Blueprint for Securing Critical Infrastructure Amid Cyber Threats
Recent cyberattacks targeting operational technology (OT) systems have highlighted the urgent need for effective isolation measures in critical infrastructure sectors. Amid rising threats, the Cybersecurity and Infrastructure Security Agency (CISA) has teamed up with Five Eyes security agencies from the US, UK, Australia, Canada, and New Zealand to release a comprehensive six-step framework aimed at guiding organizations in isolating their critical systems during cyber incidents. The guiding document, known as CI Fortify, outlines actionable strategies to minimize disruption and ensure vital services continue to operate in crisis scenarios.
Key to its findings, the report stresses that the ultimate goal is enabling continued operation of essential services even when isolated from broader networks.
A Six-Step Guide for Locking Down Systems
The cyber landscape has shifted significantly, with state-sponsored actors increasingly targeting critical systems that underpin everyday life, such as water distribution and power supply. The practical response for organizations often involves taking systems completely offline, as was the case with CAF Bank's recent suspension of online services due to vulnerabilities in third-party software, which hindered charities from processing payroll. Similarly, a coordinated cyber assault impacted several water utilities in Minnesota this week, showcasing the tangible risks.
This backdrop underscores the urgency for robust isolation strategies. The six-step process outlined in the guide begins with basic yet crucial tasks:
- Identify vital systems and networks
- Pinpoint critical customers
- Assess various levels of criticality and trust across networks
- Locate potential isolation points and understand system connections
- Establish effective separation and isolation points
- Develop and test an isolation plan
The initial steps focus on clarity: determine which systems are indispensable for operating essential services and establish delivery goals based on the requirements of top customers. This groundwork sets the stage for the more nuanced task of segmenting networks based on risk exposure.
Understanding the interconnections between critical networks and other systems is vital for developing a credible isolation strategy. Organizations must account for various connection types, especially those involving external vendors or cloud services. Each connection's trust level must be evaluated, and necessary protection mechanisms, like encryption, should be systematically implemented as per guidance.
Establishing Separation and Isolation Points
The guide suggests that while zero-trust networks aim to minimize isolation needs by inherently distrusting inter-device communication, defining clear isolation points remains critical. These isolation points serve a crucial role in containing attacks and limiting their potential operational impact.
Organizations should construct physical barriers around their vital systems to safeguard operational capabilities even when indirect connections to non-critical networks exist. This means ensuring no connectivity is permitted with non-OT networks and keeping essential resources, such as power and backup systems, within a protected environment not controlled by non-critical systems.
Strategies include hardening operational technology boundaries, fully segregating management and IT systems, and incorporating administrative controls such as VLANs and IP access lists. High-grade encryption is essential for protecting interconnections in environments where complete isolation isn't achievable, especially in organizations with extensive operational infrastructure.
Understanding Dependencies and Risks, Isolating in Phases
The complexity of threats necessitates a clear understanding of interdependencies between OT and non-OT systems, as failure to do so could lead to performance degradation during critical isolation periods. This includes managing shared resources optimally to prevent unforeseen outages or service quality drops.
Organizations should also devise a phased isolation approach to allow a progressive separation of systems while ensuring business operation continuity. The guide recommends specific steps to enhance isolation progressively:
- Remove remote access to OT systems via non-OT platforms
- Disengage on-site remote entry to OT systems from corporate systems
- Establish strict isolation for all connections between OT and non-OT environments
- Limit lower-priority connections between decentralized systems
- Realize complete isolation for OT environments and essential systems
The phased approach is highlighted as a proactive measure against emerging cyber threats, emphasizing that judiciously withdrawing access to OT systems can hinder attacks on vital operational technology and supportive infrastructures.