CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators — Threadlinqs Intelligence
As of 2026-08-07, CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators is a info-severity ics scada threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1932 · Severity: INFO · Status: ACTIVE · Category: ICS_SCADA
CISA, Australia's ASD (ACSC), the UK's NCSC, and Canada's CCCS jointly published 'CI Fortify – Advice for Isolating Vital Systems' on July 28, 2026, directing critical infrastructure operators to
On July 28, 2026, CISA, the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), the UK National Cyber Security Centre (NCSC-UK), and the Canadian Centre for Cyber Security (CCCS) jointly published 'CI Fortify – Advice for Isolating Vital Systems.' The FBI/IC3 issued a corresponding Cybersecurity Advisory (CSA #260728) the same day. The guidance directs operators of critical infrastructure — energy, water and wastewater, transportation, manufacturing, and telecommunications — to pre-engineer, not improvise, the ability to physically or logically disconnect vital OT and OT-enabling systems (HMIs, PLCs, SCADA, engineering workstations) from corporate IT, vendor connections, cloud services, and other external networks, and to sustain essential services in that disconnected state for an extended period.
The operational framework asks operators to: identify the minimum systems required to sustain critical services; map every interconnection between those systems and corporate networks, vendor/remote-access channels, and cloud platforms; establish predetermined physical or virtual isolation points; prioritize physical isolation, falling back to strong cryptographic protection (IPsec, MACsec, secure VPN) or data diodes/cross-domain solutions where physical disconnection is infeasible; develop and test graduated isolation plans with predefined triggers, exercised as complete isolations rather than single-system tests; maintain offline/printed copies of isolation plans and account for the manual processes isolation will force; and isolate shared services (Active Directory, DNS, virtualization, backups) alongside the OT environment itself.
The guidance's stated rationale is the pre-positioning threat: state-sponsored cyber actors have already established persistent, hard-to-detect footholds inside critical-infrastructure IT networks in order to enable disruptive or destructive effects during a future crisis or conflict, while cybercriminal groups separately target the same environments for extortion via data exfiltration or ransomware. Trade-press coverage names three specific precedents underlying CI Fortify's threat model. First, the PRC-linked Volt Typhoon activity described in the CISA/NSA/FBI joint advisory AA24-038A (published February 7, 2024): Volt Typhoon actors (tracked by MITRE ATT&CK as Group G1017, aliases BRONZE SILHOUETTE, Vanguard Panda, Insidious Taurus, Voltzite) used near-exclusive 'living off the land' tradecraft — built-in Windows utilities (PowerShell, wmic, ntdsutil, netsh, certutil, ldifde, Mimikatz) and valid/stolen credentials rather than custom malware — to maintain undetected access and footholds inside Communications, Energy, Transportation, and Water/Wastewater sector IT networks for at least five years. Second, the PRC-linked Salt Typhoon group (MITRE ATT&CK Group G1045, active since at least 2019), which compromised U.S. and international telecommunications providers (including AT&T, Verizon, and Lumen) primarily via exploitation of publicly disclosed — not zero-day — CVEs in network edge devices: CVE-2023-20198 and CVE-2023-20273 (Cisco IOS XE Web UI privilege-escalation and command-injection chain) and CVE-2018-0171 (Cisco Smart Install remote code execution), followed by persistence via SSH authorized-key manipulation on compromised routers and protocol tunneling for covert C2. A follow-on joint advisory, AA25-239A (published August 27, 2025 by CISA, NSA, FBI, DC3, and international partners), broadened this to Chinese state-sponsored actors compromising telecom and other networks worldwide to feed a global espionage collection system. Third, pro-Russian hacktivist groups that have targeted unsecured, internet-exposed OT systems at water facilities — illustrated by two 2024 U.S. water-sector incidents cited in CI Fortify trade coverage: a Kansas water treatment facility that reverted to manual controls after a September 2024 cyberattack, and American Water Works Company (th
Target sectors: energy, water and wastewater, transport, manufacturing, telecoms, government administration
Target regions: united states of america, australia, united kingdom, canada
Timeline
- Salt Typhoon (MITRE ATT&CK Group G1045) becomes active, per MITRE ATT&CK, beginning a multi-year campaign of network-infrastructure compromise later cited as part of the pre-positioning threat model behind CI Fortify.
- CISA, NSA, and the FBI publish joint advisory AA24-038A confirming PRC-linked Volt Typhoon actors maintained undetected, living-off-the-land access inside U.S. Communications, Energy, Transportation, and Water/Wastewater sector IT networks for at least five years — the pre-positioning threat later cited as the rationale for CI Fortify.
- A Kansas water treatment facility reverts to manual controls following a cyberattack; CISA reiterates water-sector warnings, an incident later cited in CI Fortify trade coverage as evidence for the isolation guidance.
- American Water Works Company — the largest U.S. water utility, serving 14+ million people across 14 states — suffers a cyberattack that disrupts automated operations and forces a temporary pause in customer billing; the company notifies CISA and state regulators.
- CISA, NSA, FBI, DC3, and international partners publish joint advisory AA25-239A, 'Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System,' detailing Salt Typhoon-overlapping TTPs including exploitation of Cisco IOS XE CVEs and SSH authorized-key persistence.
- CISA, Australia's ASD (ACSC), the UK's NCSC, and Canada's CCCS jointly publish 'CI Fortify – Advice for Isolating Vital Systems,' directing critical infrastructure operators to build and test OT/OT-enabling-system isolation capability.
- The FBI, via IC3, issues a corresponding Cybersecurity Advisory (CSA #260728) reiterating the CI Fortify guidance.
- Trade press (GBHackers, Xage, BleepingComputer) reports on the guidance, noting it targets water, energy, manufacturing, transportation, and telecommunications operators and cites state-sponsored pre-positioning (Volt Typhoon, Salt Typhoon) and cybercriminal extortion as the drivers.
- BlackBerry publishes analysis arguing CI Fortify's isolation directive lacks a paired communications-continuity requirement, citing a survey where 90% of security leaders report crisis-management confidence but only 49% have a unified coordination platform.
- TL-Intel-Harness HUNT phase selects this guidance for tracking as an ADVISORY-category item relevant to SOC and critical-infrastructure hardening posture; the original Industrial Cyber source article returned HTTP 403 to direct fetch and facts were verified via the underlying BlackBerry post and corroborating CISA/press coverage.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ICS_SCADA, INFO, threat intelligence, cybersecurity, T1590, T1584, T1190, T1133, T1078, T1059, T1047, T1098, T1021, T1003