TL;DR. New national guidance now expects critical infrastructure operators to be able to run essential services for three months while completely cut off, from corporate networks, the internet and their own suppliers. It is advice rather than law, but it comes from the same agency that sets the cyber framework inside your CIRMP, so it moves the bar. The engineering to make isolation possible belongs to your operational technology and architecture teams. The part that is yours, and the part most operators have not touched, is the risk. Nobody has assessed where the organisation stands against this expectation, decided who owns it, or built a position you could put in front of a board or a regulator. An expectation you have not assessed is a risk you are not managing.
Not three hours. Not until the incident responders arrive. Three months. That is the target ASD quietly set for critical infrastructure in late July, and it deserved far more attention than it got.
The guidance is called CI Fortify, Advice for Isolating Vital Systems. It was led by ASD’s Australian Cyber Security Centre and published jointly with the United States CISA, the FBI, the United Kingdom’s National Cyber Security Centre and Canada’s cyber centre, after about a year of consultation with industry. What it asks is unusually concrete. Build the ability to isolate your vital operational technology from every other network during a cyber incident or a geopolitical crisis, and keep delivering the essential service while cut off. ASD’s revision is the part that puts a number on it: you should be able to run in complete disconnection for three months.
Why three months, and why now
The target sounds extreme until you look at what it is defending against. The agencies are candid that state-sponsored actors are increasingly not breaking in to steal and leave, they are pre-positioning, quietly establishing persistent access inside critical infrastructure so they can disrupt essential services at a moment of their choosing, often tied to broader geopolitical conflict. Add the ordinary business of ransomware, and the line between espionage and crime blurs. In that world, the ability to pull your operational core off the network and keep running is not paranoia, it is continuity.
There is a design problem underneath. Operational technology, the systems that actually move gas, generate and distribute power, and run the plant, was mostly built for reliability, availability and safety, not for defending against a modern adversary. For years it sat apart, connected to little beyond its own control room. Then efficiency arrived. Remote monitoring, vendor support, data flowing up to the corporate network and the cloud, all sensible, all valuable, and all of it quietly wiring the once-isolated core into the same world as everything else. CI Fortify is asking operators to be able to reverse that on demand.
Where the real work sits, and where it does not
It is tempting to read CI Fortify as an engineering problem, and a large part of it is. Building the separation points, re-architecting a flat network so it can actually be cut, keeping the plant running on manual or alternative control paths, that is demanding, specialist work, and it belongs to your operational technology and architecture teams. It is not where most operators are exposed, and it is not what this piece is about.
Where they are exposed is one step earlier. A new resilience expectation has just landed, and in most organisations nobody has yet assessed the business against it. No one has rated how far the current position sits from the three-month bar, placed that gap alongside the other hazards in the CIRMP, decided who owns it, or produced anything a board or a regulator would accept as evidence of where you stand. The wiring is a job for engineers. The risk, the risk that you cannot demonstrate you would keep running, and cannot show you are managing the gap, is a job for whoever runs risk. And that risk is live the moment the guidance is published, not the day the engineering finishes.
An expectation you have not assessed is a risk you are not managing. CI Fortify did not just create an engineering task. It put a new line on your risk register, and right now it is blank.
A blank line on the risk register
The uncomfortable part is what that blank line sits under. In the SOCI world your board attests to the Critical Infrastructure Risk Management Program. If operational resilience of this kind is a hazard you are expected to manage, and CI Fortify is a very clear statement that it is, then an unassessed gap is not a neutral absence. It is an unmanaged risk sitting beneath an attestation someone has already signed. The danger is not only that you might not be able to run for three months. It is that you cannot say, today, whether you could, and cannot show that you are doing anything about it. Boards and regulators have stopped accepting that there is a plan as the answer. The question now is whether you can evidence a position.
Where this lands for Australian energy and gas
Two things to be clear about. CI Fortify is guidance, not a new legal obligation, so nobody is going to fine you next quarter for failing the three-month test. But do not file it under optional. It was led by ASD, the same agency whose cyber framework sits inside your Critical Infrastructure Risk Management Program, and it speaks directly to the all-hazards duty you already carry under the SOCI regime, the obligation to identify and manage the hazards that could disrupt your asset. It also rhymes with the direction the financial regulator has taken with CPS 230, where the expectation is now that you can operate through the disruption of a critical service, and prove it. From every direction, the same message: resilience is no longer a plan in a drawer, it is a position you can evidence.
For operators already climbing toward AESCSF Security Profile 2 by 2028, this is the same discipline, not a new one. The enhanced obligations are driving at exactly this, the ability to show, with evidence rather than assertion, that you understand your risks and are managing them. CI Fortify simply adds a sharp new one to the list.
The real question for the board
So the question a board should ask is not whether the engineers have an isolation plan. It is whether anyone has assessed the organisation against this expectation, whether the gap is owned and prioritised against our other hazards, and whether we could put an evidenced position in front of a regulator tomorrow. That is a risk question, not an architecture one, and it is answerable now, long before the engineering is finished.
What to actually do
Treat CI Fortify as what it is, a new risk to assess, not only a project to build. Assess where you stand against the expectation and rate the gap honestly. Place it alongside the other hazards in your CIRMP so it is prioritised in context rather than in isolation. Give it a named owner. And turn it into a board-ready position with a costed case for the uplift, the uplift itself being work for your operational technology and architecture teams, or a delivery partner you choose, scoped and quoted separately. You are not being asked, at this stage, to have finished the engineering. You are being asked to know, and be able to prove, where you stand and that you are managing it.
Assessing the risk is the part that falls over, and the reason we exist
This is the work that quietly does not happen. Not because it is hard in the clever sense, but because assessing a new expectation, rating it, owning it, and keeping the position current and provable is relentless, and it lands on a team that is already full. So the guidance gets read, the engineering gets debated, and the risk itself, the assessed, prioritised, evidenced position, never gets built, until an auditor or an incident asks for it and it is too late to build calmly.
That is precisely what running risk as an operation is for. BayRisk does not draw your network or build your isolation points, that is for your architects and engineers. What we do is assess this expectation against your framework, prioritise it beside your other hazards, and keep a current, evidenced position your board can stand behind, so that when the question comes, from the board or the regulator, you have a defensible answer rather than a promise. The risk stays yours, it sits with your board and your accountable executive, exactly as the SOCI regime intends. The operation of assessing it and keeping it provable becomes ours. The engineering to close the gap is scoped and quoted on its own.
CI Fortify’s three-month target reads like an engineering challenge, and for your operational technology teams, in part, it is. But the question it really puts to the rest of the business is simpler and more immediate: have we assessed where we stand, do we own the gap, and could we prove we are managing it? The operators who come through this well will not be the ones who happened to finish the wiring first. They will be the ones who treated a new expectation as a risk from the day it landed, and always knew where they stood.
References
- CISA and partners, CI Fortify, Advice for Isolating Vital Systems (joint guidance led by ASD, 28 July 2026), cisa.gov
- Australian Signals Directorate, ASD’s Australian Cyber Security Centre, cyber.gov.au
- iTnews, ASD sets a three-month isolation target for critical infrastructure operators (28 July 2026), itnews.com.au
- Cyber Daily, ASD, CISA and partners release critical infrastructure security advice (29 July 2026), cyberdaily.au
- Security of Critical Infrastructure Act and the Critical Infrastructure Risk Management Program, Cyber and Infrastructure Security Centre, cisc.gov.au