CISA CI Fortify Guidance Highlights Need for Critical Infrastructure Resilience

Author photo: Larry O'Brien
ByLarry O'Brien
Category:
Technology Trends

The Cybersecurity and Infrastructure Security Agency (CISA) released guidance to help critical infrastructure (CI) entities across all sectors prepare to operate through a crisis or conflict, continuing vital service delivery even as their systems are under attack. The new initiative, CI Fortify, strengthens resilience and helps CI entities and their partners maintain a baseline of continuity for critical services during a cyberattack.

The key points in this guidance urge CI entities to start now, if they have not already, to invest in and develop isolation and recovery capabilities. When a cyberattack occurs, these two emergency capabilities help ensure the affected organization can still deliver critical services. Preparation is the key.

  • Isolation: Proactively disconnecting from third-party dependencies and operating without reliable telecommunications, internet vendors, service providers, and upstream dependencies.

  • Recovery: Rapidly restoring vital compromised systems while isolated. A key part is testing recovery plans and practicing local and manual operations.

Isolating affected computing resources during a cyberattack is cybersecurity 101, as is developing a response plan. However, many end users in manufacturing and critical infrastructure often do not isolate devices quickly enough, and many have no response plan. With continued tensions in the Middle East and other parts of the world, the cyber threat environment around US manufacturing and critical infrastructure is intensifying.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients