CISA, ASD Issue Joint OT Isolation Guidance
CISA and Australia's ASD jointly urge critical infrastructure operators to pre-plan and rehearse OT isolation before a cyberattack forces the decision mid-incident.
Joint advisory out. CISA and Australia’s Signals Directorate (ASD) issued guidance today on isolating operational technology (OT) systems during cyberattacks. The specific argument: plan and rehearse the isolation procedure before it is needed, not while the incident is active.
Confirmed joint release from CISA and ASD. Reported by BleepingComputer.
What the advisory says
Incident-time OT isolation decisions carry more risk than pre-planned, rehearsed decisions. Operators without a tested sequence improvise. The advisory targets energy, water, transportation, and manufacturing sectors — organizations where IT/OT convergence creates a path from enterprise ransomware or destructive malware to physical control systems.
Specific guidance elements:
- Establish network boundaries between IT and OT before a crisis. Document them.
- Define isolation triggers in advance — the conditions that justify disconnecting OT from the network.
- Map which OT systems operate standalone and which require connectivity, including vendor remote access paths.
- Test the isolation procedure under controlled conditions. Tabletops are a minimum.
Confidence notes
CISA and ASD are confirmed co-authors. The advisory is framed as general preparedness — no named threat actor, no attributed campaign. Unconfirmed whether a specific incident drove the timing.
Any ICS incident response plan that has not been tested against a realistic isolation scenario should be treated as draft.
Found this useful? Share it.


