CISA Told Water Plants and Power Grids to Prepare for Total Internet Disconnection. That Is Not a Drill Scenario Anymore.

CISA Told Water Plants and Power Grids to Prepare for Total Internet Disconnection. That Is Not a Drill Scenario Anymore.

On May 5, the US Cybersecurity and Infrastructure Security Agency published guidance that would have seemed extreme three years ago. It told water utilities, energy providers, transport operators and hospitals to start planning for scenarios in which they lose access to the internet entirely during a geopolitical conflict. Not as a contingency. As a core operational capability.

The initiative is called CI Fortify. CISA Acting Director Nick Andersen put it plainly: “We strongly encourage organizations to review this guidance, implement the recommended actions and collaborate with CISA to strengthen CI defenses against opportunistic threat actors.”

The guidance is built around two planning objectives. The first is isolation. CISA wants critical infrastructure operators to proactively develop the ability to disconnect from third-party networks, vendor connections, telecommunications providers and cloud services when a cyberattack or conflict scenario makes those connections a liability rather than an asset. The second is recovery. That means documenting every system, maintaining current backups of critical data and practising what it looks like to switch from digital operations to manual ones when the digital option is no longer available.

The reasoning behind this is not speculative. The Stryker attack in March demonstrated how a connection to a legitimate cloud management platform can become the mechanism of destruction. The CISA advisory from April 7, issued jointly with the FBI, NSA, Department of Energy and US Cyber Command, confirmed that Iranian-affiliated cyber actors are actively targeting systems that support essential US services. The focus is not data theft. The objective is operational disruption.

US intelligence agencies have assessed that hackers linked to China, Russia, Iran and North Korea will continue to pose critical threats to US networks and critical infrastructure. CI Fortify is CISA’s operational response to that assessment.

What is new in 2026 is the framing. Previous CISA guidance focused on defending connections. CI Fortify assumes those connections will fail and asks: can you still deliver essential services when they do? That is a fundamentally different starting point for a security strategy.

For planning purposes, CISA’s guidance states that operators should assume that in a conflict scenario “third-party connections, such as telecommunications, internet, vendors, service providers, and upstream dependencies, will be unreliable and that threat actors will have some access to the operational technology network.” That sentence deserves to be read twice. CISA is not saying these things might happen. It is saying to plan as if they will.

The practical implication for water utilities is that treatment processes must be able to run on manual controls or local automation if the systems that normally manage them become inaccessible. For hospitals, it means having paper-based protocols ready for situations where electronic health records and device communication platforms go offline simultaneously. For transport operators, it means maintaining traffic management capabilities that do not rely on continuous internet connectivity.

This kind of operational resilience thinking has historically lived in business continuity and disaster recovery planning, not in cybersecurity. CI Fortify is one of the clearer signals yet that those two disciplines are merging under pressure from the current threat environment.

The Cybersecurity Dive noted that CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act passed in 2022, will extend mandatory incident reporting requirements to more than 300,000 businesses once its final rule is published in 2026. CI Fortify arrives alongside that regulatory expansion as the operational counterpart to the compliance requirement.

Organisations outside the United States are paying attention. The principles of isolation and recovery planning are not geography-specific. Any operator of industrial control systems or operational technology that relies on cloud connectivity to function has a version of this problem regardless of where they are based.

Leave a Reply

Your email address will not be published.