The Cybersecurity and Infrastructure Security Agency (CISA) has launched CI Fortify, a new initiative asking critical infrastructure operators to prepare for cyber incidents in which essential services must continue even as systems are under attack and third-party connections may fail.
CISA has released the guidance with the aim of helping critical infrastructure entities across all sectors operate through a crisis or conflict. The initiative centers on two emergency capabilities: isolation and recovery.
Isolation means proactively disconnecting from third-party dependencies and operating without reliable telecommunications, internet access, vendors, service providers or upstream dependencies.
Recovery means restoring compromised systems while isolated, including through tested recovery plans, local procedures and manual operation where needed.
CISA’s CI Fortify page describes the initiative as an allied effort to protect public health and safety, defense-critical infrastructure, continuity of the economy and national security by ensuring operators can sustain essential operations during a geopolitical conflict.
For planning purposes, operators should assume that telecommunications, internet, vendors, service providers and upstream dependencies may be unreliable, and that threat actors may have some access to operational technology networks.
Shifting to degraded continuity planning
CISA’s guidance tells operators to identify the critical customers they serve, set service delivery targets and determine which OT assets and supporting infrastructure are needed to meet those targets. Operators are also told to update business continuity plans so safe operations can continue while isolated for weeks to months.
Recovery planning requires documentation of how systems operate, backups of important files and practice replacing systems or shifting to manual processes if isolation fails.
Addressing vendor and licensing hurdles
CISA also points to a practical dependency that can limit emergency action: contracts and licensing. Its guidance asks industrial automation control system vendors and suppliers to identify blockers to isolation and recovery, including contractual or licensing issues tied to server connections that could stop operators from exercising for an emergency or taking needed steps during one.
The threat context comes from earlier U.S. government warnings about Chinese state-backed access to critical infrastructure networks. In February 2024, NSA said it had joined CISA, the FBI and other agencies in an advisory on Volt Typhoon activity targeting IT networks at U.S. communications, energy, transportation, water and wastewater organizations.
The NSA release said the agencies recognized that the PRC had already compromised those systems and that, in some cases, actors had been inside IT networks for years to pre-position for disruptive or destructive attacks against OT in a major crisis or conflict.
The Justice Department described the same risk when it announced the disruption of the KV Botnet in January 2024. FBI Director Christopher Wray said Chinese hackers were targeting American civilian critical infrastructure and “pre-positioning to cause real-world harm” in the event of conflict, naming communications, energy, transportation and water as targeted sectors.
Aligning with international resilience models
CI Fortify also closely resembles resilience planning already published by Australia. The Australian Signals Directorate’s October 2025 CI Fortify guidance asks critical infrastructure operators to identify vital OT and enabling systems, isolate them from the internet and other networks for three months while maintaining critical services, and rapidly rebuild those systems completely to minimize disruption.
ASD’s guidance also warns that isolating vital OT systems will break business processes, especially automated processes crossing from isolated networks to adjacent systems. It tells operators to plan for manual processes during crisis or service disruption, maintain offline known-good backups of firmware, configuration and processes, and accept that a minimum operating state may differ significantly from business as usual.