For Australian utility leaders, CI Fortify raises a harder question than whether the organization can meet a cyber requirement. If critical digital systems have to be disconnected, can the utility keep essential services running, make the right isolation decisions, and rebuild from trusted sources without depending on compromised infrastructure?

That is the boardroom test. CI Fortify, introduced by the Australian Signals Directorate and Australian Cyber Security Centre in October 2025, shifts the center of gravity from protection to survivability. Preventive controls still matter, but they are no longer enough. The executive question is whether the operating model can absorb disruption when normal connectivity, normal recovery pathways, and normal vendor support cannot be assumed.

The consequence of getting this wrong is not limited to a failed audit. A utility that cannot see its dependencies, isolate safely, or restore runs the risk of turning a cyber incident into a service-continuity, regulatory, and customer-trust event. The choice for leaders is whether to treat CI Fortify as another compliance workstream or use it to harden the way the enterprise operates under constraint.

This is why CI Fortify belongs on the agenda of every Australian utility’s C-suite and board agenda. It forces a practical discussion about which services must continue, which systems can be separated, who has authority to act, what must be funded, and how readiness will be proven before disruption makes those questions urgent.

The Shift: From Security Posture to Continuity Under Isolation

The CI Fortify guidance creates a demanding operating scenario. Utilities must understand which operational technology assets and enabling systems are vital to critical services, where isolation can be enacted safely, how long services can run in a reduced-connectivity state, and how systems can be rebuilt from trusted offline sources.

That scenario changes leadership accountability in three ways.

  1. Operational resilience can no longer sit inside a single cyber function. Grid operations, OT security, enterprise IT, infrastructure, vendors, business continuity, and enterprise risk all have roles in keeping services available during isolation.
  2. Readiness has to be evidenced, not asserted. Inventories, dependency maps, isolation procedures, offline backups, and rebuild paths need to be tested under constrained conditions, not only documented for review.
  3. Governance has to move closer to the operating floor. Leaders need named decision rights for isolation, service prioritization, recovery sequencing, vendor escalation, and board reporting.

Existing security frameworks such as the Essential Eight and ISO 27001 remain useful, but they do not by themselves prove that a utility can operate through sustained isolation. The harder readiness gaps usually sit in places where cyber, operations, infrastructure, and suppliers meet: incomplete asset visibility, unclear operational dependencies, untested separation points, and recovery plans that assume normal access to people, networks, or tooling. 

The Consequence: A Cyber Event Becomes an Operating Event

Modern utilities run on interdependence. OT platforms, enterprise networks, cloud services, field systems, and specialist vendors support one operating chain. During a serious cyber event, that interdependence becomes a source of fragility if leaders do not already know which connections can be cut, which services must be protected first, and which recovery paths can be trusted.

CI Fortify therefore turns resilience into a design and execution problem. Utilities need a live view of vital assets and their enabling systems; a practical view of dependencies across OT, IT, third parties, and field operations; clear points where isolation can occur without creating unacceptable service risk; and offline recovery capabilities that have been rehearsed before they are needed.

The investment issue is sequencing. Leaders do not need a catalogue of disconnected cyber projects; they need a funded pathway that starts with the most critical services and the dependencies most likely to break continuity. The practical priority is to identify where failure would create the greatest operational, regulatory, or customer impact, then close the readiness gaps that would prevent isolation or trusted recovery.

This framing also gives the board a better assurance question. Instead of asking whether controls exist, directors can ask whether the utility has proved five things: 

  1. It knows its vital services
  2. It understands the systems that enable them
  3. It can separate compromised environments
  4. It can run priority services in a degraded state
  5. It can rebuild from sources it trusts

Where evidence is missing, leaders should be explicit about it. If recovery times, dependency completeness, backup integrity, or isolation procedures have not been tested, they should be treated as assumptions rather than assurances. That distinction matters because CI Fortify is ultimately a test of what the organization can do under pressure, not what it believes it has prepared.

The Choice: Compliance Workstream or Survivability Program

The immediate risk is that CI Fortify just becomes another policy exercise. That would be a mistake. Used well, the guidance can force a disciplined operating-model review: what must continue, what can be disconnected, what can be rebuilt, and who is accountable when the enterprise is operating with fewer choices.

A practical response should start with an executive readiness diagnostic. The diagnostic should compare the current state against the services that matter most, not against a generic control checklist. It should identify the minimum capability needed to operate through isolation and the evidence required to show that capability is real.

From there, the work should be organized around four decisions.

  1. Which services are most critical, and what assets, applications, infrastructure, suppliers, and manual processes keep them running?, governance maturity, and evidence of prior testing.
  2. Where can the utility isolate systems safely, and what operating modes are required when connection to enterprise IT, the internet, or third parties is reduced?
  3. Which systems can be rebuilt from trusted offline sources, and what evidence shows that rebuild procedures work in degraded conditions?
  4. Who owns the decisions during a disruption, and how will readiness be reported to executive and board stakeholders?

This creates a clearer consulting agenda: readiness assessment, dependency and isolation design, recovery assurance, and run-state governance. Each element should produce outputs a leadership team can use: a prioritized gap view, a target survivability architecture, rehearsed recovery procedures, decision rights, metrics, and a testing calendar.typically requires and clear executive decision rights. The work is architectural, operational-led: utilities must know which services must continue, which dependencies can be severed safely, which systems can be rebuilt from trusted sources, and which leaders have authority to act during constrained conditions

The Action: Prove Survivability Before Disruption Tests It

For senior utility leaders, the near-term action is not to launch another broad cyber program. It is to answer a narrower set of questions with evidence: which services must continue, how they would operate during isolation, what must be rebuilt first, which assumptions have been tested, and what investment is required to close the highest-risk gaps.

A useful 90-day response would establish a readiness baseline, map dependencies for the most critical services, test one or two high-consequence isolation and recovery scenarios, and give the board a transparent view of evidence, assumptions, and funding choices. That sequence does not solve every resilience issue, but it changes the conversation from compliance status to operational proof.

CI Fortify should therefore be treated as a decision point. Utilities can respond with documentation and fragmented remediation, or they can use the mandate to build confidence in how the enterprise will operate when systems, suppliers, and recovery pathways are under stress. The organizations best prepared for disruption will be those that can prove continuity before they have to defend it.

About the Authors

B. Madhusudhana Reddy
General Manager & Senior Partner, EMR (Energy, Manufacturing and Resources), India Consulting Hub

Madhusudhana is the Consulting Head for the Utilities Engineering GIS (UEG) - EMR sector at Wipro, with more than 20 years of experience driving transformation programs for Utilities. He has led large-scale industry transformation initiatives, demonstrating consulting excellence and delivering technology-driven business outcomes across customer experience, asset management, and grid resiliency. His expertise spans solution architecture, program management, and strategic consulting. A Mechanical Engineer with an MBA from IIM Bangalore, Madhusudhana is committed to shaping industry practices, driving innovation, and delivering impactful change for clients.

K. Sreenadha Reddy
Partner, EMR (Energy, Manufacturing and Resources) – India Consulting Hub

Sreenadha is a Partner at Wipro with over 20 years of experience in utilities, driving digital transformation across asset management, GIS, workforce management, and OT programs. He has a strong track record in solution architecture, proposal leadership, and delivering complex global initiatives with a focus on grid resiliency and sustainable energy transition. He brings deep expertise in utilities analytics across EAM, OT, customer, metering, and green energy domains. He champions AI-enabled, AI-led consulting aligned with Wipro's approach, delivering intelligent, data-driven transformation and measurable business outcomes.