%3Aquality(100)&w=3840&q=75)
CI Fortify international guidance for critical infrastructure
Isolate Systems Without Interrupting Operations
Isolate Systems Without Interrupting Operations
The international strategic advisory "CI Fortify – Advice for Isolating Vital Systems" was published July 28, 2026, by six allied agencies. It gives critical infrastructure operators a clear directive: pre-engineer the ability to isolate OT networks and sustain essential operations under adversarial conditions. Isolation alone is not the answer. Coordinated communications through that isolation is.
200+
Cyber incidents affecting UK critical national infrastructure managed by NCSC-UK in the 12 months to May 2026 — 75 percent linked to state actors.
3,200+
Cyber incidents responded to by the Canadian Centre for Cyber Security in 2025–2026 affecting federal and critical infrastructure targets
6
Allied agencies around the world co-issuing CI Fortify — making it the most broadly endorsed critical infrastructure cyber resilience directive published to date.
The Situation
Isolation Is the Guidance. Staying Operational Is the Requirement.
CI Fortify was issued as state-sponsored actors actively target critical infrastructure across allied nations to cause widespread system disruption. The guidance reflects a hard reality: operators must be ready to isolate OT systems and continue operating through a prolonged outage. Isolation creates a new problem, however. How do teams coordinate when the network they relied on is unavailable or compromised? The answer is a communications layer that exists outside the compromised environment.
Coordination Can't Run on Compromised Infrastructure
Email, collaboration suites, and VoIP depend on the enterprise network and identity systems, the first assets an attacker controls or monitors.
People Must Be Reached in Minutes
Operators, engineers, leadership, and mutual-aid partners must be alerted, mustered, and tracked across sites, including staff without corporate desks.
Coordination Extends Beyond the Organization
Incidents involve state agencies, federal partners, and neighboring utilities. Those channels must be secure, interoperable, and auditable.
The Guidance Landscape
Aligned Across Borders
CI Fortify is a joint framework, but each participating jurisdiction has also enacted domestic legislation and issued national advisories that reinforce and extend it. Understanding both the joint guidance and the national context is essential for operators identifying their compliance obligations. BlackBerry® Secure Communications delivers a portfolio designed for the isolated and degraded network conditions that CI Fortify advises, and offers solutions that meet the unique international requirements of each issuing agency.
Led by ASD, co-issued with CISA, NCSC-UK, CCCS, NCSC-NZ, and the FBI
CI Fortify is the most broadly endorsed critical infrastructure cyber resilience directive published to date. Led by the Australian Signals Directorate and co-issued by five allied agencies across four nations, it provides operators of power grids, water systems, telecommunications networks, and transportation infrastructure with practical steps for isolating vital OT systems from all other networks in the event of a cyber incident or geopolitical crisis — and for operating in that isolation for an extended period.
Key Requirements
Identify critical OT systems and map all network connections to enable deliberate isolation
Pre-engineer isolation capability to operate without IT network dependency for an extended period
Develop and test plans for manual and alternative SCADA operation under isolated conditions
Maintain secure out-of-band communications capability for coordination during isolation
Establish interoperable channels with national authorities and sector partners for reporting and coordination
%3Aquality(100)&w=3840&q=75)
Free Download
Is Your Team Ready to Coordinate Through an Isolation Event?
Get the CI Fortify Readiness Checklist, a self-assessment covering personnel accountability, shift coordination, and reporting to state and federal partners when the network goes down.
Get the checklistThe BlackBerry Response
A Communications Layer that Remains Trusted When Nothing Else Is
BlackBerry® solutions keep critical operations connected, out-of-band, and at government-grade assurance when primary networks cannot be trusted.
%3Aquality(100)&w=3840&q=75)
Trust Communications, Not the Network
BlackBerry SecuSUITE delivers encrypted voice calls, secure messaging, and group communication on the smartphones your teams already carry, independent of enterprise email, directories, and collaboration platforms. Governments and security-critical organizations rely on its certified end-to-end encryption. It operates out-of-band, independent of anything that authenticates against your enterprise network, and deploys on standard iOS and Android devices. No exotic hardware required.
%3Aquality(100)&w=3840&q=75)
Reach Everyone, Verify Everyone
BlackBerry® AtHoc® is the critical event management platform that manages the people dimension of a crisis: mobilizing staff to manual stations, verifying safety, and keeping state and federal partners informed. It reaches everyone across mobile, SMS, voice, email, desktop, and siren or IPAWS integrations, with delivery tracking on every message. Two-way check-in confirms who is safe, on-site, or unreachable in real time, and AtHoc® Connect links your organization directly with government agencies and partner operators.
%3Aquality(100)&w=3840&q=75)
Harden the Endpoints that Carry the Mission
Incident communications ride on mobile devices. BlackBerry® UEM ensures those devices are managed, encrypted, and compliant before the incident, so they can be trusted during it. It enforces policy, containerization, and certificate management for every device running BlackBerry SecuSUITE and BlackBerry AtHoc, and can lock down or wipe lost or suspected devices the moment an incident goes active. Critical communications stay separated from personal and general-purpose apps.
The Portfolio in Action
Before, During, and After the Incident
How BlackBerry SecuSUITE, BlackBerry AtHoc, and BlackBerry UEM work together across a live event.
Prepare
BlackBerry UEM hardens the device fleet. BlackBerry AtHoc maintains rosters and escalation paths. BlackBerry SecuSUITE is provisioned to response teams. Drills run over the same channels used in a real event.
Alert
BlackBerry AtHoc alerts operators, security, and leadership across every channel, with delivery confirmation. Incident command stands up on BlackBerry SecuSUITE, off the potentially compromised network.
Coordinate
Manual operations are coordinated over BlackBerry SecuSUITE encrypted voice and messaging. BlackBerry AtHoc tracks personnel at each site. BlackBerry AtHoc keeps state and federal partners synchronized.
Verify
Send verified all-clear and re-entry notifications through BlackBerry AtHoc. Auditable communication records support after-action review and regulatory reporting.
Why the World's Most Critical Organizations Trust BlackBerry
Supported by decades of proven trust, industry-recognized certifications, and a resilient portfolio designed for sovereign, independent operations.
Decades of trust from governments, defense organizations, and critical infrastructure operators worldwide, deployed by 20 national governments and every G7 nation.
Independent certification across every primary allied market, including NIAP Common Criteria (US), NSA CSfC listing (US), NCSC CPA (UK), BSI (Germany/EU), Canada Secret CSE approval, NATO Restricted
Architecture built for the conditions CI Fortify describes, designed to work when the rest of the environment does not.
Sovereign by design with on-premises deployment, operator-held keys, and no dependency on vendor cloud infrastructure
Keep Reading
Go Deeper on Communications Continuity
Citations:
https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2025-2026 (CSE, government of Canada, June 29, 2026)
https://www.infosecurity-magazine.com/news/hostile-states-cni-75-percent-ncsc/ (Infosecurity Magazine, June 18, 2026)
Next Step
A 30-Minute Resilience Review
We map your current incident communications against the July 30 federal advisory and identify gaps. No obligation.






