CISA just told the world how to isolate critical infrastructure. Most African operators canu2019t follow it.
CISA just told the world how to isolate critical infrastructure. Most African operators can’t follow it.
The US Cybersecurity and Infrastructure Security Agency published a six-step playbook last month. CI Fortify, they call it. Backed by the Five Eyes — US, UK, Australia, Canada, New Zealand. It’s meant for power grids, water systems, transport, banking. The infrastructure that keeps a country running.
Solid guide. Clear steps. But it assumes you already have the architecture to execute it.
This week alone, CAF Bank went dark over a third-party software flaw. Charities couldn’t pay staff. Minnesota water utilities got hit in a coordinated attack. These aren’t hypotheticals. They’re Tuesday.
The six steps, no fluff
CISA wants you to enable critical services while isolated. Not shut down. Isolate. Big difference.
- Define what absolutely must stay up. Megawatts. Gallons. Transactions per minute. Everything else is negotiable.
- Set delivery targets by who matters most. The hospital’s power feed comes before the shopping mall’s.
- Segment by criticality, not org charts. Zone networks and systems by threat exposure. Risk management drives this.
- Map every interconnection. Continuously. Vendor remote access. Cloud links. Carrier circuits. Wi-Fi, satellite, radio, mobile. Document the encryption, the gateway configs, the VPN tunnels, the emergency contacts. This map becomes your isolation control plane.
- Build physical isolation points. Zero connectivity to non-OT networks. No shared switching, routing, compute, or power. Management planes fully segregated. Harden with VLANs, MPLS, ACLs, route blocking, blackhole routing.
- Phase it. You can’t flip a switch on distributed infrastructure. Graduate the lockdown as the threat escalates.
Zero trust doesn’t replace isolation
The guide notes that zero-trust architectures reduce the need for isolation. They don’t eliminate it. When attackers get inside — and they will — physical separation is the only thing that guarantees containment. Air gaps. Dedicated fiber. Hardware encryptors, not the encryption built into OT devices.
Carrier services? Treat them as hostile. The agencies say it straight: any third-party link is a potential pivot point.
Where this breaks for African enterprises
Eskom’s grid. Nigeria’s interbank settlement. M-Pesa’s rails. This is critical infrastructure. Same state-sponsored threats hitting US water utilities and UK hospitals. But the architecture to execute CI Fortify? Mostly missing.
Not for lack of awareness. For lack of topology. Isolation requires segmentation. Segmentation requires mapping. Mapping requires a network that isn’t flat with shared management planes.
This is where eHawu fits. Our network-layer VPN builds the isolation primitives the playbook assumes exist. Dedicated tunnels. Cryptographic segmentation. No shared infrastructure. When the order comes to isolate, the topology is already there. You just close the gates.
CI Fortify gives you the plan. eHawu gives you the network to run it on.