CISA Shares Advice on Isolating Vital Systems During Cyberattacks
The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
The guidance, titled 'CI Fortify – Advice for isolating vital systems,' was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), the FBI, and international partners.
Operational Technology and Critical Infrastructure
Operational technology includes the hardware and software used to monitor or control processes, such as water treatment equipment, electrical systems, manufacturing machinery, transportation systems, and telecommunications infrastructure.
The agencies say state-sponsored threat actors routinely target critical infrastructure for espionage and to establish access that could later be used for disruptive or destructive attacks during a crisis or military conflict.
Cybercriminals continue to opportunistically target CI operators. The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes.
Previous Attacks on Critical Infrastructure
In February 2024, CISA, the FBI, NSA, and other Five Eyes agencies warned that the Chinese Volt Typhoon hacking group had breached organizations in the communications, energy, transportation, and water sectors.
The hackers remained undetected in at least one critical infrastructure network for five years, with U.S. officials warning that they were positioning themselves for potentially disruptive attacks during a future crisis or conflict.
Isolating Vital Systems
The agencies recommend critical infrastructure entities first identify the minimum systems and networks required to continue delivering a critical service.
Organizations should then document every connection between those systems and corporate networks, remote-access services, cloud environments, Internet-facing infrastructure, vendors and contractors, and other critical infrastructure operators.
- Vital systems: The minimum OT and supporting systems needed to provide a critical service, such as controlling water distribution, delivering electricity, or operating a telecommunications network.
- Isolation point: A predetermined location where connectivity between critical and non-critical networks or systems can be disconnected to contain an attack and prevent lateral movement into other vital systems.
- Physical isolation: Completely disconnecting vital systems so they do not share network or computing infrastructure with non-critical systems.
- Graduated isolation: Gradually restricting access as the threat increases, such as first blocking remote workers and vendors, then disconnecting corporate networks, connected systems, and eventually all external connections.
Implementing Isolation Plans
Isolation plans should also define who can authorize each step, the conditions that would trigger it, which systems must remain available, and how operations will continue without normal network connectivity.
Organizations are urged to test the complete isolation of their vital systems regularly, rather than testing only individual systems, because partial tests may fail to identify shared infrastructure and other hidden dependencies that could cause problems when the isolation plan is initiated.
The guidance also recommends keeping a secure offline or printed copy of the isolation plan so that it remains available in the event that access to corporate network or storage servers are disrupted.
After systems have been isolated, operators should continue monitoring network traffic, routing information, and management systems to ensure that unauthorized or accidental connections have not restored access between critical and non-critical networks.
Source: BleepingComputer