Critical industries need to know how to isolate, rather than ignore


By Chris Grove*
Wednesday, 09 September, 2026


Critical industries need to know how to isolate, rather than ignore

When the Australian Signals Directorate revised its CI Fortify guidance in July, it wasn’t primarily responding to another ransomware headline. It was responding to a harder, more strategic problem: state-sponsored actors, particularly those linked to China, quietly pre-positioning themselves inside critical infrastructure networks so they can disrupt or disable essential services if a regional conflict ever reaches Australia’s shores.

This is not the work of cybercriminals chasing a payday. It is a deliberate, patient campaign, one designed to hold Australia’s essential services hostage to a future geopolitical crisis. What is even more concerning is that these threat actors can often infiltrate a network and lay idle for prolonged periods of time, waiting until the right moment to cause maximum damage.

In a recent speech Australian Security Intelligence Organisation Director‍-‍General Mike Burgess warned of persistent threats by nation-state actors compromising Australian critical infrastructure networks. In one particular case, ASIO uncovered hackers that had compromised a critical infrastructure provider in Australia: a state-sponsored group that successfully acquired credentials for active users of the networks, including the IT professionals guarding it.

The threat actor didn’t strike straight away. Instead, they waited patiently, collecting information in preparation for sabotage. Sitting in the shadows, mapping out the network and maintaining access to servers so they could cripple it whenever they chose.

With the pervasiveness of these threats, it’s no surprise that in late July the Australian Signals Directorate (ASD) updated its CI Fortify guide to help critical infrastructure organisations improve their cyber resilience. The new guide explains the importance of isolating critical operational technology and supporting systems from other networks.

The timing is not a coincidence: the clearest example of the threat CI Fortify is built to counter is Volt Typhoon, a Chinese state-sponsored group that US and Australian agencies have assessed is pre-positioning inside power, water and communications networks across the US and the wider Asia-Pacific — to be ready to disrupt those services if a conflict over Taiwan draws in the US and its allies. This is the scenario CI Fortify is built around: a state actor holding a country’s ability to function hostage until it chooses to use it.

The new guidelines outline how important visibility and isolation are to effectively understand operational technology (OT) networks and, in the worst-case scenario, shut them down if a cyber threat occurs.

What stands out about CI Fortify is how much of it rests on a single precondition: you cannot isolate what you cannot see. The guidance asks operators to identify the minimum set of systems needed to keep a critical service running, map every dependency between them, and then define clean separation points.

The revised guidance also states that operators should be able to run essential services fully disconnected from corporate networks and the internet for up to three months. That is not a switch you flip mid-incident: it requires knowing in advance which assets are vital, which can be shed, and how the isolated environment will keep functioning once the connections are cut.

Isolation is not the finish line, and the guidance is candid about the trade-offs it introduces. A disconnected environment is harder to patch, loses some external threat visibility, and becomes more exposed to risks. Continuous monitoring therefore has to continue behind the isolation boundary.

This is where preparation separates resilient operators from the rest. Threat actors who quietly map a network and wait, as ASIO described, are counting on defenders who lack that same visibility. An operator that has already inventoried its assets, rehearsed isolation and kept offline copies of its response plans can cut off an intruder in a few deliberate steps. One still discovering what is connected while an incident unfolds has already lost time it cannot spare.

At the end of the day, our threat intelligence agencies can only do so much if organisations aren’t prepared to take advice, guidance, and warnings seriously. Australia doesn’t need to be a direct party to a conflict over Taiwan to feel its consequences at home. If the scenario ever plays out, the operators who treated CI Fortify as a compliance exercise, rather than a genuinely tested isolation capability, will be the ones finding out the hard way.

*Chris Grove is Director of Cyber Security Strategy at Nozomi Networks.

Top image credit: iStock.com/Organic Media

Related Articles

Demystifying zero trust in OT

Implementing zero trust in OT environments requires a holistic approach that unites informed...

The important role of software engineering in industry

To keep up with increasing complexity, the programming practices used in industry need to be...

Calibration explained: principles, processes and modern reporting

Accurate calibration ensures reliable measurements, supports preventive maintenance, and...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd