Editor’s Note: Allied cyber agencies have turned a quiet engineering assumption into published doctrine. “CI Fortify: Advice for Isolating Vital Systems,” released July 28 by CISA and the Australian Signals Directorate’s Australian Cyber Security Centre in collaboration with the FBI and international partners, asks critical infrastructure operators to pre-engineer, authorize and rehearse the physical severing of operational technology from corporate networks, vendors and cloud services, then keep essential services running anyway, potentially for months.
The trigger is confirmed pre-positioning by Chinese state actors and live disruption by Iranian-affiliated groups, but the durable story is legal. The guidance is voluntary, yet law firm analysis already frames it as a baseline that may follow operators into regulatory examinations, insurance negotiations and post-breach litigation. The dependency maps, trigger criteria and exercise records that implementation generates are candidates for tomorrow’s discovery requests, and their absence may be read as a choice.
Watch next for sector regulators and underwriters converting the advice into binding expectations. In Australia, any such decision would sit with the Department of Home Affairs under the Security of Critical Infrastructure Act. Security, governance and discovery teams that start the mapping work now will answer easier questions later.
Content Assessment: The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
Information - 93%
Insight - 92%
Relevance - 93%
Objectivity - 91%
Authority - 91%
92%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation."
Industry News – Cybersecurity Beat
The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
ComplexDiscovery Staff
The first document requested after the next major infrastructure breach may not be a firewall log. It may be an isolation plan that was never written, never tested or never authorized. Allied cyber agencies have now told critical infrastructure operators exactly what that plan should contain, and at least one law firm began briefing clients on the liability stakes back in May.
On July 28, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate’s Australian Cyber Security Centre, in collaboration with the FBI and international partners, published joint guidance titled “CI Fortify: Advice for Isolating Vital Systems,” urging operators to pre-engineer and test the ability to sever operational technology from corporate networks, vendors and cloud services while keeping essential services running.
The guidance is voluntary. Its practical effect may not be.
A six-step path to pulling the plug
The document lays out a six-step path: identify the minimum set of systems required to deliver a critical service, identify critical customers, classify systems by criticality and trust, map every connection to corporate networks, vendors, cloud environments and peer utilities, build separation points, and then create and test graduated isolation plans with trigger criteria defined in advance and linked to incident response.
Physical separation is the preferred end state. To qualify as physically separate, the guidance says, OT networks “must not share any active infrastructure” with other networks, including switches, routers, repeaters, multiplexers or compute elements. Where carrier services cannot be avoided, operators “must treat any carrier-provided service as untrusted and potentially hostile.” The document acknowledges that complete physical isolation at every site may not be operationally feasible for organizations that depend on internet-facing services or dispersed operations, and it offers alternatives: hardened OT boundaries, encryption over untrusted links, cross-domain solutions and the capability to rapidly rebuild vital systems. Graduated isolation proceeds in defined steps, from disabling remote worker access through severing all non-OT connections to complete isolation of vital systems.
The agencies also identify why isolation plans fail in practice: enabling systems. Shared identity, name and address services such as Active Directory, Domain Name System and Dynamic Host Configuration Protocol, along with certificate services, time synchronization and shared virtualization platforms, are routinely embedded in OT environments. Cut the cable and equipment that was never damaged may stop working where authentication, name resolution or other required services remain outside the isolation boundary. The guidance recommends that operators test the isolation of all vital systems together, because testing a single system or subset “may not identify all dependencies.” Plans should be stored in secure offline hard copy.
Heidi Hutchison, ASD assistant director-general for cyber uplift, said the target state is a full disconnection from external network connectivity, including corporate IT environments and the internet, and Australian guidance asks operators to be capable of sustaining isolation for up to three months. The joint document itself avoids a fixed number, instead directing organizations to consider how they will operate in that state “for an extended period.”
The threat driving a doctrine of disconnection
The agencies are not writing for a hypothetical adversary. In a February 2024 joint advisory, CISA, the National Security Agency and the FBI assessed that China’s Volt Typhoon actors had maintained access to U.S. critical infrastructure networks for at least five years, pre-positioning for disruptive attacks rather than espionage. Salt Typhoon, another Chinese state-linked campaign, compromised at least nine U.S. telecommunications carriers, according to the White House. Chris Butera, CISA’s acting executive assistant director for cybersecurity, said America’s critical infrastructure is frequently targeted by state-sponsored actors whose aim is persistent access to vital systems and disruption of essential services.
Iranian-affiliated actors have moved from pre-positioning to disruption. An April 7 advisory from the FBI, CISA, NSA, EPA, the Department of Energy and U.S. Cyber Command documented Iranian-affiliated actors manipulating programmable logic controllers across water, energy and government facilities, with some victims experiencing operational disruption and financial loss. On July 22, six days before CI Fortify’s release, the agencies updated that advisory to warn that changes made by the actors “disabled critical shutdown and alarm logic, allowing systems to enter unsafe conditions without notifying operators of the anomalies.”
The doctrine is not reserved for wartime. The guidance names criminal ransomware operations alongside state actors among the threats to critical infrastructure, and for many operators the first live use of an isolation plan may come during a criminal extortion event, not a geopolitical crisis.
Voluntary guidance, possible courtroom evidence
The guidance carries the standard disclaimers: it is provided “as is” for informational purposes, its “must” statements represent cybersecurity best practice rather than legal command, and it is not legal advice. Nothing in it creates enforceable rights or obligations.
One law firm read it differently. CISA unveiled its domestic CI Fortify initiative on May 5, adapting Australian guidance first published in 2025; the July document extends the doctrine internationally. In a May client alert responding to the CISA launch, Crowell & Moring wrote that the program “establishes a federal baseline that will be difficult to ignore post-incident” and raises expectations for boards, executives and legal teams in future regulatory examinations, insurance disputes and litigation. The alert is client-development material as well as analysis, and it describes a baseline likely to attract post-incident attention rather than a negligence standard already adopted by any court or regulator. Still, its logic tracks how voluntary frameworks have hardened before: the NIST Cybersecurity Framework was never mandatory either, and it now anchors reasonableness arguments in breach litigation across sectors.
Australia illustrates a possible route from guidance to regulation, although that conversion has not occurred. ASD anticipates that operators covered by the country’s Security of Critical Infrastructure Act already address much of the required system delineation through their critical infrastructure risk management programs. ASD is not a regulator and has no enforcement powers, however, and Hutchison said it would be up to the Department of Home Affairs to decide what, if anything, becomes mandatory. American precedent runs a parallel course; the Transportation Security Administration’s pipeline security directives, issued after the Colonial Pipeline shutdown, already require segmentation controls designed to keep OT running if IT is compromised.
The mechanism is discovery. CI Fortify tells operators to document their connections, map their dependencies and test isolation regularly, with trigger criteria for each step defined in advance. The document does not expressly prescribe exercise records, but implementation will generate them, along with dependency maps and connection inventories; organizations should also decide who holds authority to approve each isolation stage. Those records may become discoverable in litigation when relevant, proportional and nonprivileged, and their absence can be just as visible. An operator that suffers a prolonged outage and cannot produce a tested isolation plan could face an uncomfortable deposition question: allied governments told you how to prepare, and what did you do?
Insurers may ask first. The Crowell alert names insurance disputes alongside regulatory examinations as arenas where the baseline may surface, and a published multinational benchmark hands underwriters a ready-made questionnaire for OT policy renewals. The closest recent example has limits worth naming: when American Water, the largest U.S. water utility, disconnected customer-facing systems after an October 2024 intrusion, the incident centered on IT systems rather than OT isolation, and the class actions that followed within weeks concerned alleged personal-data exposure. The episode shows how quickly litigation follows disruption, and future incidents will unfold against a published benchmark that did not exist then.
What security, governance and discovery teams should do now
The immediate work is archival as much as architectural. Dependency mapping should start with the enabling systems the guidance names, because that is where exercises fail silently. Authorization decisions need names, not just roles, and trigger criteria need board visibility, because a decision to sever revenue-generating connectivity for weeks will not be made by a shift supervisor. Exercise records should be written with two audiences in mind: the engineers who will use them and the examiners, underwriters and opposing counsel who may read them later. Information governance teams should treat isolation plans, test results and after-action reports as records with defined retention, versioning and privilege review. Privilege planning has limits: ordinary-course operational records do not become privileged merely because counsel later reviews them, while materials prepared principally in anticipation of litigation may receive work-product protection under governing law, and the underlying facts an exercise reveals remain reachable in discovery.
A quieter eDiscovery problem sits inside the guidance itself. Isolation severs the cloud-hosted preservation, monitoring and forensic tools that modern incident response assumes. A utility running isolated for weeks will generate logs, manual operation records and safety documentation on systems designed for continuity, not collection. Counsel should ask now how evidence gets preserved from an air-gapped plant.
Skeptics spoke up at the May launch. Richard Forno, associate director of the UMBC Cybersecurity Institute, told CSO Online the proposal resembles the business continuity, disaster recovery and incident response planning organizations should have adopted long ago, and that executing it requires keeping expensive resources on hot standby. James Winebrenner, chief executive of network security vendor Elisity, said in the same article that the doctrine is right but the operator-side investment to make it executable is missing, and that operators cannot plan to run disconnected from third parties until they can list who those third parties are.
Both may be correct. Budgets are finite, and the guidance asks for engineering work that some operators will defer. But deferral is now a documented choice against a documented baseline. When the next intrusion forces a utility offline, will your organization be holding a tested isolation plan, or explaining to a regulator, an underwriter and a jury why it never wrote one?

News sources
- CI Fortify: Advice for Isolating Vital Systems (Joint Guidance PDF) (ASD and CISA with allied agencies, via IC3.gov)
- CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure (CISA)
- CISA Pushes Critical Infrastructure Operators to Prepare to Work in Isolation (CSO Online)
- ASD to Critical Infrastructure Ops: Be Ready to Isolate Systems for Three Months (iTnews)
- CISA Releases Joint Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure (HSToday)
- CISA Shares Advice on Isolating Vital Systems During Cyberattacks (BleepingComputer)
- US, Australia Release OT Isolation Guidance for Critical Infrastructure (SecurityWeek)
- China and Iran Are Already Inside US Grids: CISA Demands Tested Isolation Plans (Tech Times)
- CISA’s CI Fortify Initiative Signals New Expectations for Critical Infrastructure Resilience (Crowell & Moring)
- PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A) (CISA, NSA and FBI via IC3.gov)
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (AA26-097A, April 7, 2026) (FBI, CISA, NSA, EPA, DOE and USCYBERCOM via IC3.gov)
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (AA26-097A update, July 22, 2026) (FBI, CISA, NSA, EPA, DOE, USCYBERCOM and Treasury via IC3.gov)
- US Government Says Iran-Linked Hackers Are Disrupting American Water and Energy Providers (TechCrunch)
- America’s Largest Water Utility Hit by Cyberattack at Time of Rising Threats Against U.S. Infrastructure (CNBC)
Assisted by GAI and LLM technologies
Additional reading
- Stadler rejects $12.3 million ransom after supplier-linked platform breach
- SharePoint attackers are stealing the keys, and patching alone will not evict them
- UK and EU impose first simultaneous cyber sanctions as Poland attack is attributed to the FSB
- The negotiator was the leak: insider who betrayed ransomware victims gets 70 months
- Why a single Signal recovery key is a preservation problem
- Europe’s critical sectors are maturing, but seven still sit in ENISA’s risk zone
- When the worm targets the assistant: Miasma turns AI coding agents into the trigger
- Glasswing widens: Anthropic puts Mythos inside power, water and hospital operators across more than 15 countries
- Canvas breach moves from disclosure to demand as ShinyHunters sets May 12 deadline
- CISA’s CI Fortify rewrites the disconnection playbook for critical infrastructure
- A 48-month federal benchmark resets the incident-response insider question
- Data collection in occupied territory: A closer read of Cyber Law Toolkit scenario 35
- Cyber Law Toolkit tests surveillance and data collection under occupation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.



























