Skip to main content

Critical Infrastructure Under Attack

When Operational Technology Goes Offline, Coordination Can't

Recent cyberattacks on U.S. water utilities delivered a stark wake-up call. OT networks at critical infrastructure are prime targets for threat actors, and the risk is no longer theoretical. That's why CISA's July 28 CI Fortify advisory is a clear directive: prepare today to isolate vital OT systems and sustain essential operations. But isolation creates a new problem. How do operators coordinate when the network is no longer available?

The Situation

Isolation Is the Guidance. Staying Operational Is the Requirement.

The targeted water and wastewater utilities are now executing that isolation guidance under real conditions, not a tabletop exercise. In reported cases, operators lost automated monitoring and reverted to manual control to keep service running. Isolation alone is not resilience. Organizations must continue communicating, coordinating response efforts, managing operations, and reporting to state authorities and CISA, even when critical networks are offline. That guidance exposes three communications problems most continuity plans do not address.

Coordination Can't Run on Compromised Infrastructure

Email, collaboration suites, and VoIP depend on the enterprise network and identity systems, the first assets an attacker controls or monitors.

People Must Be Reached in Minutes

Operators, engineers, leadership, and mutual-aid partners must be alerted, mustered, and tracked across sites, including staff without corporate desks.

Coordination Extends Beyond the Organization

Incidents involve state agencies, federal partners, and neighboring utilities. Those channels must be secure, interoperable, and auditable.

Free Download

Is Your Team Ready to Coordinate Through an Isolation Event?

Get the CI Fortify Readiness Checklist, a self-assessment covering personnel accountability, shift coordination, and reporting to state and federal partners when the network goes down.

Get the checklist

The BlackBerry Response

A Communications Layer that Remains Trusted When Nothing Else Is

BlackBerry® solutions keep critical operations connected, out-of-band, and at government-grade assurance when primary networks cannot be trusted.

Trust Communications, Not the Network

BlackBerry® SecuSUITE® delivers encrypted voice calls, secure messaging, and group communication on the smartphones your teams already carry, independent of enterprise email, directories, and collaboration platforms. Governments and security-critical organizations rely on its certified end-to-end encryption. It operates out-of-band, independent of anything that authenticates against your enterprise network, and deploys on standard iOS and Android devices. No exotic hardware required.

Reach Everyone, Verify Everyone

BlackBerry® AtHoc® is the critical event management platform that manages the people dimension of a crisis: mobilizing staff to manual stations, verifying safety, and keeping state and federal partners informed. It reaches everyone across mobile, SMS, voice, email, desktop, and siren or IPAWS integrations, with delivery tracking on every message. Two-way check-in confirms who's safe, on-site, or unreachable in real time, and AtHoc® Connect links your organization directly with government agencies and partner operators.

Harden the Endpoints that Carry the Mission

Incident communications ride on mobile devices. BlackBerry® UEM ensures those devices are managed, encrypted, and compliant before the incident, so they can be trusted during it. It enforces policy, containerization, and certificate management for every device running BlackBerry SecuSUITE and BlackBerry AtHoc, and can lock down or wipe lost or suspected devices the moment an incident goes active. Critical communications stay separated from personal and general-purpose apps.

The Portfolio in Action

Before, During, and After the Incident

How BlackBerry SecuSUITE, BlackBerry AtHoc, and BlackBerry UEM work together across a live event.

Prepare

BlackBerry UEM hardens the device fleet. BlackBerry AtHoc maintains rosters and escalation paths. BlackBerry SecuSUITE is provisioned to response teams. Drills run over the same channels used in a real event.

Alert

BlackBerry AtHoc alerts operators, security, and leadership across every channel, with delivery confirmation. Incident command stands up on BlackBerry SecuSUITE, off the potentially compromised network.

Coordinate

Manual operations are coordinated over BlackBerry SecuSUITE encrypted voice and messaging. BlackBerry AtHoc tracks personnel at each site. BlackBerry AtHoc keeps state and federal partners synchronized.

Verify

Verified all-clear and re-entry notifications through BlackBerry AtHoc. Auditable communication records support after-action review and regulatory reporting.

Why the World's Most Critical Organizations Trust BlackBerry

Supported by decades of proven trust, industry-recognized certifications, and a resilient portfolio designed for sovereign, independent operations.

Decades of trust from governments, defense organizations, and critical infrastructure operators worldwide

Certifications that matter: Common Criteria evaluation for secure voice, FedRAMP Certification for BlackBerry AtHoc

A portfolio designed to work when the rest of the environment does not: independent, sovereign, auditable

Next Step

A 30-Minute Resilience Review

We map your current incident communications against the July 30 federal advisory and identify gaps. No obligation.