Skip to main content

CI Fortify Answers the Gap Minnesota's Critical Infrastructure Attack Exposed

SUBJECT: Isolation Blueprint STATUS: Ongoing AUDIENCE: Government, Defense, Critical Infrastructure Security Leads

Aug 3, 2026

·

Blog

·

Secure Communications

CISA and Five Eyes agencies release joint OT isolation blueprint amid active water utility attack

What Happened

CISA, joined by cybersecurity agencies from the UK, Australia, Canada, and New Zealand, published "CI Fortify," a six-step blueprint for isolating operational technology (OT) during cyberattacks. The guide instructs critical infrastructure operators to build dedicated isolation points into vital systems so essential services can continue even when networks are deliberately cut off from the outside.

CAF Bank temporarily suspended online services following issues linked to a third-party software vulnerability, requiring the organization to implement contingency measures while service restoration efforts were underway.1

The release lands alongside two active incidents cited in coverage: CAF Bank suspended online services after a third-party software vulnerability, and a coordinated attack disrupted OT systems at more than 30 Minnesota water utilities. Minnesota's water utilities and CAF Bank both show what happens without a fallback communication layer during forced isolation: coordination breaks down at the exact moment it matters most.

Minnesota Water Utilities: What We Know

  • Attack window: July 26-27, 2026. Minnesota IT Services (MNIT) confirmed the intrusion publicly on July 28 and activated a statewide cybersecurity incident response.2

  • More than 30 community water and wastewater systems were affected; Braham, Plymouth, South St. Paul, and Maple Plain publicly disclosed impact to automated control functions.3

  • Contingency procedures kept water and wastewater service running in most affected communities. The Minnesota Department of Health reported no municipality issued a change-in-use advisory to residents.4

  • Attribution is unconfirmed as of July 29. MNIT is coordinating with CISA, the EPA, and the FBI, and has noted access-pattern similarities to intrusions seen in other states and sectors without naming a responsible actor.

  • Federal context: CISA Advisory AA26-097A, updated in the same window, tracks Iranian-affiliated actors exploiting programmable logic controllers (PLCs) across U.S. critical infrastructure. Reporting has noted the timing aligns with that broader activity, though no formal link to the Minnesota attacks has been established.5

  • Structural risk factor: the U.S. has roughly 150,000-170,000 water systems, most of them small and under-resourced. A 2024 EPA Office of Inspector General audit found the majority of water systems reviewed were not current on required risk assessments and emergency response plans.6 7

The Six Steps

  1. Identify vital systems and networks

  2. Identify critical customers

  3. Identify common levels of criticality and trust for networks and hosts

  4. Identify potential isolation points and map connections to vital systems

  5. Build effective separation and isolation points

  6. Create and test an isolation plan

Why It Matters

The guide's central instruction is blunt: organizations must build physical isolation points into vital systems and treat carrier-provided networks as untrusted and potentially hostile. That requirement creates an immediate operational gap. If an agency isolates its OT or IT network, how does it keep personnel informed and coordinated during the isolation event itself?

This is a mass notification and emergency communication problem before it is anything else. The guide assumes operators can isolate infrastructure; it does not solve how command staff, field personnel, and affected customers stay in contact once that isolation happens. That gap is where the BlackBerry portfolio sits.

How BlackBerry Fits the Blueprint

Guide Requirement
BlackBerry Product
Alignment
Dedicated, non-shared communication paths that keep functioning when primary IT/OT networks are isolated
BlackBerry® AtHoc®
Out-of-band mass notification operates independent of the networks it reports on, including during deliberate isolation
Treat carrier-provided and third-party networks as untrusted; avoid relying on encryption built into commodity devices
BlackBerry® SecuSUITE®
NSA CSfC listed, dedicated encryption layer, not dependent on carrier or consumer app infrastructure
Maintain command visibility and coordination across isolated zones during a graduated isolation plan
BlackBerry AtHoc
Multi-channel alerting reaches personnel across segmented network zones without crossing isolation boundaries
Document emergency contacts and maintain rapid, verified communication during incident response
BlackBerry AtHoc
Built for exactly this: verified, trackable emergency communication during active incidents
  • Pair any OT/IT isolation plan with a communication continuity plan. Isolation without a coordination channel just delays the disruption, it doesn't prevent it.

  • Inventory which emergency and command communications currently depend on the same carrier or IT infrastructure being isolated. That dependency is the gap CI Fortify doesn't close.

  • Test the isolation plan and the communication fallback together. The guide's own six-step process ends with "create and test an isolation plan"; notification and coordination should be tested as part of that same exercise, not separately.

  • Prioritize out-of-band, multi-channel notification for any zone identified as a candidate for graduated isolation, so command visibility survives the isolation event itself.

BlackBerry Perspective

"CI Fortify" tells agencies to isolate their networks. It doesn't tell them how to stay connected once they do. The consequences of Minnesota's water utilities and CAF Bank both show what that gap costs in practice: services down, no clear fallback for command and coordination. BlackBerry AtHoc is built for exactly that gap: verified, multi-channel emergency communication that operates independently of the infrastructure it's reporting on.

Related reading:

Citations:

  1. Work continues to restore services at charity bank (CAF Bank customer update regarding ongoing service restoration efforts following a third-party software vulnerability, August 1, 2026.)

  2. State Cybersecurity Response Activated Following Water Utility Cyber Incident

    (Minnesota IT Services, MNIT News Release, July 28, 2026.)

  3. Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks (Security Week, July 29, 2026.)

  4. Minnesota continues response to cyber activity affecting community water systems (Minnesota IT Services, MNIT News Release, July 30, 2026.)

  5. Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure (AA26-097A) (Cybersecurity and Infrastructure Security Agency (CISA),CISA Advisory AA26-097A, July 22, 2026.)

  6. Fact Sheet on Risk and Resilience Assessment and Emergency Response Plan Requirements (EPA, May 26, 2026.)

  7. Critical’ cyber vulnerabilities found in many water utilities, warns EPA inspector general

    (U.S. Environmental Protection Agency Office of Inspector General. Assessment of cybersecurity vulnerabilities affecting U.S. drinking water systems, summarized in State Scoop, November 18, 2024.)

Get updates about the latest in-depth knowledge for secure communications.

Industry Discussion

On-Demand Webinar: What CI Fortify Doesn't Say About Communications

In July, CISA and other agencies released joint guidance titled "CI Fortify – Advice for Isolating Vital Systems," directing critical infrastructure operators to proactively isolate vital OT systems from unreliable third-party networks and sustain essential operations independently. Join us for an informative session about what CI Fortify asks operators to do, what it costs, and what it leaves unaddressed.

Watch now