# When to Pull the Plug: CISA's New Playbook for Isolating Industrial Systems Under Attack


The hardest decision in operational technology security isn't patching or detection — it's knowing when to deliberately break your own infrastructure to stop something worse from happening.


That's the core of new joint guidance released this week by CISA and Australia's Cyber Security Centre, aimed at critical infrastructure operators who manage industrial control systems, SCADA networks, and the other operational technology that keeps power flowing, water treated, and pipelines running. The message, stripped of bureaucratic language: know in advance what you're going to cut, how you're going to cut it, and who's authorized to make that call, before an adversary forces you to improvise under pressure.


## The Isolation Problem No One Wants to Talk About


Isolating OT during an active cyberattack sounds straightforward until you're standing in a control room watching process historians go dark and realizing that the "isolated" network segment still talks to six other systems through a historian you forgot existed.


The CISA-ACSC guidance targets exactly this — the gap between what organizations *think* their OT isolation capabilities are and what actually works when someone is actively moving through their environment. Most critical infrastructure operators have documented their network architecture. Fewer have actually tested whether they can execute an emergency segmentation under operational conditions, with a real-time process that can't simply be paused like an IT workload.


The guidance emphasizes what practitioners call "resilience by design" — pre-positioning isolation capabilities rather than scrambling to implement them mid-incident. That means documented manual override procedures, tested out-of-band communication paths for operators who've just lost their normal channels, and — critically — pre-defined thresholds for *when* isolation actually triggers. That last piece is where most organizations fail.


## The Clock Problem


Colonial Pipeline is the case study that every OT security professional now has to reference, because it illustrated something the industry had theorized about for years: organizations will shut down operational systems far more aggressively than necessary if they don't have clear decision frameworks going in.


Colonial's IT team made a defensible choice in 2021. The ransomware hit their business systems, not the pipeline OT directly, but lacking clear visibility into what was compromised and what wasn't, they pulled the shutdown trigger proactively. The result was the largest fuel disruption in U.S. history — not because attackers broke the pipeline, but because the defenders couldn't confidently answer a simple question: *is the OT clean?*


The new guidance tries to build the architecture that makes that question answerable. Specifically, it pushes operators to define "safe states" for their industrial processes — configurations where systems can continue operating in a degraded but secure mode, or can be safely stopped without catastrophic consequences. A water treatment facility running with manual chlorination oversight is in a different risk position than one that's completely dark. Knowing what "degraded operations" looks like before the incident means operators aren't choosing between full operation and full shutdown.


## What Joint US-Australia Guidance Actually Signals


When the U.S. and Australian governments co-publish an advisory like this, it's rarely coincidental. The Five Eyes and their adjacent partners tend to coordinate guidance releases around shared intelligence — threat activity that both governments are tracking and want operators to start hardening against before it becomes a headline.


The current threat picture for critical infrastructure OT isn't theoretical. CISA has issued warnings about Volt Typhoon — the Chinese state-sponsored group that has been pre-positioning access in U.S. critical infrastructure specifically for disruptive capability — throughout 2024 and into this year. The Australian Signals Directorate has documented analogous activity targeting Pacific-adjacent infrastructure. This guidance lands in that context, and operators should read it that way.


Pre-positioned access means adversaries are already inside environments, waiting. The isolation playbook matters more when the attacker isn't rushing — when they've had months to map your OT network, understand your process dependencies, and identify the segments that, if isolated, would cause the most operational damage.


## The Manual Fallback Gap


One section of the guidance that deserves more attention than it usually gets: the emphasis on manual operations capability. CISA and ACSC are explicitly recommending that operators train staff to run processes without digital control systems, maintain physical procedure documentation that doesn't depend on network-connected systems, and exercise those manual capabilities regularly.


This is uncomfortable for many industrial operators because manual operations are slower, more error-prone, and in many modern facilities, barely practiced at all. Automation has made OT environments dramatically more efficient and dramatically more brittle. A water treatment plant built 30 years ago with manual valve controls and analog gauges has isolation options that a modern fully-automated facility doesn't.


The guidance doesn't sugarcoat this. Organizations that have automated away manual fallback capabilities have a harder problem to solve, and they should know it.


---


## HackWire Analysis


The release of this guidance fits a pattern that's worth naming explicitly: governments issuing OT security advisories *after* the threat is already well-established in environments they're trying to protect.


Volt Typhoon's activity in U.S. critical infrastructure was first publicly disclosed in May 2023. CISA has spent the intervening two-plus years issuing a cascade of advisories, alerts, and guidance documents about the group's TTPs. The organizations that were going to patch their Cisco routers and review their VPN configurations have mostly done so. This new OT isolation guidance likely lands for a similar audience — operators who are already engaged enough to be reading CISA advisories.


The harder problem is the long tail: the mid-size municipal water authority that has one IT person, the rural electric co-op running decade-old SCADA on unsegmented networks, the port operator whose OT vendor told them the system "isn't connected to anything." These organizations exist in large numbers, and they're not the audience that downloads 40-page guidance documents.


What the guidance gets right is the framing around decision-making frameworks. The worst outcomes in OT incidents come not from the initial intrusion but from poorly-executed response — over-isolation that causes more damage than the attack, under-isolation that lets ransomware spread to engineering workstations, or total operational paralysis because no one had authority to make the call. Pre-defined safe states and isolation thresholds are operationally expensive to develop but they're the difference between a managed degradation and a cascading failure.


For defenders reading this: the exercise value is the point. Don't read the guidance, file it, and check the box. Run the tabletop. Find the historian server no one remembered. Discover which of your manual procedures actually work before someone forces you to use them under a deadline.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)