Full Report
Critical infrastructure operators need to assume hackers will breach their networks and prepare to keep essential services running through an attack, top U.S. and Australian cybersecurity officials said. The warning reflects a growing concern that adversaries are pre-positioning themselves to disrupt the systems that sustain daily life, while AI accelerates their ability to find and…
Analysis Summary
# Best Practices: Resilience-Based Cyber Planning for Critical Infrastructure
## Overview
These practices address a fundamental shift from "perimeter defense" to **"operational resilience."** The focus is on "fighting through compromise"—assuming an adversary (particularly state-sponsored actors using "living off the land" techniques) has already breached the network. The goal is to ensure that even during a successful cyberattack, essential services sustain delivery to the public and national economy.
## Key Recommendations
### Immediate Actions
1. **Identify Critical Assets (Not just sectors):** Move beyond labeling your organization as "critical." Identify the specific individual assets and data flows that sustain your most essential functions (e.g., a specific valve controller, a specific billing database).
2. **Network Segmentation:** Immediately isolate Operational Technology (OT) from Administrative/Enabling systems. Air-gap or strictly gate-keep the systems that control energy, water, or safety mechanisms.
3. **Cross-Sector Dependency Mapping:** Identify which other infrastructure sectors your assets depend on (e.g., if the local power grid fails, how does it impact your water treatment ability?).
### Short-term Improvements (1-3 months)
1. **Risk-Based Patching (AI-Aware):** Shift away from patching based solely on CVSS severity scores. Prioritize vulnerabilities that are highly exposed to the internet and those that AI-automated tools are currently exploiting.
2. **Business Impact Continuity Planning:** Draft procedures for "fighting through" an attack. This includes defining how to operate in a "degraded mode" where some IT systems are down but OT remains functional.
3. **Joint Exercises:** Conduct tabletop exercises with vendors and international partners (if applicable) to test how dependencies react during a synchronized disruption.
### Long-term Strategy (3+ months)
1. **"Secure by Design" Culture Change:** Engage the Board and CEO to accept planned service interruptions for security hardening. Prioritize security over 24/7 availability for non-essential upgrades to prevent catastrophic unplanned outages.
2. **Resilience Investment:** Shift budget from simple prevention tools to rapid recovery and automated failover systems for essential functions.
3. **Customer Expectations Management:** Develop a communications strategy to prepare customers/citizens for necessary downtime required to perform deep-security maintenance.
## Implementation Guidance
### For Small Organizations
* **Focus on Visibility:** Focus on knowing every device on your network. You cannot protect or isolate what you cannot see.
* **Use Free Resources:** Leverage CISA’s "CI Fortify" guidance and free scanning tools to identify the most exposed entry points.
### For Medium Organizations
* **Prioritize OT Isolation:** Invest in industrial demilitarized zones (IDMZs) to ensure that a breach in the corporate email system cannot reach the machinery or service delivery layer.
* **Dependency Audits:** Conduct audits of U.S. and international software dependencies to understand where a supply chain failure might cripple operations.
### For Large Enterprises
* **Automated Response & AI Defense:** Use AI to match the speed of AI-driven exploits, focusing specifically on protecting the "crown jewel" assets identified in your mapping.
* **Executive Leadership:** Mandate regular briefings where cyber defenders report directly to the board regarding the trade-offs between system availability and security posture.
## Configuration Examples
* **Network Micro-segmentation:** Configure VLANs and Firewalls to deny all traffic between IT and OT by default (*Deny All*), allowing only specific, authenticated, and encrypted protocols required for operation.
* **Multi-Factor Authentication (MFA):** Enforce phishing-resistant MFA (such as FIDO2/WebAuthn) for all access points to critical asset controllers.
## Compliance Alignment
* **CISA CI Fortify:** Core alignment with CISA’s initiative for critical infrastructure resilience.
* **NIST Cybersecurity Framework (CSF) 2.0:** Focus on the "Govern," "Detect," and "Recover" functions.
* **ISO/IEC 27001:** Specifically regarding incident management and operational continuity.
## Common Pitfalls to Avoid
* **The "Compliance" Trap:** Thinking that being compliant with standards equals being secure against targeted state-sponsored actors.
* **Over-reliance on Prevention:** Spending 100% of the budget on firewalls and 0% on "fighting through" a breach that has already occurred.
* **Ignoring Dependencies:** Assuming your systems will work if the third-party cloud or power utility they rely on fails.
## Resources
* **CISA CI Fortify Guidance:** [hXXps://www.cisa.gov/resources-tools/programs/critical-infrastructure-resilience]
* **McCrary Institute Cyber Focus Podcast:** [hXXps://mccraryinstitute.com/cyber-focus-podcast/]
* **Australian Cyber Security Centre (ACSC) Essential Eight:** [hXXps://www.cyber.gov.au/acsc/view-all-content/essential-eight]