2 min read

CISA's CI Fortify quietly concedes that eviction alone has failed- 222

CISA's CI Fortify quietly concedes that eviction alone has failed- 222

May 6, 2026

The Cybersecurity and Infrastructure Security Agency has a new answer to a question it has spent three years failing to close out: what happens when a state-backed intrusion into critical infrastructure simply cannot be evicted. CI Fortify, unveiled this week, asks critical infrastructure operators to stop treating "find and remove the hackers" as the primary defense and instead prepare to isolate, operate blind, and recover fast — a quiet admission that Volt Typhoon, and adversaries like it, are already too deeply embedded to fully root out.

CISA frames CI Fortify as guidance for organizations to prepare for technology and telecommunications outages caused by cyberattacks, built around proactive disconnection from third-party dependencies and the ability to restore compromised systems while isolated from the network. Acting Director Nick Andersen described it as timely, actionable guidance to protect networks from actors seeking to degrade or disrupt infrastructure, and said CISA will conduct targeted assessments of critical infrastructure organizations, though he declined to specify how many or where.

The initiative's own reference material tells the more pointed story: the first link on the CI Fortify site is a 2024 CISA advisory on Volt Typhoon, the Chinese state-linked campaign that prepositioned inside U.S. critical infrastructure to enable destructive action in the event of a kinetic conflict. Former CISA director Jen Easterly claimed in 2024 that the agency had found and eradicated Volt Typhoon intrusions across multiple sectors, and repeated in 2025 that the goal remained to identify and evict Chinese cyber actors. Yet researchers have continued to report that Chinese hackers remain deeply embedded in U.S. critical infrastructure systems even after three years of law enforcement effort, and CISA's own advisory acknowledges some victims were first breached as far back as 2019 — with Volt Typhoon known to re-target the same organizations and retain stolen domain credentials for repeated access. Andersen publicly denied that CI Fortify targets Volt Typhoon specifically, framing it instead as protection against destructive OT impact from any nation-state actor, and pointed to Russian-linked attacks on Polish OT networks earlier this year as an equally relevant reference case.

Cybersecurity expert Matthew Hartman put the strategic shift plainly: eviction remains the objective, but it cannot be the only strategy against actors already embedded deeply enough that removal is no longer a near-term, deterministic outcome. Segmentation and resilience — assuming compromise and limiting blast radius rather than chasing a constantly reconstituting threat — is the pragmatic alternative. Andersen tied the urgency of that shift directly to artificial intelligence, telling reporters that CISA and the current administration have discussed at length how rapidly AI is set to change the speed and scale of impact for both IT and OT defenders. That concern is not abstract: incident response firm Dragos reported this week that a hacker used an AI model to compromise a municipal water and drainage utility in Monterrey, Mexico — a preview, on a smaller stage, of the exact velocity problem CI Fortify is meant to prepare critical infrastructure operators for.