Four Agencies Just Told You to Pre-Build Your Isolation Plan. Thirty Minnesota Water Systems Are the Reason Why.
Updated: Aug 11
On July 28, CISA published a joint framework with the Australian Signals Directorate, the UK's National Cyber Security Centre, and the Canadian Centre for Cyber Security. It is called CI Fortify, and its subject is isolating vital systems.
Its central argument is one sentence long: isolation has to be engineered and tested before the attack, because it cannot be invented during one.
Two days earlier we published an audit of the Purdue reference architecture. The day before the advisory we published a list of what a small water utility should check on its PLCs that night. This morning we published a correction saying the Minnesota water incident we had sized at five systems was actually more than thirty.
We are not claiming we called this. Four agencies did not read our blog. But the advisory and our last week of work are describing the same problem from opposite ends, and the overlap is worth putting in front of the people who have to act on it.
What the advisory actually asks for
The checklist is short and it is not technology shopping. It is five pieces of homework.
Asset mapping. Know which systems are actually vital and know what they depend on. Not the asset register that was accurate in 2019 — the interdependencies, including the ones nobody documented because they were obvious to whoever built them and that person has retired.
Separation points. Decide in advance where the cut goes. A defined boundary between the systems that must keep running and everything else, chosen while you are calm.
Isolation mechanisms. Air gap, segmentation, or a controlled disconnection procedure — whatever your estate supports, decided and built ahead of time.
Manual fallbacks. Can the plant run without its digital dependencies? For how long? Who knows how?
Personnel readiness. The people on shift at 3am have to be able to execute the isolation without a conference call.
CISA also issued five ICS advisories the same day. The framework got the headlines and the individual advisories are the ones with the part numbers in them, so read both.
Why the framing matters more than the checklist
Every item on that list is something an operator theoretically already knows. The reason the advisory exists is that knowing it and having built it are different states, and almost nobody has built it.
The distinction the advisory is drawing is between isolation as a capability and isolation as an intention. Intention is "we'd pull the plug if it came to that." Capability is a documented cut point, a tested procedure, a fallback that has been run in daylight, and an operator on shift who has done it before. Under pressure, intention converts to a forty-minute argument about whether pulling the plug is an overreaction.
This is the same failure mode we described in the Purdue audit. The Purdue model is a good architecture and a bad compliance artifact, because a diagram showing clean levels is not evidence that the levels are separated in the building. The advisory is asking for the evidence.
The Minnesota version of this
Here is why we are not treating this as a routine advisory post.
Across 26 and 27 July, community water systems in Minnesota had their control environments attacked. We wrote it up at 02:57 UTC on July 28 — the same news cycle — with 21 indicators published free and no registration, including the 175.110.121.x cluster, and tied it to the CISA advisory AA26-097A guidance on Iranian-affiliated actors reaching programmable logic controllers. We said five systems. This morning we corrected that to more than thirty. We were early and right about the event and wrong about the size by a factor of six.
Those are not large utilities. A Minnesota community water system is a handful of staff, a SCADA package somebody's predecessor specified, and a budget that does not contain a line item for a segmentation project. Handing that operator a four-agency framework about pre-engineered isolation is correct advice and it is also, on its own, not usable. They will read "map your interdependencies" and have nowhere to start.
So the useful translation, for the smallest operators, is to work the list backwards — start at manual fallback, because it is the only item that costs no capital and it is the one that keeps water moving.
Can you run the plant on manual? Find out this week, on a scheduled morning, with the person who would have to do it. Write down what broke. That single exercise produces your asset map as a byproduct, because the things that stop working when you go manual are your critical dependencies, and the list you get from doing it is more honest than any list you get from asking.
Then the cut point. For most small water systems there is exactly one meaningful boundary, and it is between the control network and everything that touches the internet — the historian, the remote-access appliance, the vendor's support tunnel, the business LAN that shares a switch because it was there. You do not need a reference architecture to identify that. You need to know which cable it is and to have unplugged it once.
Personnel readiness at that scale is one page taped inside the panel door.
Where we stand
We hold 21 indicators from the Minnesota incident in our feed, free to anyone, no account required, and they are in the IP list our edge blocklist publishes. We have a standing watch on the actors named in AA26-097A. We do not have visibility into whether the attacks against the additional systems used the same infrastructure, and we are not going to pretend otherwise — the scale correction we published this morning came from reporting, not from our own telemetry, which is exactly the limit worth naming.
What we can say is that a joint advisory from four agencies is a gift to a small operator, because it converts "somebody should look at this" into "four governments say to look at this," and that is a sentence a plant manager can take to a city council.
Use it that way. The advisory is leverage before it is a checklist.
Confidence capped at 95%. The framework contents are from the CISA publication of July 28 and its partner agencies; the Minnesota incident details are from our own coverage of 27 and 28 July and subsequent reporting; the scale figure is reported, not independently verified by us.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=four-agencies-just-told-you-to-pre-build-your-isolation-plan-thirty-minnesota-water-systems-are-the




Comments