For the organisations that keep water flowing, power moving and trains running, one hard question sits behind every conversation about cyber risk. "If a serious incident hit tomorrow, could essential operations keep going while the systems behind them were protected and restored?"
Guidance from the Australian Signals Directorate (ASD) - CI Fortify: Advice for isolating vital systems, developed with international partners - puts that question front and centre. It focuses on an organisation's ability to identify, isolate and protect the operational technology (OT) - the systems that monitor and control physical processes - and the enabling infrastructure that underpins critical services.
CI Fortify's central message is a practical one. If the threat environment deteriorates, or an incident takes hold, operators need the ability to disconnect their most vital systems from everything else and keep delivering essential services - potentially for an extended period. Isolation contains an attack, buys time to evict an intruder, and creates the conditions to rebuild compromised systems safely.
That sounds simple. In a modern industrial environment, it rarely is.
essential services, such as water treatment and delivery.
The guidance draws attention to a range of dependencies common across industrial environments: shared networks and virtualisation platforms, storage and backup systems, identity services, time synchronisation and management infrastructure.
For many organisations, these dependencies have built up over time and are now woven deeply into day-to-day operations. That connectivity delivers real operational benefits. But it also means a system you think you can isolate may quietly depend on something you can't - and that can widen the impact of an incident when critical systems and their supporting services aren't fully understood or protected.
In other words, the risk often isn't the OT system everyone watches. It's the quiet dependency no one mapped.
CI Fortify sets out a practical path. In plain terms, it asks operators to:
A recurring theme is that isolation isn't a single switch. A graduated approach, progressively cutting pathways as the threat rises, with full isolation of the most vital systems as the end goal, lets operators balance security against the need to keep operating. And a plan only counts if it's tested; the guidance is clear that testing one system in isolation rarely surfaces every dependency.
None of this is trivial. These are challenges organisations continue to navigate as OT environments become more interconnected and more reliant on shared services.
Perhaps the most useful takeaway is a mindset shift. Cyber resilience isn't solely about preventing incidents. It's about understanding your critical dependencies, preparing for disruption, and making sure essential operations can continue when an incident does occur.
That reframing matters. Prevention will always be part of the picture. But a resilient operator also plans for the day something gets through, and knows exactly which systems must keep running, how to protect them, and how to recover.
for disruption and ensuring essential services can continue if an incident occurs.
This is the work we do every day. At SAGE, we help organisations identify their critical operational assets, assess cyber risk within OT environments, and develop practical recommendations that reflect the realities of industrial operations, not just the theory.
Our capability extends beyond advice. We can support the implementation of the resilience measures and security controls that reduce operational risk and strengthen critical infrastructure environments.
And through our Security Operations Centre (SOC) and National Operations Centre (NOC), we provide ongoing monitoring, management and protection of critical assets, helping organisations maintain visibility of emerging threats while building long-term operational resilience.
CI Fortify is a timely reminder that the goal isn't a system that never gets tested. It's an operation that can keep serving its community when it does. Understanding your critical dependencies, preparing for disruption and protecting the services that matter most: that's what turns cyber security investment into genuine resilience.
If your organisation is working through the implications of the ASD guidance and would like to talk about improving OT cyber resilience, the SAGE Cyber Security team would be glad to help.