{"id":3961,"date":"2026-05-26T11:42:57","date_gmt":"2026-05-26T09:42:57","guid":{"rendered":"https:\/\/www.seclab-security.com\/?p=3961"},"modified":"2026-06-10T10:50:20","modified_gmt":"2026-06-10T08:50:20","slug":"resilience-critical-infrastructures-isolation-ot-2026","status":"publish","type":"post","link":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/","title":{"rendered":"Resilience of Operational and Critical Infrastructures: When States Talk About Isolation"},"content":{"rendered":"<p><!-- ============================================================ ARTICLE BLOG SECLAB \u2014 AVADA Fusion Builder Coller dans : Fusion Builder > \u00c9l\u00e9ment \"Code\" (HTML)\nD\u00e9sactiver \"Encode Special Characters\" si activ\u00e9 dans AVADA\n============================================================ --><\/p>\n<p><!-- [H1] --><\/p>\n<h1>Resilience of Operational and Critical Infrastructures: When States Talk About Isolation<\/h1>\n<p><!-- [CHAPEAU] --><\/p>\n<p style=\"font-weight: 400;\">Within the space of a few months, the Five Eyes countries (the intelligence-sharing alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States), Japan, and France have each published cyber resilience guides for critical infrastructure operators. The tone has changed decisively. The conversation is no longer about &#8220;strengthening defenses.&#8221; It is about <strong>isolating OT systems<\/strong>, <strong>operating in degraded mode during attacks<\/strong>, and <strong>rebuilding from offline backups<\/strong>.<\/p>\n<p style=\"font-weight: 400;\">This shift is not theoretical. It is driven by two converging realities: state-sponsored pre-positioning campaigns discovered inside civilian infrastructures, and an armed conflict, the one pitting the United States and Israel against Iran, during which OT attacks have caused real operational disruptions on American soil.<!-- ============================================================ SECTION 1 \u2014 The Context ============================================================ --><\/p>\n<h3><\/h3>\n<h3><span style=\"color: #28e39c;\"><strong>Key Takeaways<\/strong><\/span><\/h3>\n<ul style=\"font-weight: 400;\">\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">The United States, the United Kingdom, Australia, Canada, Japan, and France have all published cyber resilience guides for critical infrastructure.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">All guides converge on the same priorities: inventory, identification of vital systems, proactive isolation of those systems, continuous detection, and tested recovery.<\/li>\n<li class=\"font-claude-response-body whitespace-normal break-words pl-2\">The Seclab Xcore platform enables organizations to meet the recommendations of these guides through a three-phase journey: Discover, Isolate, Detect.<\/li>\n<\/ul>\n<h3><\/h3>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>1. The Context: Threats That Are No Longer Hypothetical<\/strong><\/span><\/h3>\n<h3><span style=\"color: #28e39c;\"><strong>State Actors Already Inside<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\"><strong>Volt Typhoon<\/strong>, a group attributed to China, is reported to have maintained persistent access inside American critical infrastructures (energy, water, telecommunications, transportation) for at least five years before being detected. The group was notably observed testing access to OT systems, such as HVAC equipment and energy and water control systems.<\/p>\n<p style=\"font-weight: 400;\"><strong>Salt Typhoon<\/strong>, also attributed to China, is reported to have compromised at least nine major US telecom operators and more than 200 organizations across 80 countries. The FBI confirmed in February 2026 that the threats remained active.<\/p>\n<p style=\"font-weight: 400;\">The objective of these campaigns is not classic intelligence gathering. US agencies state this with a high degree of confidence: the goal is to be able to <strong>disrupt or destroy critical OT functions at a time of the attacker&#8217;s choosing<\/strong>, typically in the event of armed conflict over Taiwan.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>OT Attacks Now Operational<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">On April 7, 2026, six US federal agencies (FBI, CISA, NSA, EPA, DoE, CNMF) published a joint advisory confirming that APT actors affiliated with Iran were actively exploiting internet-accessible programmable logic controllers (PLCs) in the water, energy, and government services sectors. Some victims experienced <strong>operational disruptions and financial losses<\/strong>.<\/p>\n<p style=\"font-weight: 400;\">The geopolitical context is direct: these attacks intensified in the wake of the Epic Fury military operation launched on February 28, 2026, against Iran. Cyberattacks and kinetic conflict are now advancing in parallel. In Europe, Poland suffered coordinated cyberattacks against its power plants in December 2025, in the middle of winter, targeting heating systems.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>The Agencies&#8217; Verdict<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">The UK NCSC&#8217;s formulation in its guide published in January 2026 captures the paradigm shift: <strong>resilience, not prevention, is now the defining requirement<\/strong>. Cyberattacks will not always be stopped at the perimeter. Organizations must be able to maintain their operations and recover under pressure.<\/p>\n<p>&nbsp;<\/p>\n<p><!-- ============================================================ SECTION 2 \u2014 National Initiatives ============================================================ --><\/p>\n<h3><span style=\"color: #28e39c;\"><strong>2. National Initiatives: What the Guides Are Asking For<\/strong><\/span><\/h3>\n<h3><span style=\"color: #28e39c;\"><strong>\ud83c\uddfa\ud83c\uddf8 United States, May 2026<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">In very recent news, CISA launched <strong>CI Fortify<\/strong>, its resilience initiative for critical infrastructures. The document is unambiguous about the planning scenario: operators must <strong>assume that, in a conflict scenario, third-party connections (telecommunications, Internet, vendors, service providers) will be unreliable, and that malicious actors will have access to the OT network<\/strong>.<\/p>\n<p style=\"font-weight: 400;\"><strong>Recommendations:<\/strong><\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Proactively disconnect OT networks from enterprise networks and third-party connections to maintain essential operations in a degraded communications environment.<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Document systems, back up critical files, and practice replacing systems or switching to manual mode in the event of isolation failure.<\/p>\n<p style=\"font-weight: 400;\">CISA has begun targeted assessments with organizations supporting national security, public health, and economic continuity, with a scale-up objective in the coming months.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>\ud83c\uddec\ud83c\udde7 United Kingdom, January 2026<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">The <strong>National Cyber Security Centre<\/strong> also published its guide for critical infrastructure operators. The document defines the concept of a <strong>severe cyber threat<\/strong>: a deliberate, highly disruptive or destructive attack aimed at stopping critical services for extended periods, physically damaging systems, or erasing data to make recovery impossible.<\/p>\n<p style=\"font-weight: 400;\"><strong>Recommendations:<\/strong><\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Develop organization-wide response strategies and plans<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Improve situational awareness through monitoring and intelligence sharing<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Harden systems and networks to reduce vulnerabilities<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Ensure the ability to maintain operations and recover during a disruption<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>\ud83c\udde6\ud83c\uddfa Australia, October 2025<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">Australia was the first of the Five Eyes alliance to publish its own CI Fortify program. The document follows in the wake of ASIO&#8217;s (domestic intelligence agency) annual assessment, which characterizes espionage and foreign interference as being at <strong>extreme<\/strong> levels and on an upward trajectory.<\/p>\n<p style=\"font-weight: 400;\">The Australian CI Fortify is structured around <strong>three preparatory steps<\/strong> and <strong>two planned actions<\/strong>:<\/p>\n<p style=\"font-weight: 400;\"><strong>Preparatory steps:<\/strong><\/p>\n<ol style=\"font-weight: 400;\">\n<li>Maintain an <strong>up-to-date inventory of all OT assets<\/strong> and supporting systems, classified by criticality<\/li>\n<li>Identify the <strong>vital OT systems<\/strong> required to maintain continuity of critical services<\/li>\n<li>Define <strong>risk thresholds<\/strong> to assess the impact of isolation on operations<\/li>\n<\/ol>\n<p style=\"font-weight: 400;\"><strong>Planned actions:<\/strong><\/p>\n<ul style=\"font-weight: 400;\">\n<li>Be able to <strong>isolate vital OT systems for 3 months<\/strong><\/li>\n<li>Be able to <strong>fully rebuild these systems<\/strong> from offline sources<\/li>\n<\/ul>\n<p style=\"font-weight: 400;\">The program states that these capabilities should serve beyond the cyber scenario alone: they also improve response to natural disasters and supply chain disruptions.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>\ud83c\udde8\ud83c\udde6 Canada, April 2026<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">The <strong>Canadian Centre for Cyber Security<\/strong> launched the <strong>CIREN<\/strong> initiative (Critical Infrastructure Resilience and Escalated Threat Navigation).<\/p>\n<p style=\"font-weight: 400;\"><strong>Recommendations:<\/strong><\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Be prepared to <strong>isolate systems for up to 3 months<\/strong><\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Develop and test plans to <strong>operate independently<\/strong> (without external connectivity)<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Plan for the <strong>complete reconstruction of systems<\/strong> in response to severe cyber incidents<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>\ud83c\uddef\ud83c\uddf5 Japan, October 2025<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">Japan&#8217;s Ministry of Economy defined <strong>specific OT security guidelines for semiconductor manufacturing facilities<\/strong>, acknowledging that a cyberattack against a manufacturing plant would have cascading global repercussions. This sector-focused approach to resilience, centered on infrastructures whose failure would trigger an international domino effect, echoes the prioritization logic underpinning the CI Fortify and CIREN programs.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>\ud83c\uddea\ud83c\uddfa Europe, NIS2<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">Europe was a <strong>pioneer<\/strong> on the subject of critical infrastructure resilience. In 2016, the NIS1 Directive had already laid the groundwork for a regulatory framework well before the Five Eyes&#8217; operational guides. NIS2 (2022) significantly expanded the initiative.<\/p>\n<p style=\"font-weight: 400;\">Where the Five Eyes chose a <strong>directly operational approach<\/strong>, Europe took a <strong>regulatory route<\/strong>. The ambition is broader and the framework more structurally enduring over the long term\u2026 but implementation is noticeably slower.<\/p>\n<p style=\"font-weight: 400;\">In France, the <strong>Resilience Law<\/strong>, which transposes NIS2 among other directives, is expected in <strong>July 2026<\/strong>. ANSSI therefore published <strong>ReCyF v2.5<\/strong> in March 2026, encouraging organizations to take ownership of the subject without waiting and to apply the recommended measures to meet NIS2&#8217;s security objectives.<\/p>\n<p>&nbsp;<\/p>\n<p><!-- ============================================================ SECTION \u2014 What These Guides Have in Common ============================================================ --><\/p>\n<h3><span style=\"color: #28e39c;\"><strong>What These Guides Have in Common<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">Despite different formats and national contexts, a <strong>common set of recommendations converges<\/strong>:<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> <strong>Inventory<\/strong> all OT assets, their dependencies, and their external connections.<\/p>\n<p style=\"font-weight: 400;\">All initiatives place the <strong>comprehensive inventory of OT assets<\/strong> as a non-negotiable prerequisite for any resilience strategy.<\/p>\n<p style=\"font-weight: 400;\">The inventory must be <strong>continuous<\/strong> (OT environments change), <strong>classified by criticality<\/strong> (not all assets carry the same importance for continuity of service), and <strong>inclusive of enabling systems<\/strong> (authentication servers, DNS, NTP, license servers, backup systems) whose failure can render OT assets inoperable.<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> <strong>Identify the vital systems<\/strong> required to maintain a minimum level of service.<\/p>\n<p style=\"font-weight: 400;\">In an OT environment with hundreds or thousands of assets, it is unrealistic (and counterproductive) to protect everything at the same level. Complexity explodes, costs become unmanageable, and operational teams, already understaffed for cybersecurity, find themselves overwhelmed.<\/p>\n<p style=\"font-weight: 400;\">Rather than deploying uniform protection and then managing exceptions, the approach is to first identify the assets whose failure would cause a production shutdown or a safety risk, and to concentrate maximum protection on that restricted perimeter: hardware isolation, offline backups, tested reconstruction procedures.<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> <strong>Reduce the attack surface<\/strong> by removing obsolete or unnecessary assets, flows, and access points.<\/p>\n<p style=\"font-weight: 400;\">Asset discovery is not merely a mapping exercise. It must also lead to an <strong>active reduction of the attack surface<\/strong> by identifying and removing assets, flows, and access points that are no longer necessary for operational functioning.<\/p>\n<p style=\"font-weight: 400;\">Experience shows that OT environments accumulate over time obsolete equipment left connected, remote access credentials for contractors that were never revoked, network flows configured for a one-off project and then forgotten, protocols enabled by default but never used. Each of these elements constitutes a potential entry point for an attacker. The Volt Typhoon campaigns specifically exploited forgotten edge devices (SOHO routers, unpatched VPN appliances) to establish their access.<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> <strong>Proactively isolate<\/strong> critical OT systems from IT networks and the Internet, with a tested capability to operate in isolated mode for weeks to months.<\/p>\n<p style=\"font-weight: 400;\">The capability for <strong>proactive isolation of vital OT systems<\/strong> must be viewed not as an improvised last resort, but as a planned, tested, and mastered capability.<\/p>\n<ul style=\"font-weight: 400;\">\n<li>A <strong>verifiable physical or logical separation<\/strong> between OT networks and IT\/Internet networks: not merely firewall rules, but a protocol break guaranteeing that no network packet can cross the boundary in an uncontrolled manner. The system must allow vital functions to keep running with the minimum connectivity required.<\/li>\n<li><strong>Identified and documented isolation points<\/strong> enabling rapid disconnection of critical OT segments.<\/li>\n<li><strong>Verified offline backups<\/strong> of firmware, configurations, and documentation, enabling reconstruction without dependency on online services.<\/li>\n<li><strong>Manual failover procedures<\/strong> for automated processes that cross the OT\/IT boundary.<\/li>\n<li><strong>Regular testing<\/strong> of these procedures, because isolation that has never been exercised is isolation that will fail when it is needed.<\/li>\n<\/ul>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> <strong>Detect<\/strong> threats and anomalies continuously across the entire infrastructure, including through threat hunting before any reconnection following a period of isolation.<\/p>\n<p style=\"font-weight: 400;\">In OT environments, detection cannot rely on the same approaches as in IT. Industrial networks change little: a new flow, a new piece of equipment, a change in behavior are all significant signals.<\/p>\n<p style=\"font-weight: 400;\">The most appropriate approach is to <strong>detect deviations from a known baseline state<\/strong>, rather than attempting to identify each threat individually. Unlike the approach favored in IT, this method produces fewer false positives and is better suited to operational teams that are not sized to handle hundreds of daily alerts.<\/p>\n<p style=\"font-weight: 400;\"><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> <strong>Prepare for reconstruction<\/strong> from verified offline backups.<\/p>\n<p style=\"font-weight: 400;\">Backups must be stored on media physically disconnected from the network (air-gapped) to prevent any intentional degradation. They must be verified regularly: an untested backup is a promise, not a guarantee. Restoration procedures must be documented and exercised, ideally under conditions close to the actual scenario, meaning without Internet access, without remote vendor support, and with teams that may never have performed a full reconstruction.<\/p>\n<p>&nbsp;<\/p>\n<p><!-- ============================================================ SECTION 3 \u2014 The Seclab Approach ============================================================ --><\/p>\n<h3><span style=\"color: #28e39c;\"><strong>3. The Seclab Approach: From Assessment to Action<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\">The converging recommendations from these initiatives are reflected in the approach of the Seclab Xcore platform. This approach structures the OT cybersecurity journey into three phases: Discover, Isolate, Detect. Each phase delivers immediate value and prepares the next, without requiring a monolithic deployment or interrupting production.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>Phase 1: DISCOVER, building a thorough understanding of the OT environment<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Identify all OT assets and flows.<\/strong> This is the starting point. You cannot protect what you do not know. The Seclab Xplore module performs a non-intrusive mapping of all equipment connected to the OT network and USB ports in use, without injecting traffic or disrupting processes. The objective: obtain an accurate picture of what actually exists in the field, including forgotten equipment, undocumented connections, and unauthorized flows.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Build a structured inventory, a flow matrix, and a network map.<\/strong> Raw identification is not enough. Information must be structured: classifying assets by type, function, and zone; mapping flows between equipment and between zones; and producing a network representation that is usable by both IT and OT teams. This structured inventory is the deliverable required by the Australian agency, by the Canadian CIREN, and by NIS2 (Article 21). It also constitutes the essential foundation for any IEC 62443 audit or compliance assessment.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Identify vulnerabilities and assess risks.<\/strong> Based on the inventory, each asset is cross-referenced against known vulnerabilities, risky configurations, and network exposures. The objective is to produce a prioritized risk assessment that distinguishes critical vulnerabilities, those that could be exploited to compromise an industrial process, from secondary risks.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Define the critical assets to be protected (MVDI) and the business flows to be authorized.<\/strong> This is the decisive step. All initiatives ask for the identification of &#8220;vital systems&#8221; (Australia), the &#8220;minimal service in isolated mode&#8221; (United States), and &#8220;essential functions&#8221; (Canada). Seclab formalizes this concept under the name <strong>MVDI (Minimum Viable Digital Industry)<\/strong>: the minimal perimeter of digital assets whose continuity is indispensable for maintaining industrial operations. This means identifying assets whose failure would cause a production shutdown or a safety risk, the enabling systems that support them, and the business flows strictly necessary for their operation. The MVDI is the digital survival foundation of the plant.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>Phase 2: ISOLATE, deploying discovery-guided protection<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Isolate critical assets (MVDI) at the network level.<\/strong> This is the heart of the resilience promise. The guides call for a verifiable separation between OT and IT networks, not merely firewall rules. The Volt Typhoon and Salt Typhoon campaigns specifically exploited software security equipment (unpatched Fortinet devices, compromised SOHO routers) to maintain their access for years. When an attacker is already in the IT network with privileged access, software-based separation between IT and OT becomes a digital Maginot Line.<\/p>\n<p><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Seclab Xchange<\/strong> meets this requirement through <strong>electronic isolation<\/strong> that creates a true <strong>hardware airgap<\/strong> between the two networks. Seclab&#8217;s Electronic AirGap technology <strong>physically breaks the network protocol<\/strong>. There is no direct network path between the two sides. Authorized data is reconstructed and transferred across this hardware break, in strict compliance with the defined security policy (direction of transfer, file types, protocols). This hardware airgap <strong>cannot be corrupted by an attacker<\/strong>, even if they have administrative access on one side of the boundary. The result: isolation that allows only the flows necessary for operational functioning to pass through, while guaranteeing that no network attack can cross the boundary, including zero-days.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Secure legacy or disconnected critical assets via USB isolation.<\/strong> Some MVDI equipment is not connected to the network: PLCs at remote sites, supervision workstations in restricted areas, legacy systems with no network interface. For these environments, <strong>USB is the only means of interacting with OT machines and equipment<\/strong>. Firmware updates, loading PLC recipes, exporting logs, transferring configurations: everything goes through a USB drive.<\/p>\n<p style=\"font-weight: 400;\">This is also the case in the extended isolation scenarios described by CI Fortify and CIREN: when network connections are cut for weeks or months, USB media becomes the last operational lifeline. Yet this vector is also one of the most exploited in OT environments (37% of OT threats are designed to spread via USB, according to Honeywell). <strong>USB isolation<\/strong> therefore becomes indispensable. <strong>Seclab Xport<\/strong>, plugged between the USB media and the critical workstation, creates a hardware control point: file integrity and authenticity verification, blocking of physical attacks, and directional transfer control. It is fully plug-and-play and requires no software installation.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Segment non-critical assets with standard security equipment.<\/strong> Not all OT assets fall within the MVDI. For non-critical systems, conventional network segmentation (industrial firewalls, VLANs, DMZ zones) remains appropriate and proportionate. The discovery carried out during the DISCOVER phase makes it possible to size this segmentation based on actual knowledge of flows, rather than on assumptions.<\/p>\n<p>&nbsp;<\/p>\n<h3><span style=\"color: #28e39c;\"><strong>Phase 3: DETECT, continuously monitoring threats and anomalies<\/strong><\/span><\/h3>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Maintain continuous monitoring of changes.<\/strong> The OT environment evolves: new connected equipment, modified flows, added remote access points. Seclab Xplore provides continuous monitoring that detects any deviation from the baseline state established during the Discover phase. A new asset, an unexpected flow, a USB port used on a workstation where it should not be: these are all signals that trigger an alert before they become attack vectors.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Detect threats and anomalies in real time.<\/strong> Beyond change tracking, Seclab Xplore incorporates three complementary detection engines (Sigma signatures, Suricata, AI) to identify ongoing attacks: network scans, connection attempts on industrial ports such as Modbus or S7, abnormal PLC behavior, lateral movements. Isolation of the MVDI mechanically reduces the monitoring perimeter and the volume of alerts, concentrating detection where it is most needed.<\/p>\n<p style=\"font-weight: 400;\"><strong><img decoding=\"async\" class=\"emoji\" role=\"img\" draggable=\"false\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/svg\/2705.svg\" alt=\"\u2705\" \/> Adapt isolation or segmentation in response.<\/strong> Detection only has value if it leads to action. When a threat is confirmed on a non-critical segment, the response may consist of strengthening segmentation, temporarily isolating an additional zone, or tightening the filtering policies on Seclab Xchange. The model thus loops back on itself: detection feeds protection, which feeds detection.<\/p>\n<p style=\"font-weight: 400;\">For more information: <a href=\"https:\/\/www.seclab-security.com\/en\/ot-defense-in-depth\/\"><strong>Seclab Xcore, Defense in Depth OT<\/strong><\/a><\/p>\n<p>&nbsp;<\/p>\n<p><!-- ============================================================ SECTION Sources ============================================================ --><\/p>\n<h3><span style=\"color: #28e39c;\"><strong>Sources<\/strong><\/span><\/h3>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 CISA, <em>CI Fortify<\/em>, May 2026 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.cisa.gov\/topics\/industrial-control-systems\/ci-fortify\" data-fusion-font=\"true\">https:\/\/www.cisa.gov\/topics\/industrial-control-systems\/ci-fortify<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 CISA, FBI, NSA et al., <em>Advisory AA26-097A<\/em>, April 2026 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\" data-fusion-font=\"true\">https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 NCSC UK, <em>CNI Guide<\/em>, January 2026 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.ncsc.gov.uk\/collection\/how-to-prepare-and-plan-your-organisations-response-to-severe-cyber-threat-a-guide-for-cni\" data-fusion-font=\"true\">https:\/\/www.ncsc.gov.uk\/collection\/how-to-prepare-and-plan-your-organisations-response-to-severe-cyber-threat-a-guide-for-cni<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 ASD\/ACSC, <em>CI Fortify<\/em>, October 2025 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.cyber.gov.au\/business-government\/secure-design\/operational-technology-environments\/ci-fortify\" data-fusion-font=\"true\">https:\/\/www.cyber.gov.au\/business-government\/secure-design\/operational-technology-environments\/ci-fortify<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 Canadian Centre for Cyber Security, <em>CIREN<\/em>, April 2026 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.cyber.gc.ca\/en\/cyber-security-readiness\/critical-infrastructure-resilience-escalated-threat-navigation-initiative\" data-fusion-font=\"true\">https:\/\/www.cyber.gc.ca\/en\/cyber-security-readiness\/critical-infrastructure-resilience-escalated-threat-navigation-initiative<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 ANSSI, <em>NIS2 Directive and ReCyF<\/em>, March 2026 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/cyber.gouv.fr\/reglementation\/cybersecurite-systemes-dinformation\/directives-nis-nis2-et-dispositif-saiv\/directive-nis-2\/\" data-fusion-font=\"true\">https:\/\/cyber.gouv.fr\/reglementation\/cybersecurite-systemes-dinformation\/directives-nis-nis2-et-dispositif-saiv\/directive-nis-2\/<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 METI Japan, <em>OT Security Guidelines<\/em>, October 2025 &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.meti.go.jp\/english\/policy\/safety_security\/cybersecurity\/index.html\" data-fusion-font=\"true\">https:\/\/www.meti.go.jp\/english\/policy\/safety_security\/cybersecurity\/index.html<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 CISA, <em>Advisory AA24-038A (Volt Typhoon)<\/em> &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa24-038a\" data-fusion-font=\"true\">https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa24-038a<\/a><\/p>\n<p><span style=\"font-size: 20px;\" data-fusion-font=\"true\">\u2022 Seclab, <em>Xcore Platform<\/em> &#8211; <\/span><a style=\"font-size: 20px;\" href=\"https:\/\/www.seclab-security.com\/en\/ot-defense-in-depth\/\" data-fusion-font=\"true\">https:\/\/www.seclab-security.com\/en\/ot-defense-in-depth\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Resilience of Operational and Critical Infrastructures: When States Talk About  [&#8230;]<\/p>\n","protected":false},"author":9,"featured_media":3953,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[83],"tags":[],"class_list":["post-3961","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Resilience of critical OT infrastructure<\/title>\n<meta name=\"description\" content=\"Inventory, isolation of critical systems, detection, backup management: key government recommendations for 2026.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Resilience of critical OT infrastructure\" \/>\n<meta property=\"og:description\" content=\"Inventory, isolation of critical systems, detection, backup management: key government recommendations for 2026.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"Seclab Security\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-26T09:42:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-10T08:50:20+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/05\/Isolation-1024x572.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"572\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Matthieu Bonenfant\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Matthieu Bonenfant\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"20 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/\"},\"author\":{\"name\":\"Matthieu Bonenfant\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#\\\/schema\\\/person\\\/778932625df52311f75b667fc76cf7b1\"},\"headline\":\"Resilience of Operational and Critical Infrastructures: When States Talk About Isolation\",\"datePublished\":\"2026-05-26T09:42:57+00:00\",\"dateModified\":\"2026-06-10T08:50:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/\"},\"wordCount\":2841,\"publisher\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.seclab-security.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/Isolation-scaled.png\",\"articleSection\":[\"Blog\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/\",\"url\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/\",\"name\":\"Resilience of critical OT infrastructure\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.seclab-security.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/Isolation-scaled.png\",\"datePublished\":\"2026-05-26T09:42:57+00:00\",\"dateModified\":\"2026-06-10T08:50:20+00:00\",\"description\":\"Inventory, isolation of critical systems, detection, backup management: key government recommendations for 2026.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.seclab-security.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/Isolation-scaled.png\",\"contentUrl\":\"https:\\\/\\\/www.seclab-security.com\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/Isolation-scaled.png\",\"width\":2560,\"height\":1429,\"caption\":\"Futuristic image that represents IT\\\/OT isolation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/2026\\\/05\\\/26\\\/resilience-critical-infrastructures-isolation-ot-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Resilience of Operational and Critical Infrastructures: When States Talk About Isolation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/\",\"name\":\"Seclab Security\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#organization\",\"name\":\"Seclab Security\",\"url\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.seclab-security.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/LOGO-SECLAB-BLACK-1-e1772644859613.png\",\"contentUrl\":\"https:\\\/\\\/www.seclab-security.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/LOGO-SECLAB-BLACK-1-e1772644859613.png\",\"width\":250,\"height\":46,\"caption\":\"Seclab Security\"},\"image\":{\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/#\\\/schema\\\/person\\\/778932625df52311f75b667fc76cf7b1\",\"name\":\"Matthieu Bonenfant\",\"sameAs\":[\"http:\\\/\\\/www.seclab-security.com\"],\"url\":\"https:\\\/\\\/www.seclab-security.com\\\/en\\\/author\\\/mat59\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Resilience of critical OT infrastructure","description":"Inventory, isolation of critical systems, detection, backup management: key government recommendations for 2026.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/","og_locale":"en_US","og_type":"article","og_title":"Resilience of critical OT infrastructure","og_description":"Inventory, isolation of critical systems, detection, backup management: key government recommendations for 2026.","og_url":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/","og_site_name":"Seclab Security","article_published_time":"2026-05-26T09:42:57+00:00","article_modified_time":"2026-06-10T08:50:20+00:00","og_image":[{"width":1024,"height":572,"url":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/05\/Isolation-1024x572.png","type":"image\/png"}],"author":"Matthieu Bonenfant","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Matthieu Bonenfant","Est. reading time":"20 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#article","isPartOf":{"@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/"},"author":{"name":"Matthieu Bonenfant","@id":"https:\/\/www.seclab-security.com\/en\/#\/schema\/person\/778932625df52311f75b667fc76cf7b1"},"headline":"Resilience of Operational and Critical Infrastructures: When States Talk About Isolation","datePublished":"2026-05-26T09:42:57+00:00","dateModified":"2026-06-10T08:50:20+00:00","mainEntityOfPage":{"@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/"},"wordCount":2841,"publisher":{"@id":"https:\/\/www.seclab-security.com\/en\/#organization"},"image":{"@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/05\/Isolation-scaled.png","articleSection":["Blog"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/","url":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/","name":"Resilience of critical OT infrastructure","isPartOf":{"@id":"https:\/\/www.seclab-security.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/05\/Isolation-scaled.png","datePublished":"2026-05-26T09:42:57+00:00","dateModified":"2026-06-10T08:50:20+00:00","description":"Inventory, isolation of critical systems, detection, backup management: key government recommendations for 2026.","breadcrumb":{"@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#primaryimage","url":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/05\/Isolation-scaled.png","contentUrl":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/05\/Isolation-scaled.png","width":2560,"height":1429,"caption":"Futuristic image that represents IT\/OT isolation"},{"@type":"BreadcrumbList","@id":"https:\/\/www.seclab-security.com\/en\/2026\/05\/26\/resilience-critical-infrastructures-isolation-ot-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.seclab-security.com\/en\/"},{"@type":"ListItem","position":2,"name":"Resilience of Operational and Critical Infrastructures: When States Talk About Isolation"}]},{"@type":"WebSite","@id":"https:\/\/www.seclab-security.com\/en\/#website","url":"https:\/\/www.seclab-security.com\/en\/","name":"Seclab Security","description":"","publisher":{"@id":"https:\/\/www.seclab-security.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.seclab-security.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.seclab-security.com\/en\/#organization","name":"Seclab Security","url":"https:\/\/www.seclab-security.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.seclab-security.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/03\/LOGO-SECLAB-BLACK-1-e1772644859613.png","contentUrl":"https:\/\/www.seclab-security.com\/wp-content\/uploads\/2026\/03\/LOGO-SECLAB-BLACK-1-e1772644859613.png","width":250,"height":46,"caption":"Seclab Security"},"image":{"@id":"https:\/\/www.seclab-security.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.seclab-security.com\/en\/#\/schema\/person\/778932625df52311f75b667fc76cf7b1","name":"Matthieu Bonenfant","sameAs":["http:\/\/www.seclab-security.com"],"url":"https:\/\/www.seclab-security.com\/en\/author\/mat59\/"}]}},"_links":{"self":[{"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/posts\/3961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/comments?post=3961"}],"version-history":[{"count":9,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/posts\/3961\/revisions"}],"predecessor-version":[{"id":3971,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/posts\/3961\/revisions\/3971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/media\/3953"}],"wp:attachment":[{"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/media?parent=3961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/categories?post=3961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.seclab-security.com\/en\/wp-json\/wp\/v2\/tags?post=3961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}