# CISA Issues CI Fortify Network Isolation Guidance

The Cybersecurity and Infrastructure Security Agency (CISA), in coordination with allied international agencies including the UK's National Cyber Security Centre (NCSC), the Australian Signals Directorate (ASD), and the Canadian Centre for Cyber Security (CCCS), has released the CI Fortify framework. This guidance urges critical infrastructure operators, including federal agencies and their contractors, to enhance network isolation and recovery capabilities to maintain operational resilience during cyber crises. While network isolation strengthens cybersecurity by limiting attacker lateral movement, it also introduces operational challenges such as potential shadow IT and reduced data synchronization efficiency. Procurement professionals and contractors supporting federal critical infrastructure should evaluate solutions that balance robust isolation with secure, efficient data sharing to comply with evolving cybersecurity expectations and sustain mission-critical operations.

- **Why this matters:** Federal agencies must integrate network isolation strategies that align with CI Fortify guidance to mitigate cyber risks while maintaining operational continuity.
- Contractors providing cybersecurity and IT solutions should prioritize offerings that enable secure data synchronization and recovery in isolated network environments.
- Organizations can leverage this guidance to inform procurement requirements, emphasizing both security and operational efficiency in critical infrastructure contracts.
- Collaboration with international cybersecurity standards bodies like NIST and allied agencies highlights the growing global alignment on critical infrastructure protection, influencing future procurement standards.

**Jurisdictions:** federal
**Industries:** Public Safety, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** September 18, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Australian Signals Directorate (ASD)
- Canadian Centre for Cyber Security (CCCS)
- National Cyber Security Centre (NCSC)
- National Institute of Standards and Technology (NIST)

### Vendors
- Connecting Software (software solution provider)

### Key Quotes
> Operators of U.K. critical national infrastructure (CNI) must not only take note but, as we have said before, act now.
> — Jonathon Ellison, Senior Official, National Cyber Security Centre (NCSC)

### Sources
- [
        Network isolation: Why CI Fortify’s new guidance presents both risks and opportunities for federal agencies and contractors | Federal News Network](https://federalnewsnetwork.com/commentary/2026/09/network-isolation-why-ci-fortifys-new-guidance-presents-both-risks-and-opportunities-for-federal-agencies-and-contractors) - federalnewsnetwork.com