IC Technology & Surveillance — 2026-05-09
CISA Warns Critical Infrastructure Operators to Prepare for Prolonged Cyber Outages
CISA published CI Fortify this week, a guidance initiative directing critical infrastructure operators to prepare to deliver services during cyberattacks by proactively isolating from third-party dependencies and operating without reliable internet access, The Record reported. CISA Acting Director Nick Andersen said the effort requires organizations to segment and isolate operational technology networks and restore compromised systems while cut off from outside connectivity. Andersen told reporters the initiative was "not in response to any particular nation-state actor," though CI Fortify's webpage cites Volt Typhoon prepositioning operations and alleged Russian cyberattacks on Polish OT networks among the motivating threats. He also cited accelerating AI-enabled offensive capabilities as a primary driver of the effort.
AnalysisCI Fortify shifts official doctrine from eradication to blast-radius limitation, operationally accepting persistent adversary access as a chronic condition. That pivot implicitly concedes evicting Volt Typhoon is not a realistic near-term outcome, even as the administration maintains that policy rhetorically. AI-accelerated offensive capabilities, per Acting Director Andersen in The Record, extend the guidance's urgency well beyond any single nation-state. The resilience framing may instead be political insulation, allowing CISA leadership to redefine failure to evict entrenched actors as deliberate doctrine rather than operational shortfall. It is
very likely at least one U.S. critical infrastructure sector will report a publicly disclosed incident causing operational disruption within 60 days, though uneven sector disclosure tempers confidence.
1 sources
- CISA tells critical organizations to prepare for cyber outages - Federal News Network
View in full brief →