Skip to main content
Guidance

How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI

Act now to be ready to withstand and recover from severe cyber attacks.

Page 16 of 26

3.3 Plan how to harden networks rapidly in event of severe cyber threat

Network hardening both reduces the likelihood of successful attacks and limits the impact of any breaches that do occur. You should undertake the following activities now to be ready to escalate hardening of networks later, if required.


Note that some hardening measures will impact other security activities. For example, network segmentation may affect your ability to patch or monitor systems effectively.


There are 3 primary isolation strategies:

Isolation strategySupporting information
Site-based isolation separates entire physical or logical sites from one another. Each site operates as an independent security boundary, with inter-site connectivity tightly controlled or completely disabled.
  • Segment network traffic by geographical or organisational site boundaries.
  • Any necessary inter-site traffic must be controlled via gateways, firewalls, or preferably using a Cross Domain solution.
Application/service specific isolation isolates individual applications or services rather than whole sites. Each application is placed in its own protected network segment or enclave.
  • Implement fine-grained segmentation using VLANs, Virtual Routing and Forwarding (VRF), micro-segmentation, or zero trust principles.
  • Access controls must be defined per application or service.
  • Isolation practices should be documented as an operationally usable set of actions, and tested.
  • Ensure isolation isn’t undermined by underlying platforms supporting the applications
Site isolation with hardware enforced trusted communications combines site-level isolation with dedicated hardware that enforces secure, trusted communications between sites.
  • Implement technology that is designed to provide a security boundary and has independent verification, this could include hardware based solutions.
  • Network traffic should only be permitted over explicitly authorised, hardware-enforced channels.

Published

Reviewed

Version

1.0