CISA Is Telling Critical Infrastructure to Practice Disconnecting Before a Crisis

CISA
Written By:
IndustryTrends
Published on
Updated on

Critical infrastructure organizations are being urged to prepare for cyber incidents in advance and rehearse, rehearse, rehearse. That even means an option many organizations still consider a last resort - knowingly severing sections of the network before the attacker can go any further.

This is becoming a key component of Cyber Incident Response. CISA has urged critical infrastructure owners to consider isolation and manual fallback options and processes to continue operations in the absence of trusted digital systems. The point is clear: when the network goes down, there shouldn't be the first time anyone finds out what doesn't work.

Isolation Is No Longer an Emergency Button

Network isolation was once considered an extreme containment measure to use for years.

Should ransomware proliferate across a hospital, utility, or transport network, defenders may shut down affected systems to prevent further harm. The issue was that the effects of operating were not always known beforehand.

A CIP cannot just pull the plug and wait. Patients still need to be cared for in hospitals. Water systems need to function. The energy networks must be stable. Transport operators must have a means of communication for their employees and passengers.

This means that isolation must be a planned operational capability rather than a technical response.

Organizations must understand which systems can be isolated, which systems must stay on, and which mechanisms will replace the usual connectivity when it fails.

Manual Workarounds Are Becoming a Cybersecurity Control

Digital transformation has rendered critical infrastructure more efficient, while also making it more reliant on connected systems. When those systems go down, organizations require an alternative way to function.

For example, this might include paper-based records, offline contact lists, manually managed equipment, or communication channels.

While these measures might seem like old-fashioned solutions compared to AI-powered security systems and advanced monitoring tools, they could prove invaluable during a critical incident.

Ransomware attacks can not only raise a cybersecurity issue. Can cause a business continuity issue within minutes.

Even a technically successful containment decision can lead to unnecessary disruptions if employees don't know how to work without certain core applications.

Every Asset Cannot Be Treated the Same

Disconnection also makes organizations aware of their dependencies.

Some systems may be rather easily isolated. Others might be used to support a safety-related process or be linked to equipment that cannot be readily shut down.

That's where asset intelligence comes into the picture. Responders must be aware of the function of the device, the systems that rely on it and the consequences of its removal.

That context should be there prior to the incident.

It is not a good time to discover that a seemingly insignificant server is used for an important business function when ransomware has become pervasive.

Good exercise designs can reveal these hidden dependencies without the stress of an actual attack.

Cyber Exercises Need to Break Things Deliberately

Even with many incident response exercises, meetings are still a significant part of the drill.

Teams talk about who would be engaged, how decisions would be escalated and what public statements would be made.

While these exercises are valuable, critical infrastructure organizations are also increasingly demanding practical exercises.

What if there's no remote access? Are operators able to operate critical equipment? Do backup communication channels work? Is there a way to access procedures when the document management system is down?

Exploring these scenarios can show uneaseful gaps. That is the point.

A planned exercise provides organizations with the opportunity to resolve those issues before an attacker does.

The Cloud Has Not Removed the Need for Offline Planning

Cloud platforms, software-as-a-service applications, and remote administration are becoming vital parts of modern infrastructure.

While that can help in some cases, it can also establish new dependencies.

An organization can find that the backup communication system uses the same identity provider as the compromised network. Employees can have offline procedures in an application that is no longer available. Emergency contacts can only be within the corporate email.

These are little things that can be big issues in the event of a breach. Cyber resilience thus involves considering independence and redundancy. Relying on the same infrastructure as the primary system for backup can't offer much protection.

Disconnection Needs an Exit Strategy Too

Containment is only the initial step in taking systems offline. It can be more difficult to return them safely.

Organizations must have assurance that hacked accounts are secure, malware has been removed from the system, and the system is clean before reconnecting it to the wider network.

Reconnecting too soon will allow the attacker to reconnect. If you wait too long, it can disrupt your operations.

That means recovery and isolation planning are essential. Teams should be aware of the system restoration order and the validation and monitoring required.

Resilience Means Knowing How to Operate Without the Network

The key takeaway from CISA's strategy is that cybersecurity is inseparable from operational resilience.

Prevention is not always effective for critical infrastructure operators. Some attacks will get through. Credentials will be compromised. Systems may need to be isolated quickly.

The best-equipped organizations for those times may not be the ones with the most advanced security technology.

They might be the ones who have already experienced situations in which technology is unavailable. Disconnection puts the question into perspective: Can we still function safely if part of the network is not reliable?

Ultimately,  that could be the most important incident-response question of all for critical infrastructure.

logo
Analytics Insight: Top Tech & Crypto Publication | Latest AI, Tech, Crypto News
www.analyticsinsight.net