Security guidance is usually read for its controls. It is more informative read for its assumptions, because the assumptions record what the authors have concluded is no longer worth arguing.
CI Fortify, published on 28 July 2026, offers advice on isolating vital systems, and asks operators to prepare for running them disconnected for extended periods. The framing sits alongside repeated warnings that state-sponsored groups — Salt Typhoon and Volt Typhoon among them — remain a threat to electricity, water and communications.
Three Postures, In Sequence
The first posture was exclusion: keep intruders out, and treat a breach as a failure. The second was detection and response: assume compromise is possible, and compete on how fast you find it. Guidance of this kind describes a third: assume compromise may already have happened and may not be reversible on a useful timeline, and ensure the essential function survives anyway.
That is not defeatism. It is the same reasoning that produced backup power for hospitals. Nobody treats a generator as an admission that the grid is hopeless.
What It Asks Of An Operator
Isolation is easy to write down and hard to do. Modern operational technology has accumulated dependencies on remote vendor support, cloud-based monitoring, licensing checks and telemetry pipelines. Cutting external connectivity means discovering which of those the plant genuinely needs to run — and the honest answer is usually unknown until it is tested.
Which is why the emphasis on testing is the operative part of the document. A plan for isolation that has never been exercised is a hypothesis about your own dependencies, and hypotheses of that kind are usually wrong in at least one expensive way.
This is a standards file rather than an incident file. Compiled from the published framework and public reporting, listed below. Corrections: corrections@forensicpost.com.