How to prepare for and plan your organisation's response to severe cyber threat: a guide for CNI
Pages
Page 16 of 26
3.3 Plan how to harden networks rapidly in event of severe cyber threat
Network hardening both reduces the likelihood of successful attacks and limits the impact of any breaches that do occur. You should undertake the following activities now to be ready to escalate hardening of networks later, if required.
3.3.1 Network segmentation
As highlighted in the NCSC’s secure design principles, segmenting networks is a highly effective strategy for containing breaches and preventing attackers from moving laterally across your network whilst ensuring continuity of operations and services.
You should:
-
Decide and document how you will plan, design, enforce and monitor network segmentation. Decisions on how to segment a network will typically consider the protections different assets require, their need for interaction with other assets, and the extent to which their integrity is trusted. The ACSC’s guidance on implementing network segmentation and segregation provides details of how to do this.
-
Implement segmentation based on business functions and security zones to help contain a compromise to the segment that has been breached. This enables you to better protect business functions that are most sensitive or valuable, and it supports the ability to limit or examine communication flows between segments.
-
Use the intelligence gathered from situational awareness activities to prioritise segmentation actions.
Note that some hardening measures will impact other security activities. For example, network segmentation may affect your ability to patch or monitor systems effectively.
3.3.2 Network isolation, or islanding
Islanding isolates parts of a network, or entire systems, from broader connectivity such as the internet or enterprise IT networks. This is an extreme option for hardening infrastructure against cyber threats, however may sometimes be necessary if robust data flow controls (in line with NCSC’s Secure Connectivity guidance) are not in place.
You should:
-
Define your isolation process, taking into account any potential impacts to wider business and making it part of your wider business continuity plans.
-
Where possible, design systems so that critical functions are not dependent on external network components or services. This reduces the impact from compromise and helps avoid single points of failure, including dependencies on less trusted or less resilient parts of the system. If this isn’t possible, ensure you fully understand the dependencies of your systems and any impact that islanding may have. Refer to the NCSC’s Secure Connectivity Guidance’s section on data flow security.
-
Agree with vendors the conditions under which it will be acceptable to drop connections.
-
Define which services you would agree to disable in the event of severe cyber threat – which would not normally be a proportionate response.
-
For organisations managing multiple sites, develop both site-specific isolation plans and comprehensive strategies addressing large-scale isolation requirements. Consider scenarios where a crucial infrastructure component is compromised, potentially enabling lateral movement across all sites.
-
Consider the risks of implementing islanding, particularly losing visibility of logging and monitoring.
There are 3 primary isolation strategies:
| Isolation strategy | Supporting information |
|---|---|
| Site-based isolation separates entire physical or logical sites from one another. Each site operates as an independent security boundary, with inter-site connectivity tightly controlled or completely disabled. |
|
| Application/service specific isolation isolates individual applications or services rather than whole sites. Each application is placed in its own protected network segment or enclave. |
|
| Site isolation with hardware enforced trusted communications combines site-level isolation with dedicated hardware that enforces secure, trusted communications between sites. |
|
3.3.3 Risks of islanding – and alternative approaches
While full site isolation can be an effective response in extreme scenarios, it may not be practical or sustainable for all organisations, particularly in a non-severe threat environment. To have confidence in alternatives to site‑wide isolation, organisations need to invest in security controls early in the system lifecycle.
Well‑designed segmentation, strong access control, and hardware-based security controls can reduce reliance on site-wide islanding as a defensive measure. These approaches can provide improved visibility during incidents and support business continuity for critical services – allowing a proportionate response to cyber threats, even during severe incidents.
Even when operating in island mode, organisations will likely need to import or export data. You should design secure data flows to support any business‑critical data transfers and ensure that monitoring and logging remain effective. Further guidance on secure connectivity and segmentation is available in the NCSC’s secure connectivity for operational technology principles.


