Joint Guidance

Advice for isolating vital systems

This guide details steps to successfully isolate vital operational technology (OT) and enabling systems from all other networks.

PUBLISHED DATE: 29 July 2026

State-sponsored cyber actors routinely target critical infrastructure (CI) to conduct espionage or to pre-position for disruptive and destructive effects in the event of crisis or conflict.
 
Cybercriminals continue to opportunistically target CI operators. The sensitivity of the data stored by these entities, and the importance of their services, makes them attractive for cybercriminals seeking to extort victims via data exfiltration or by conducting ransomware attacks for disruptive or destructive purposes.
 
In response to persistent threats, CI operators should have the capability to isolate vital Operational Technology (OT) and enabling systems from all other networks to ensure continuity of critical services. Isolating vital OT and enabling systems can disrupt the ability of malicious cyber actors to achieve their goal, contain active incidents, and allow for safe rebuilding of compromised systems.

These two pieces of guidance define the capability to isolate vital OT and enabling systems from the internet and other networks. With this capability, OT owners, operators and cyber defenders can provide continuity of their critical services in instances of crisis or service disruption.

These documents have been produced under the CI Fortify programme from the Australian Signals Directorate and may reference documents that have not been co-sealed NCSC-NZ.

The New Zealand definitions for Critical Infrastructure are currently under consideration by the Department of the Prime Minister and Cabinet. Examples used in these documents may not align with the New Zealand definition for Critical Infrastructure.

 
For questions related to this guidance, email info@ncsc.govt.nz.