# When the Grid Goes Dark on Purpose: CISA and Australia's OT Isolation Playbook
The attack doesn't have to succeed to win. That's the uncomfortable truth embedded in new joint guidance from CISA and Australia's Cyber Security Centre — a document that assumes adversaries are already inside the network and asks a harder question: can you survive cutting yourself off from everything?
"CI Fortify – Advice for Isolating Vital Systems" landed Tuesday, and it's not a vulnerability patch notice or a threat advisory. It's a continuity manual for critical infrastructure operators who may one day have to amputate a limb to save the patient.
## Designed for the Scenario Nobody Wants to Plan For
Most OT security guidance targets prevention or rapid detection. This document starts from a different premise: your corporate network is compromised, your vendor remote access is suspect, your cloud connections are a liability — now what?
The answer CISA and ACSC give is methodical and physically demanding. Organizations are told to build actual isolation points into their infrastructure before a crisis, not as a response to one. "Planned physical separation of vital systems from all other networks and systems is a pre-requisite for physical isolation," the guidance states plainly.
That framing matters. You can't isolate what you haven't pre-engineered to isolate. A power utility that has never disconnected its SCADA environment from corporate IT — even in a test — has no reliable way to do it under fire, on a timer, with an adversary potentially watching.
The steps the document outlines follow a logical sequence that OT teams have heard in pieces before, but rarely assembled into a single operational doctrine:
The graduated isolation piece is underappreciated. It means not going from fully connected to fully dark in one switch-throw. It means having a playbook for "cut vendor access first, then cloud telemetry, then corporate IT, then peer utility connections" — each step tested, each dependency mapped in advance.
## The Volt Typhoon Shadow
This guidance didn't emerge from a vacuum. The timing follows roughly 18 months of sustained public reporting on Volt Typhoon — the Chinese state-backed group that FBI Director Christopher Wray described in early 2024 as pre-positioning inside US critical infrastructure not for espionage, but to enable disruptive attacks on water, power, and communications during a future conflict.
That's the adversary model this document is quietly written for. Not ransomware crews after a payout. Not opportunistic scanning. Nation-state actors with years of patient access and a specific operational trigger in mind.
When CISA says operators need to "operate in isolation for an extended period," they're describing something closer to wartime continuity of operations than incident response. Extended isolation isn't a temporary measure while you kick out a ransomware affiliate. It's a sustained posture that assumes the external network environment remains hostile — or unavailable.
Australia's inclusion here is pointed. The Five Eyes alliance has been unusually direct in the past two years about attributing Chinese cyber operations, and Canberra has its own critical infrastructure concerns around port facilities, energy grids, and telecommunications. A joint publication signals shared threat intelligence and, likely, shared operational lessons from exercises neither government has publicized.
## The Honest Part About What Isolation Breaks
To their credit, CISA and ACSC don't pretend isolation is free. The guidance lists the operational and security risks that "CI Fortify" introduces, and they're real:
Patch gaps. An isolated OT environment can't receive automatic updates. Vulnerabilities that would be patched in hours on a connected network sit unaddressed — potentially for months. This is the classic OT tradeoff accelerated to its extreme.
Reduced external visibility. Your threat intelligence feeds, your cloud-based SIEM, your vendor's remote monitoring — all of it goes dark. You're flying on local sensors and logs only.
Removable media risk. When the USB drive becomes the primary means of moving data in or out, adversaries know it. Infected thumb drives have compromised air-gapped networks before — Stuxnet made this famous, but it's been a technique in the toolkit long before and after.
These aren't afterthoughts. They're conditions that isolated organizations have to plan mitigations for: local patch staging, on-premises logging infrastructure, strict removable media controls and scanning. Organizations that build an isolation capability without building those mitigations have traded one attack surface for another.
## HackWire Analysis
The publication of this guidance marks something of an institutional acknowledgment that the OT security conversation has shifted permanently from "prevent intrusion" to "assume breach and contain."
That's a maturation, not a defeat — but it's one a lot of critical infrastructure operators aren't ready for. The guidance document is well-structured, but it asks organizations to do things that require years of lead time: redesigning network architectures, negotiating isolation procedures with peer utilities and schedulers, training operators to run manual processes they've never touched in normal operations.
The peer dependency problem in particular deserves more attention than it's getting. A water utility can isolate its own SCADA environment. It cannot isolate the regional grid it depends on for power, or the chemical supplier whose delivery schedule feeds into its treatment process, or the municipal IT network that shares a fiber run. The guidance tells organizations to "identify and work through critical dependencies with impacted peers" — which is the right answer, but it implies a level of cross-sector coordination that doesn't currently exist at scale in most regions.
The most underreported risk here is that published isolation guidance is also a roadmap for adversaries. If CISA is telling utilities to build isolation points at vendor remote access boundaries, Volt Typhoon-aligned groups now know that's where defenders will sever access first — and can plan accordingly. This isn't an argument against publishing the guidance. It's an argument for actually executing the plan before the adversary does their own version of it.
Defenders in the energy, water, and transportation sectors should treat this document as a readiness audit checklist. The question isn't whether isolation procedures exist on paper. It's whether anyone in the organization has ever actually drilled one — end to end, including the manual fallback procedures, with the systems that would be needed actually disconnected. Most haven't. That gap is the real exposure.
— HackWire Editorial
## Related Coverage