CISA CI Fortify: Planning for Cyber Emergencies When Connectivity Itself Is the Target
Analyzing CISA's CI Fortify initiative: preparing critical infrastructure organizations for total telecommunication and internet severance.
This article is part of our Week of May 7, 2026 Security Roundup.
CISA has launched CI Fortify — a new initiative requiring critical infrastructure organizations to plan for cybersecurity emergencies including scenarios where internet access, telecommunications, and technology services are completely severed. The guidance arrives as CISA returns from the longest US government shutdown in history.
Two Core Objectives
Isolation: operate securely with no external connectivity — authentication, monitoring, and security controls must function without cloud services or internet access. Recovery: defined, tested procedures for restoring operations after a geopolitically motivated attack that targets connectivity itself.
The Threat Model Has Changed
CI Fortify explicitly names geopolitical crisis scenarios — nation-state adversaries targeting multiple interconnected infrastructure systems simultaneously. This is a departure from the generic cybercriminal framing of previous CISA guidance and reflects a broader shift toward resilience-by-design under the assumption that connectivity cannot be guaranteed during an active incident.
OT Focus
CI Fortify builds on CISA's April 2026 OT zero-trust guidance. Industrial control systems, SCADA, and PLCs are in scope. A 2025 DoD IG audit found the Navy made minimal progress mitigating infrastructure cyber vulnerabilities — CI Fortify appears to be a direct policy response.
Questions Your Organization Should Be Able to Answer
Can your authentication systems function without internet access? Do you have local backups of configurations and credentials? Are your incident response playbooks written for scenarios without cloud monitoring? Have you tested recovery with primary communication channels down?
References: Federal News Network | CISA announcement | DoD IG audit