CISA and international partners published new CI Fortify guidance on July 28, 2026 for isolating vital operational technology and supporting systems during cyber incidents, service disruption, or periods of increased threat. The guidance is aimed at critical infrastructure operators, but the business lesson reaches well beyond utilities.
The core idea is simple to say and harder to prove: know which systems are vital, know every connection they depend on, and know how to disconnect less-trusted networks without stopping the service the business or community depends on. That matters for water, energy, transportation, telecommunications, manufacturing, healthcare, schools, and any organization where technology controls real-world operations.
The continuity question behind the guidance
Many organizations have backup plans, incident response plans, and vendor contact lists. Fewer have tested whether essential systems can operate when normal connectivity is deliberately severed. CISA's CI Fortify guidance asks operators to identify the minimum systems required to deliver a critical service, map the connections around those systems, and define isolation points before a crisis begins.
For a business owner, this is not only a cybersecurity discussion. It is a continuity discussion. If a network attack spreads through corporate IT, remote access, a contractor connection, or a cloud dependency, someone may need to decide whether to isolate part of the environment. That decision should not be invented while phones are ringing, staff are locked out, and vendors are asking for emergency access.
Vendor access is part of the map
The guidance specifically calls attention to connections between vital systems and corporate networks, internet-facing infrastructure, cloud environments, vendors, contractors, managed service providers, and other outside operators. That is where many smaller organizations can turn the guidance into a useful management question.
If a manufacturing line, building system, clinical device, dispatch process, access-control system, or telecom link depends on outside support, the owner should know what that support path looks like. Remote access can be necessary and legitimate. It can also become one of the paths that has to be restricted quickly when the risk changes.
The practical issue is ownership. Who can approve isolation? Who knows which vendor sessions are routine and which are emergency-only? Who has an offline copy of the plan if shared drives, ticket systems, or email are unavailable? If the answers live only in one person's head, the plan is not much of a plan.
Questions to ask your IT provider or internal team
- Which systems are vital to keeping the organization operating at a safe minimum level? Ask for names, locations, owners, and dependencies, not just a broad category.
- What networks, cloud services, vendors, contractors, and remote-access tools connect to those systems? The list should include routine support and emergency support paths.
- Where are the isolation points? A useful plan identifies how access can be reduced or disconnected, who can authorize it, and what business impact each step creates.
- Can the organization operate while isolated? Ask what manual workarounds, communications methods, monitoring gaps, patching delays, and staffing needs would appear after disconnection.
- Has the full isolation workflow been tested? Testing one device or one firewall rule is not the same as testing the shared infrastructure and hidden dependencies around a vital process.
- Where is the plan stored if normal systems are unavailable? CISA's guidance recommends keeping a secure offline or printed copy so the plan remains usable during disruption.
A practical next step
For New Jersey businesses, schools, healthcare practices, nonprofits, and industrial operators, the next step is not to copy a federal critical infrastructure playbook word for word. It is to ask for a short vital-systems review that identifies the essential processes, the technology behind them, the outside access paths, and the person authorized to make isolation decisions.
Start with one process that would hurt the most if it stopped: production scheduling, patient check-in, building access, payment processing, dispatch, refrigeration, phone service, or a core SaaS workflow. Ask your IT provider or internal team to map what has to remain available and what could be disconnected if containment became more important than convenience.
Isolation is not a magic switch. It can reduce monitoring, complicate updates, increase manual work, and create its own operational risks. That is exactly why it belongs in planning instead of improvisation. When the day comes to make systems stand alone, the business should already know which ones can do it.
Sources and further reading