2026-07-28OPINION · CRITICALINFRASTRUCTURE · CYBERRESILIENCE · EXECUTIVERISK · INCIDENTRESPONSE · GOVERNANCEANDRISK5 MIN READ READ
FILED UNDER

Three Months in Isolation: Is Your Critical Infrastructure Ready?

ASD's three-month isolation guidance exposes a continuity gap that faster detection cannot close.

Your Incident Response Plan Was Not Built for This

Most executive teams running essential services in Australia are carrying a quiet assumption: that a serious cyber incident is a days-long crisis, not a months-long operating condition. That assumption is now officially wrong.

The Australian Signals Directorate has issued technical guidance telling critical infrastructure operators to be prepared to isolate systems for up to three months. Read the iTnews coverage and you might file it under “technical matter for the IT team.” That would be a mistake. This guidance is a strategic signal from Australia’s peak signals intelligence agency, and it has direct consequences for how you govern your organisation, what your insurance actually covers, and whether your continuity planning is fiction.

What ASD Is Describing

The scenario in view is not a ransomware group locking your files while you restore from backup. It is a nation-state intrusion: an adversary who has been moving laterally through your environment for months, has embedded itself in the systems you depend on, and cannot be cleanly removed without isolating those systems and rebuilding from a known-good state.

Three months is not a padded figure. It is what evicting a persistent actor who does not want to leave actually takes. These operators pre-position, survive reboots and maintain redundant footholds, and the detect-eject-restore playbook your incident response retainer is built around assumes an adversary who behaves like a burglar. A nation-state actor behaves more like a tenant who has changed the locks.

Which leads somewhere uncomfortable: an organisation that cannot run critical functions in isolation for three months has a continuity gap that faster detection does not close.

The Governance Problem Beneath the Technical One

Your incident response plan almost certainly grades severity by duration and data impact, escalates to the CEO somewhere around the 24 or 48 hour mark, and quotes a recovery time objective measured in days. None of that architecture was designed for someone who has been inside the environment for four months before anybody noticed.

Three consequences deserve direct executive attention.

Your insurer has not priced this scenario. Cyber insurance policies are written around incidents with defined start and end points. A three-month operational isolation — with associated revenue loss, manual workaround costs, third-party dependencies failing, and regulatory obligations accumulating — is not the loss event your broker modelled. Read your policy wording against that scenario before you need to.

Your regulators expect capability you may not have. SOCI Act obligations require critical infrastructure entities to have and maintain a critical infrastructure risk management programme. APRA CPS 234 requires financial entities to maintain information security capability commensurate with their threat environment. If the threat environment now officially includes three-month isolation scenarios and your programme does not address that, you are not compliant in substance, regardless of what your last audit found.

Your major customers and counterparties are exposed through you. Supply chain dependencies in essential services mean your isolation is their disruption. Some of them have their own regulatory obligations that will be triggered by your incident. They do not yet know that your recovery plan cannot sustain this scenario — but they will, and the conversation will be worse if it happens during an incident than before one.

Why Most Organisations Will Not Act on This Until It Is Too Late

Incentives, mostly. The scenario feels remote and abstract, and preparing for it is expensive. The continuity work involved is invisible to customers and regulators right up until the week it matters. And the people running incident response, internal or retained, gain nothing by telling a client that the retainer already purchased does not cover this adversary profile.

We do not sell response retainers, so we can say the thing plainly. The distance between what most critical infrastructure operators have prepared for and what ASD now describes as plausible is large, and closing it takes decisions well above the CISO’s pay grade.

That makes it a CEO and COO problem. Which functions can run manually or degraded for a long period, what that costs, and whether the organisation will fund the capability before it is needed — operational and financial questions, all of them.

What to Do Differently, Starting Now

None of this involves ringing IT.

Put the three-month isolation scenario to the continuity planning team as a live exercise prompt. Not a tabletop for the security function: a business continuity question. Which revenue-generating or service-delivery functions survive it, which collapse, and are the manual fallbacks real or a paragraph someone wrote in 2019?

Have legal and risk read the cyber insurance policy against this specific scenario and identify where the wording breaks down under a three-month operational event rather than a contained breach. Get that in writing before renewal, not after.

Then brief the board on what the guidance means operationally, framed as a governance question rather than a threat briefing. Do we have the capability this implies we need? An unclear answer is itself a material finding.

ASD has said the quiet part out loud: these intrusions are persistent, deeply embedded, and not cleanly evictable inside the timeframes your plans assume. Anyone who passes that down to IT as a technical update will get to explain, later, to regulators and insurers and customers, why their continuity planning ignored a scenario their own government had formally described.

Next dossier
OpenAI Supports Australian Regulation Because It Helped Write It →
Engage the author
Adam van Vliet is currently taking on briefs.
Brief Adam
Share