September 22, 2026

US, Australia Release OT Isolation Guidance for Critical Infrastructure

In brief

CISA and the Australian Cyber Security Centre have issued joint guidance to help critical infrastructure organizations isolate essential operational technology and supporting systems during cyber incidents or other crises. Operators should first identify the systems, networks, services and customers involved in critical operations, then classify assets by criticality and trust level. They should document every connection to corporate IT, vendor remote-access services, cloud platforms, untrusted networks and other infrastructure providers, while accounting for dependencies whose interruption could affect utilities, dispatch operators or partner organizations.

The guidance recommends building effective separation points between critical and non-critical environments, including physical disconnection capabilities that allow vital systems to operate independently for extended periods. Organizations should develop and regularly test a graduated isolation plan so connections can be progressively restricted without unnecessarily stopping essential services, and they must continuously verify that isolation remains effective. CISA and ACSC also warn that prolonged separation introduces risks such as delayed patching, reduced external monitoring and greater exposure to malware carried through removable media, all of which should be addressed in continuity and recovery planning.

Source: SecurityWeek

‍

‍

Explore More Insightful Articles: