In October 2025, ASD’s ACSC published CI Fortify, guidance designed to strengthen service continuity and resilience for Australian critical infrastructure operators, with a particular emphasis on operational technology (OT) environments.
At Secolve, we’ve seen CI Fortify quickly become a board and executive topic across the energy and water sectors. While it is published as guidance (not legislation), the direction is clear: government expectations for operational resilience are shifting from “have a plan” to “prove you can operate under sustained isolation and recover reliably.”
This blog outlines what CI Fortify is asking, why energy and water operators are discussing it in the context of SOCI and CIRMP, and the practical steps Secolve recommends for operators who want to respond in a way that is both operationally realistic and evidence-ready.
Why CI Fortify is landing now: alignment with proposed CIRMP uplifts
Many energy and water organisations are asking whether CI Fortify will become a new SOCI or CIRMP requirement. Today, the most accurate answer is:
- The Department of Home Affairs is consulting on enhancements to the CIRMP Rules (consultation open 9 December 2025 to 13 February 2026).
- The consultation material proposes an uplift relating to critical systems network protection, segregation and recovery, including the ability to isolate critical systems for 3 months while maintaining operation, and maintain a plan to completely rebuild critical systems whilst continuing operation.
- The consultation proposes a compliance timeframe for that uplift by 30 June 2028, with attestation expected in July to September 2028.
From a client advisory perspective, this is the key point: CI Fortify is strongly aligned with the uplift concepts currently being consulted on, and energy operators should treat it as an indicator of emerging baseline expectations. Separately, the Critical Infrastructure Security Centre has flagged a stronger assurance and audit focus in its 2025 to 2026 compliance posture, which further reinforces the need for evidence-based resilience, not just policy statements.

What CI Fortify is really asking energy and water operators to do
CI Fortify distils into two outcomes that matter operationally:
- Isolate “vital OT and enabling systems” for 3 months while maintaining critical services
- Rapidly rebuild those vital OT and enabling systems completely to minimise disruption
CI Fortify also makes a pragmatic observation that we see repeatedly in real environments: isolation tends to break cross-network automation, requiring processes to be executed manually during the isolation period.
At Secolve, we summarise CI Fortify as a shift toward resilience-by-design: know what is vital, be able to isolate it for a sustained period, and be able to rebuild it from known-good foundations.
How Secolve advises energy and water operators to respond to CI Fortify
Our approach focuses on building the minimum defensible line-of-sight and then turning that into repeatable, testable operating capability.
1. Establish line-of-sight: assets, architecture, critical services, vital systems
CI Fortify is explicit that an organisation must maintain an up-to-date inventory and identify the systems that are vital to keeping critical services running. In our experience, the foundational deliverables are:
- Complete technology asset inventory for OT and enabling systems (not just “OT devices”)
- Documented network architecture that reflects real data flows and trust boundaries
- A mapping model that ties critical services to supporting business processes, and business processes to vital OT and vital enabling systems (identity, remote access pathways, management tooling, historian pathways, backups, time sources, and more)
This is also where we recommend operators align the work to frameworks they already use, particularly where they participate in AESCSF alignment.
2. Define “isolation” as a sustained operating state
CI Fortify expects a graduated isolation plan with thresholds. So instead of one “pull the plug” isolation mode, you design a progressive sequence of isolation states. Secolve helps clients turn this into a practical definition of isolation that answers:
- What is the minimum viable operating state for each critical service?
- Which dependencies must be redesigned to survive isolation (identity, monitoring and telemetry, vendor access, patching channels, secure file transfer)?
- Which processes become manual, and do we have the staffing, procedures, and safety controls to sustain them for the required period?
For many energy and water organisations, this becomes a tiered model: partial isolation (tightened conduits), constrained isolation (restricted but controlled flows), and full isolation (local-only sustainment), each tied to escalation triggers.
3. Use BIA to make “3 months” realistic and prioritised
Whether or not a future rule codifies that benchmark, the operational response still needs to be informed by business and safety requirements. We typically recommend that clients use or refresh a Business Impact Analysis (BIA) to support:
- Prioritisation of services
- Acceptable degradation levels
- Operational constraints and safety considerations
- Which enabling systems are genuinely “vital”
This avoids the trap of over-scoping “vital systems” and creating an isolation model that is impossible to sustain.
4. Treat isolation and rebuild as risk controls and make them auditable
If CI Fortify continues to be reflected in CIRMP uplift expectations, as current consultation language suggests, then organisations will need to evidence controls, not merely describe them. Secolve’s guidance here is consistent:
- Incorporate isolation and restoration capability into risk management plans and CIRMP-aligned evidence packs
- Include these capabilities within internal audit scope as operational risk controls, not just cyber controls
This approach aligns with the broader compliance posture that is increasingly focused on assurance and audit.
5. Validate through exercises: tabletop scenarios and rebuild drills
CI Fortify is ultimately about performance under stress. We therefore recommend routine testing via:
- Tabletop incident simulations that validate decision thresholds, communications, manual workarounds and isolation transitions
- Targeted rebuild drills that test known-good baselines, offline backups, restoration sequencing, and safety considerations for OT
The outcomes of these exercises, such as minutes, runbooks, and evidence of corrective actions, are often the most persuasive material for both executive confidence and regulatory assurance.

Where AESCSF helps energy operators accelerate the work
Many of our clients participate in the AESCSF program targeting SP1, and the framework provides a practical structure for organising CI Fortify uplift. AESCSFv2 is commonly used in the sector to guide improvement and demonstrate SOCI-aligned security maturity.
From a mapping perspective, CI Fortify touches multiple domains, but the most direct alignment is:
- ASSET: Inventory, configuration, lifecycle, dependency tagging
- ARCHITECTURE: Zones and conduits, trust boundaries, control placement, defensible segmentation
- RESPONSE: Operate through cyber events, isolation runbooks, restoration and rebuild capability
For operators already conducting AESCSF assessment cycles, we recommend using CI Fortify as a targeted uplift overlay, so isolation and rebuild outcomes are measurable, prioritised, and tracked through an established governance mechanism.
A pragmatic roadmap to CI Fortify
Below is the staged approach Secolve is recommending to energy operators to avoid “big bang” programs while still building credible capability.
Phase 1: Foundation
- Consolidate OT and enabling system inventories and establish “vital” tagging
- Document the architecture and real data flows
- Map critical services to supporting systems and identify isolation points
Phase 2: Isolation operating model
- Define isolation states (allowed flows, manual processes, dependencies)
- Address key blockers: identity, vendor access, monitoring, patching, file transfer
- Build runbooks and thresholds for graduated isolation
Phase 3: Rebuild capability
- Implement known-good baselines, offline recovery artefacts, restoration sequencing
- Run targeted drills and confirm safety constraints for OT restoration
- Capture evidence and corrective actions
Phase 4: Assurance and sustainment
- Integrate into CIRMP evidence and internal assurance cycles
- Track uplift through AESCSF assessments and management reporting
- Refresh mappings as services and architectures evolve

World map texture credits to NASA.
(https://visibleearth.nasa.gov/view.php?id=55167)
Takeaways
CI Fortify is best understood as a practical resilience benchmark: can you identify what is vital, isolate it for a sustained period, and rebuild it quickly from known-good foundations?
Given the CIRMP uplift consultation language now referencing similar capabilities, including 3-month isolation and rebuild planning, energy operators should treat CI Fortify as a credible preview of emerging expectations and focus on building evidence-ready capability rather than paper compliance.
At Secolve, we are helping energy and water operators translate CI Fortify into a staged, operationally realistic program that aligns to existing governance mechanisms. For energy operators in particular, we consider where AESCSF is already in use, and ensures the program stands up to scrutiny and future assurance needs. Get in touch with our team today to find out how we can help your organisation.
This article is general information and does not constitute legal advice. Organisations should obtain sector-specific and asset-specific advice when assessing SOCI and CIRMP obligations.
