A newly released guide by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and other allied global cybersecurity agencies outlines a six-step plan for isolating critical infrastructure during cyberattacks. The guide, named CI Fortify, aims to help organizations build dedicated isolation points into their operational technology to contain attacks effectively and maintain essential services.
Most IT operators recognize the importance of isolating critical systems during crises; however, many lack the specific knowledge on executing such isolation securely and with minimal disruption. The CI Fortify plan focuses on enabling essential services to operate in isolation, citing that this is crucial for continuing operations should the system undergo an attack.
Six Steps to Isolation
-
Identify Vital Systems and Networks: Determine the minimum number of systems required to support essential services.
-
Identify Critical Customers: Set delivery targets based on the needs of key customers.
-
Identify Levels of Criticality and Trust: Segment networks, hosts, and systems according to their nature and exposure to threats.
-
Identify Isolation Points: Map connections to vital systems, accounting for any external connections that could pose risks.
-
Build Separation and Isolation Points: Create physical separation to ensure vital operations can function independently of potentially compromised networks.
-
Create and Test an Isolation Plan: Develop a strategy for isolating systems in response to real-world threats and test this plan periodically.
Importance of Isolation
Today, cyber actors, especially state-sponsored ones, increasingly target operational technology (OT) infrastructures to conduct espionage or disrupt essential services like power and water. Recent incidents highlight this, such as CAF Bank, which had to suspend online services due to a third-party software vulnerability affecting its operations. Similarly, a coordinated cyberattack this week targeted multiple Minnesota water utilities, causing widespread disruption.
To mitigate such risks, establishing isolation points between networks and services is critical. The guide emphasizes that physical isolation points are essential to containing attacks and minimizing damage to operations. It requires avoiding any connectivity with non-OT networks through shared infrastructure.
Managing Dependencies and Risks
Cybersecurity experts recommend understanding the dependencies between OT and non-OT systems and emphasizing secure OT capabilities. Organizations must ensure they remain operational during extended periods of separation to prevent performance degradation or compliance issues.
While isolating critical infrastructure might seem daunting, implementing the steps progressively allows companies to address threats effectively without compromising business processes.
Ultimately, as cyber threats continue to evolve, the blueprint provided by CISA and their partners offers essential guidance for organizations seeking to enhance their resilience against potential cyberattacks.
For more information, refer to the full guide: CI Fortify.