Network isolation: Why CI Fortify’s new guidance presents both risks and opportunities for federal agencies and contractors | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


As of July 28, the United States’ Cybersecurity and Infrastructure Security Agency, alongside the Australian Signals Directorate (ASD), Canadian Centre for Cyber Security (CCCS) and the United Kingdom’s National Cyber Security Centre (NCSC) released new guidance for operators of critical infrastructure (CI) in a new framework, CI Fortify.

It advocates for CI operators to “fortify their systems to allow vital services in the United States to sustain essential operations during a geopolitical conflict,” saying that “investing in isolation and recovery capabilities today is essential to maintaining service delivery during a future crisis, when an adversary may disrupt communications and manipulate control systems.”

CISA has made it a priority for CI operators to develop the capability to physically and digitally isolate critical systems, like operational technology (OT) from its broader network, and third-party systems.

This is the culmination of a trend already felt across the private and public sector in many jurisdictions, echoed by frameworks like the Network and Information Security (NIS2) directive in the European Union and segmentation guidance from the National Institute of Standards and Technology in the U.S., all responding to threat actors who compromise critical infrastructure by exploiting bi-directional remote access paths.

Why these moves are necessary

Bi-directional remote-access paths, such as VPNs, firewalls, and shared authentication infrastructure, are consistently what allow attackers to move laterally once they’ve gained an initial foothold, turning a single compromised device into a network-wide incident.

For instance, cyber attackers were able to gain access to the Polish power grid using poorly secured edge devices. Attackers were able to gain access to the grid’s operation technology and deployed wiper technology designed to sabotage and damage critical systems.

This incident raised alarm bells in several governments, with Jonathon Ellison, a senior official at the NCSC, writing, “Operators of U.K. critical national infrastructure (CNI) must not only take note but, as we have said before, act now.”

The ability to and capacity for CI operators to meaningfully isolate critical systems can be decisive in incidents like these, allowing IT teams to cut off attacker’s ability to penetrate systems and deploy harmful software.

Many of these methods are not new, but are in many cases sparsely deployed – one example being air-gapped environments secured with devices like data diodes that enforce one-way communication between a secure server and a less secure one.

However, in my experience working with large public sector organizations, while air-gapped and isolated systems have major security benefits, they also can come with significant roadblocks as well. It’s a problem companies urgently need to think about before implementing these kinds of systems.

The problems that can emerge

When critical systems are isolated or air-gapped from the rest of the broader network, even on a temporary basis, it leads to significant headaches within the company.

Take, for instance, employees assigned to a critical data server. When there is no sanctioned path to synchronize or send and receive data, employees have to take long, time-consuming ways to exchange data even as insignificant as emails and calendar requests, slowing many processes down.

In many cases, this increases the risk of shadow IT processes emerging. These can take the form of employees using personal devices to transfer data, or even information being passed on sticky notes.

These kinds of glaring security breaches are rare, to be sure, but every time a company puts in place processes that impede workers’ ability to do their jobs effectively, organizations introduce these kinds of risks.

In this way, an isolated system that meaningfully impedes productivity can have a counterintuitive risk of increasing cybersecurity threats in some areas of the organization.

The solution to this that is often overlooked is maintaining the security of one-way security devices like data diodes over airgaps, while allowing for the kinds of two-way synchronization that is critical for efficiency using secure middleware software.

What secure bi-directional sync looks like

Solutions like these allow organizations to streamline secure data transfer between different applications in stand-alone networks, even bidirectionally and without exposing sensitive data to cyber risks.

Document and collaboration platforms like SharePoint can stay usable across the boundary, allowing agency staff and contractors to work together without a standing two-way connection ever existing. This also applies to applications like calendar requests and emails, which can synchronize safely across classified/unclassified boundaries with strict control over what gets shared — this vastly reduces the risk of employees reaching for shortcuts that can lead to shadow IT.

Key points for agencies and contractors

Federal contractors and agencies need to be mindful of CI Fortify’s recommendations – especially for critical infrastructure, cyber attackers will exploit networks that are not able to isolate and secure key operational technology.

The key is implementing these features without an overall slowdown of the entire system – which would not only decrease efficiency for vital functions, but in some cases increase risks. These barriers can be overcome in many cases by middleware software that can enable bi-directional synchronization without opening organizations up for attack.

CI Fortify itself frames the goal as sustaining essential operations “in a degraded communications environment,” a bar that can only be met in practice if the isolated environment remains one that people can actually work in day to day. Key organizations need to achieve this balance when implementing the recommendations of the framework.

Thomas Berndorfer is chief executive officer of Connecting Software.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.