Skip to main content
Straife
High-voltage transmission lines at sunset

Plan to Be Cut Off: What CISA's CI Fortify Initiative Asks of Infrastructure Operators

Straife

Michael Clarke

May 14, 2026

On May 5, 2026, the Cybersecurity and Infrastructure Security Agency announced CI Fortify, an initiative directing critical infrastructure owners and operators to prepare for a specific and uncomfortable scenario: geopolitical conflict in which adversaries are actively targeting operational technology networks while communications infrastructure is degraded at the same time.

The initiative's core planning assumption deserves to be read slowly. It is that in a conflict scenario, a threat actor already holds some level of access to your OT network, and you cannot count on outside help to restore it.

That is not a warning about what might happen. It is an instruction to plan on the basis that it already has.

From Keeping Them Out to Operating Through It

Most critical infrastructure security programs are built around prevention and detection. Perimeter controls, network monitoring, threat intelligence, incident response retainers — the architecture assumes that the objective is to stop an intrusion, and that when one occurs, external resources will be available to help contain and remediate it.

CI Fortify inverts both assumptions. It asks operators to design for continuity of essential services under conditions where prevention has already failed and external support is unavailable. The relevant question is no longer whether a nation-state actor can get into the control environment. It is whether the utility can keep delivering water, power, or fuel for a sustained period while that actor is inside it.

This is a meaningful shift in what the federal government is asking of operators, and it follows a year in which the theoretical became demonstrable.

The Degraded Conditions Operators Are Asked to Assume

The guidance directs planning against a combination of failures that most continuity plans treat as mutually exclusive:

Compromised OT networks, where the control systems themselves cannot be trusted and manual or degraded-mode operation may be necessary. Lost or unreliable communications, removing the assumption that dispersed sites, control rooms, and leadership can coordinate in real time. Unavailable vendors, where the integrators and OEMs who normally provide emergency support are themselves under attack or unreachable. Third-party and business-network outages, including the enterprise IT systems that billing, scheduling, and logistics depend on.

The combination is the point. Any one of these is a manageable contingency. Together they describe an operating environment that very few utilities have ever rehearsed.

Isolation as a Deliberate Capability

The most operationally demanding element of CI Fortify is its treatment of disconnection. Operators are urged to develop isolation and recovery capabilities — the ability to proactively sever connections to business networks, third-party services, and vendor links while continuing to deliver essential services.

For most organizations this capability does not currently exist in any meaningful sense. Disconnection is treated as a catastrophic last resort, undertaken in a panic, with no clear picture of which dependencies will break. CI Fortify asks operators to convert it into a rehearsed, reversible, and documented procedure — one that can be executed on a defensible timeline by staff who have practiced it.

Getting there requires knowing, with precision, which functions depend on which external connections. Most dependency maps are aspirational documents rather than tested ones.

A Ninety-Day Readiness Agenda

For operators asking what to do with this guidance, five actions are achievable in a quarter and produce evidence of good-faith engagement:

  • Run a manual-operations drill in which the control system is assumed compromised and untrusted. Measure how long essential service delivery can be sustained, and where it fails first.
  • Establish and test out-of-band communications for leadership, control room staff, and field crews that do not traverse the primary corporate or telecom infrastructure.
  • Build a validated vendor-dependency map identifying every external party whose availability is assumed by an existing recovery procedure, and plan for each being unreachable.
  • Draft delegation-of-authority documents that let site-level staff make isolation and shutdown decisions when leadership cannot be reached.
  • Rehearse reconnection. Restoring service after deliberate isolation is materially harder than isolating, and it is the phase most plans ignore entirely.

The Bigger Picture

CI Fortify is not binding regulation, and operators may be tempted to treat it accordingly. That would be a mistake for reasons that have nothing to do with regulatory enforcement.

Guidance of this kind establishes a federal baseline of reasonable conduct, and baselines are what get cited afterward — in regulatory examinations, in insurance coverage disputes, in shareholder litigation, and in congressional testimony. An operator that experiences a destructive attack in 2027 and cannot show it engaged with guidance published in May 2026 will be answering a difficult question about why not.

The more substantive point is that the federal government has now formally priced in the possibility of a destructive nation-state cyberattack on U.S. critical infrastructure as a near-term contingency rather than a tail risk. Boards that have not adjusted their own assumptions accordingly are working from an outdated threat model.