Blog | SAGE Group

Beyond prevention: What the ASD's CI Fortify guidance means for OT cyber resilience

Written by Jeremy Hulse | September 28, 2026

For the organisations that keep water flowing, power moving and trains running, one hard question sits behind every conversation about cyber risk. "If a serious incident hit tomorrow, could essential operations keep going while the systems behind them were protected and restored?"

Guidance from the Australian Signals Directorate (ASD) - CI Fortify: Advice for isolating vital systems, developed with international partners - puts that question front and centre. It focuses on an organisation's ability to identify, isolate and protect the operational technology (OT) - the systems that monitor and control physical processes - and the enabling infrastructure that underpins critical services. 

The core idea: keep running, even in isolation

CI Fortify's central message is a practical one. If the threat environment deteriorates, or an incident takes hold, operators need the ability to disconnect their most vital systems from everything else and keep delivering essential services - potentially for an extended period. Isolation contains an attack, buys time to evict an intruder, and creates the conditions to rebuild compromised systems safely.

That sounds simple. In a modern industrial environment, it rarely is.

CI Fortify recommends understanding what operational assets are critical to maintaining
essential services, such
as water treatment and delivery.  

The dependencies hiding in plain sight

The guidance draws attention to a range of dependencies common across industrial environments: shared networks and virtualisation platforms, storage and backup systems, identity services, time synchronisation and management infrastructure.

For many organisations, these dependencies have built up over time and are now woven deeply into day-to-day operations. That connectivity delivers real operational benefits. But it also means a system you think you can isolate may quietly depend on something you can't - and that can widen the impact of an incident when critical systems and their supporting services aren't fully understood or protected.

In other words, the risk often isn't the OT system everyone watches. It's the quiet dependency no one mapped.

What good preparation looks like

CI Fortify sets out a practical path. In plain terms, it asks operators to:

  • Understand which operational assets are critical to maintaining essential services.
  • Map the dependencies and connections between OT environments and the enterprise systems that support them.
  • Build effective separation and isolation points into those environments.
  • Assess how a cyber incident could affect operational continuity.
  • Create, test and rehearse an isolation plan, and keep controls and response plans aligned with operational requirements.

A recurring theme is that isolation isn't a single switch. A graduated approach, progressively cutting pathways as the threat rises, with full isolation of the most vital systems as the end goal, lets operators balance security against the need to keep operating. And a plan only counts if it's tested; the guidance is clear that testing one system in isolation rarely surfaces every dependency.

None of this is trivial. These are challenges organisations continue to navigate as OT environments become more interconnected and more reliant on shared services.

Cyber resilience is more than prevention

Perhaps the most useful takeaway is a mindset shift. Cyber resilience isn't solely about preventing incidents. It's about understanding your critical dependencies, preparing for disruption, and making sure essential operations can continue when an incident does occur.

That reframing matters. Prevention will always be part of the picture. But a resilient operator also plans for the day something gets through, and knows exactly which systems must keep running, how to protect them, and how to recover.

Cyber resilience in critical infrastructure means understanding critical dependencies, preparing
for disruption and ensuring essential services can continue if an incident occurs.

How SAGE supports OT cyber resilience

This is the work we do every day. At SAGE, we help organisations identify their critical operational assets, assess cyber risk within OT environments, and develop practical recommendations that reflect the realities of industrial operations, not just the theory.

Our capability extends beyond advice. We can support the implementation of the resilience measures and security controls that reduce operational risk and strengthen critical infrastructure environments.

And through our Security Operations Centre (SOC) and National Operations Centre (NOC), we provide ongoing monitoring, management and protection of critical assets, helping organisations maintain visibility of emerging threats while building long-term operational resilience.

 

Preparing for the day it matters

CI Fortify is a timely reminder that the goal isn't a system that never gets tested. It's an operation that can keep serving its community when it does. Understanding your critical dependencies, preparing for disruption and protecting the services that matter most: that's what turns cyber security investment into genuine resilience.

If your organisation is working through the implications of the ASD guidance and would like to talk about improving OT cyber resilience, the SAGE Cyber Security team would be glad to help.