Government Advisory

New Guidance Urges Businesses to Isolate Critical Operational Technology from Other Networks

ACSC · 28 July 2026
Key Takeaway Review how your business network is structured and separate any critical equipment or operational systems from general internet-connected devices to limit the damage a cyber attack can cause.

The Australian Cyber Security Centre (ACSC) has published new guidance encouraging organisations that rely on operational technology (OT) — such as industrial control systems, equipment, and enabling infrastructure — to isolate these systems from their broader IT networks. The advice highlights network isolation as a proactive defence measure that can make it significantly harder for attackers to reach and compromise essential systems.

According to the ACSC, properly isolating OT and enabling systems serves three key purposes: it disrupts an attacker's ability to launch a successful attack in the first place, helps contain any breach that does occur before it spreads further, and ensures essential services can keep running even during a broader cyber incident or network disruption. This is particularly relevant for organisations where OT downtime could affect physical operations, safety, or service delivery.

While OT systems are often associated with larger critical infrastructure operators, many small and medium businesses also rely on connected equipment, building management systems, or industrial devices that could be exposed if not properly segmented from general business networks. The ACSC's guidance is a reminder that network architecture decisions play a major role in limiting the impact of cyber attacks.

operational technology network segmentation ACSC guidance

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.