators of critical infrastructure — energy, water and wastewater, transportation, manufacturing, and telecommunications — to pre-engineer, not improvise, the ability to physically or logically disconnect vital OT and OT-enabling systems (HMIs, PLCs, SCADA, engineering workstations) from corporate IT, vendor connections, cloud services, and other external networks, and to sustain essential services in that disconnected state for an extended period.
The operational framework asks operators to: identify the minimum systems required to sustain critical services; map every interconnection between those systems and corporate networks, vendor/remote-access channels, and cloud platforms; establish predetermined physical or virtual isolation points; prioritize physical isolation, falling back to strong cryptographic protection (IPsec, MACsec, secure VPN) or data diodes/cross-domain solutions where physical disconnection is infeasible; develop and test graduated isolation plans with predefined triggers, exercised as complete isolations rather than single-system tests; maintain offline/printed copies of isolation plans and account for the manual processes isolation will force; and isolate shared services (Active Directory, DNS, virtualization, backups) alongside the OT environment itself.
The guidance's stated rationale is the pre-positioning threat: state-sponsored cyber actors have already established persistent, hard-to-detect footholds inside critical-infrastructure IT networks in order to enable disruptive or destructive effects during a future crisis or conflict, while cybercriminal groups separately target the same environments for extortion via data exfiltration or ransomware. Trade-press coverage names three specific precedents underlying CI Fortify's threat model. First, the PRC-linked Volt Typhoon activity described in the CISA/NSA/FBI joint advisory AA24-038A (published February 7, 2024): Volt Typhoon actors (tracked by MITRE ATT&CK as Group G1017, aliases BRONZE SILHOUETTE, Vanguard Panda, Insidious Taurus, Voltzite) used near-exclusive 'living off the land' tradecraft — built-in Windows utilities (PowerShell, wmic, ntdsutil, netsh, certutil, ldifde, Mimikatz) and valid/stolen credentials rather than custom malware — to maintain undetected access and footholds inside Communications, Energy, Transportation, and Water/Wastewater sector IT networks for at least five years. Second, the PRC-linked Salt Typhoon group (MITRE ATT&CK Group G1045, active since at least 2019), which compromised U.S. and international telecommunications providers (including AT&T, Verizon, and Lumen) primarily via exploitation of publicly disclosed — not zero-day — CVEs in network edge devices: CVE-2023-20198 and CVE-2023-20273 (Cisco IOS XE Web UI privilege-escalation and command-injection chain) and CVE-2018-0171 (Cisco Smart Install remote code execution), followed by persistence via SSH authorized-key manipulation on compromised routers and protocol tunneling for covert C2. A follow-on joint advisory, AA25-239A (published August 27, 2025 by CISA, NSA, FBI, DC3, and international partners), broadened this to Chinese state-sponsored actors compromising telecom and other networks worldwide to feed a global espionage collection system. Third, pro-Russian hacktivist groups that have targeted unsecured, internet-exposed OT systems at water facilities — illustrated by two 2024 U.S. water-sector incidents cited in CI Fortify trade coverage: a Kansas water treatment facility that reverted to manual controls after a September 2024 cyberattack, and American Water Works Company (the largest U.S. water utility, serving 14+ million people across 14 states) which suffered an October 9, 2024 cyberattack that disrupted automated operations and forced a temporary pause in customer billing, notifying CISA and state regulators.
BlackBerry's August 4, 2026 analysis does not dispute the isolation directive itself but argues it is operationally incomplete: once isolation begins, incident-response teams, leadership, field personnel, and external partners still need a trusted, out-of-band way to coordinate decisions, share status, and escalate issues — precisely when primary IT-dependent communications systems are unavailable, compromised, or intentionally disconnected. BlackBerry cites its own 2026 State of Secure Communications survey finding that 90% of security leaders report confidence in their crisis-management capabilities, yet only 49% have a unified platform to coordinate crisis response, and positions its own AtHoc (multi-channel crisis alerting), UEM (device compliance/MDM), and SecuSUITE (NSA CSfC- and NATO Restricted-certified encrypted voice/messaging) products as the kind of out-of-band, sovereign-controlled coordination layer CI Fortify's isolation directive presumes but does not itself specify. No CVE, exploit, PoC, or active-exploitation event is associated with this record itself; it is tracked as government guidance relevant to SOC and critical-infrastructure hardening posture, with the actor TTPs above documented only as sourced context for the guidance's threat model, not as new activity against a specific target in this record.
MITRE ATT&CK techniques used in TL-2026-1932
Credential Access
Collection
Lateral Movement
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
Defense Evasion
T1218 System Binary Proxy Execution
Command and Control
Resource Development
T1584 Compromise Infrastructure
Reconnaissance
Affected products and versions in CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation
- N/A — cross-sector guidance — OT and OT-enabling systems across critical infrastructure (HMIs, PLCs, SCADA, engineering workstations) in energy, water and wastewater, transportation, manufacturing, and telecommunications sectors
Remediation for CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation
Immediate actions
- Identify vital OT and OT-enabling systems (HMIs, PLCs, SCADA, engineering workstations) and the minimum assets required to sustain critical services
- Map every interconnection between vital systems and corporate IT, vendor/remote-access channels, and cloud platforms
- Establish predetermined physical or virtual isolation points for rapid disconnection
Workarounds
- Where physical isolation is infeasible, apply strong cryptographic protections (IPsec, MACsec, secure VPN) and data diodes/cross-domain solutions for controlled one-way data transfer
Longer-term hardening
- Develop and regularly test graduated (phased) isolation plans with predefined triggers, exercised as complete isolations rather than single-system tests
- Pair every OT/IT isolation plan with an out-of-band communications-continuity plan (crisis alerting, device compliance, encrypted voice/messaging) so coordination survives disconnection
- Deploy distributed identity, authentication, and least-privilege access controls that continue operating locally in a disconnected or degraded environment
- Isolate shared services (Active Directory, DNS, virtualization, backups) alongside the OT environment
- Patch internet-facing network edge devices (routers, VPN gateways) promptly — Salt Typhoon's telecom-sector intrusions relied on publicly disclosed Cisco IOS XE CVEs, not zero-days
- Maintain offline/printed copies of isolation plans and pre-register personnel, roles, and external contacts before an isolation event
Timeline of CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation
- Salt Typhoon (MITRE ATT&CK Group G1045) becomes active, per MITRE ATT&CK, beginning a multi-year campaign of network-infrastructure compromise later cited as part of the pre-positioning threat model behind CI Fortify.
- CISA, NSA, and the FBI publish joint advisory AA24-038A confirming PRC-linked Volt Typhoon actors maintained undetected, living-off-the-land access inside U.S. Communications, Energy, Transportation, and Water/Wastewater sector IT networks for at least five years — the pre-positioning threat later cited as the rationale for CI Fortify.
- A Kansas water treatment facility reverts to manual controls following a cyberattack; CISA reiterates water-sector warnings, an incident later cited in CI Fortify trade coverage as evidence for the isolation guidance.
- American Water Works Company — the largest U.S. water utility, serving 14+ million people across 14 states — suffers a cyberattack that disrupts automated operations and forces a temporary pause in customer billing; the company notifies CISA and state regulators.
- CISA, NSA, FBI, DC3, and international partners publish joint advisory AA25-239A, 'Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,' detailing Salt Typhoon-overlapping TTPs including exploitation of Cisco IOS XE CVEs and SSH authorized-key persistence.
- The FBI, via IC3, issues a corresponding Cybersecurity Advisory (CSA #260728) reiterating the CI Fortify guidance.
- CISA, Australia's ASD (ACSC), the UK's NCSC, and Canada's CCCS jointly publish 'CI Fortify – Advice for Isolating Vital Systems,' directing critical infrastructure operators to build and test OT/OT-enabling-system isolation capability.
- Trade press (GBHackers, Xage, BleepingComputer) reports on the guidance, noting it targets water, energy, manufacturing, transportation, and telecommunications operators and cites state-sponsored pre-positioning (Volt Typhoon, Salt Typhoon) and cybercriminal extortion as the drivers.
- BlackBerry publishes analysis arguing CI Fortify's isolation directive lacks a paired communications-continuity requirement, citing a survey where 90% of security leaders report crisis-management confidence but only 49% have a unified coordination platform.
- TL-Intel-Harness HUNT phase selects this guidance for tracking as an ADVISORY-category item relevant to SOC and critical-infrastructure hardening posture; the original Industrial Cyber source article returned HTTP 403 to direct fetch and facts were verified via the underlying BlackBerry post and corroborating CISA/press coverage.
Sources cited for CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation
- CI Fortify OT Isolation: Communications Continuity During Disconnection
- CI Fortify | CISA
- CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure
- CI Fortify – Advice for isolating vital systems
- CISA shares advice on isolating vital systems during cyberattacks
- CI Fortify – Advice for isolating vital systems (Cybersecurity Advisory CSA #260728)
- CISA Urges Critical Infrastructure Operators to Isolate Vital OT Systems During Cyberattacks
- CISA's CI Fortify Initiative Signals a New Operational Reality for Critical Infrastructure
- PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A)
- Volt Typhoon, BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad, Group G1017 | MITRE ATT&CK
- Salt Typhoon, Group G1045 | MITRE ATT&CK
- Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System (AA25-239A)
- America's largest water utility hit by cyberattack at time of rising threats against U.S. infrastructure
- American Water Works reconnecting systems a week after cyberattack
More in ics scada
- Kaspersky ICS-CERT Q1 2026 Review: Sandworm/Static Tundra Wiper Hits Polish Energy Grid, Suspected Iran Intrusion at NCBJ Nuclear Centre, Void Manticore's Handala Persona Wipes 200,000 Stryker Devices, DragonForce Ransomware Disrupts Hazeldenes Poultry
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate Devices
- AI-Powered Attacks Targeting Siemens S7 Series PLCs in U.S. Critical Infrastructure
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)
Detection coverage for TL-2026-1932
As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1932 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.