<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=2975524&amp;fmt=gif">
BLOG

How Garland Technology Supports ASD’s CI Fortify Guidance

August 13, 2026

HOW-GARLAND-TECHNOLOGY-SUPPORTS-ASD’S-CI-FORTIFY-GUIDANCE

Editor’s Note: This blog was written by Garland Techology’s Technical Director for APJ, Ben Burt.

  • Garland Technology’s visibility hardware (Network TAPs, Network Packet Brokers, and Hardware Data Diodes) align with the Australian Signals Directorate’s (ASD) CI Fortify guidance to help OT operators maintain service continuity during long-term isolation scenarios.
  • Packet‑level visibility from Network TAPs exposes undocumented connections and dependencies critical for planning and validating isolation controls across OT environments.
  • Aggregating and delivering traffic to security tools without introducing inline risk or relying on production switching infrastructure preserves monitoring during isolation.
  • Hardware Data Diodes enable one‑way transfer packet-level data out of isolated networks without creating a return path, supporting ASD guidance for secure data flow.


Introduction

Garland Technology provides the network visibility layer that security, monitoring and performance tools depend on. Our portfolio includes Network TAPs, Aggregators, Network Packet Brokers, Inline Bypass solutions and Hardware Data Diodes. These products help organisations capture, aggregate, filter, and deliver the right network traffic to their tools.

These capabilities support OT and ICS networks, enterprise environments, data centres, service providers and government networks. They become especially relevant in critical infrastructure, where visibility must not affect the availability or integrity of operational systems.

The Australian Signals Directorate’s (ASD) CI Fortify guidance highlights one such use case. It asks critical infrastructure operators to prepare for a serious but realistic scenario: isolating vital operational technology and enabling systems while continuing to deliver critical services.

The guidance sets two main objectives:

  1. Maintain critical services while vital systems remain isolated for up to three months.
  2. Be able to rebuild vital systems completely if their integrity can no longer be trusted.

ASD’s more recent Advice for Isolating Vital Systems provides further detail on how operators should build, test, and monitor this capability.

This includes identifying vital systems, mapping connections, creating isolation points, testing graduated isolation plans, and monitoring the environment throughout the isolation period.

Garland Technology supports several parts of this architecture through Network TAPs, Network Packet Brokers, and Hardware Data Diodes.


Understanding the environment before isolation

You cannot isolate vital systems if you do not understand how they communicate.

ASD recommends identifying all connections between critical networks and other environments, including:

  • Corporate IT systems
  • Remote access services
  • Vendors and third parties
  • Cloud services
  • Carrier networks
  • Other critical infrastructure operators
  • Shared identity, DNS, time and backup services

Network diagrams and asset inventories provide a starting point. They do not always show active connections, undocumented dependencies, or changes made since the diagram was created.

Garland Technology Network TAPs provide packet-level visibility from critical network links. This allows OT security, IDS, and NDR platforms to identify communication paths and dependencies using the actual traffic that crosses the network.

Unlike SPAN mirroring, a Network TAP does not rely on switch configuration and is not affected by switch resource constraints or SPAN oversubscription.

Passive Network TAPs also have no IP address, MAC address, or management interface. They provide visibility without becoming another addressable device on the production network.

This helps operators validate their environment and identify where isolation controls may need to be placed.


Maintaining visibility during isolation

Isolation should not mean losing visibility of the systems being protected.

ASD states that operators must monitor the effectiveness of isolation controls when isolation begins and throughout the isolation period. This includes monitoring network flows and looking for unauthorised or unintended connections between critical and non-critical networks.

Garland Technology Network TAPs can provide continuous access to traffic at key points inside the OT environment and around isolation boundaries.

Network Packet Brokers can then aggregate, filter, and distribute that traffic to the required monitoring platforms.

This allows security tools to continue monitoring the environment without sitting inline or becoming part of the production traffic path.

It also gives operators a source of packet data that does not depend on the same switches, VLANs, or routing policies being monitored.

This becomes especially important when operators need to confirm that an isolation control remains effective and that no unexpected connection has been introduced.


Getting monitoring data out without creating a return path

One of the biggest questions during isolation is what data still needs to leave the protected environment. Security and operations teams may still need access to:

  • Packet data
  • Syslog messages
  • Security events
  • Alarms
  • Telemetry
  • Other operational data feeds

Using a standard network connection to send this information outside the isolated environment can create a return path into the systems being protected.

ASD specifically recommends considering data diodes and/or cross-domain solutions when information must move between critical and non-critical networks.

Garland Technology Hardware Data Diodes provide a physically enforced one-way data path.

Data can leave the protected environment, but traffic cannot return through the same connection. This is enforced by the hardware rather than a firewall rule, routing policy, or software configuration.

This allows supported monitoring data to be sent to an OT security, IDS, SIEM, or NDR platform outside the isolated environment without creating a bidirectional network path back into vital systems.

For example, a Garland Technology Hardware Data Diode can support a one-way packet feed from an isolated OT network to an external monitoring platform.

The security team maintains visibility. The protected environment does not receive traffic from the monitoring network.


Selecting the right one-way architecture

ASD also warns that data diodes must be deployed correctly.

Some applications and protocols require acknowledgements, session establishment, or other return traffic. These applications will not work across a basic Hardware Data Diode because the return path does not exist.

This distinction must be understood during the design.

Garland Technology Hardware Data Diodes suit use cases where data needs to move in one direction and the application can operate without a response. Common examples include packet feeds and connectionless syslog, event, and telemetry traffic.

A cross-domain solution may include application proxies or other services to support more complex data-transfer requirements.

Garland Technology does not provide the complete cross-domain solution. We provide the physically enforced one-way network path for supported data flows.

The application, protocol and required direction of traffic should always be confirmed before selecting the architecture.


Supporting physical separation

ASD describes physical isolation as the most effective form of protection for vital systems. Physical separation means critical and non-critical networks do not share active infrastructure such as switches, routers, repeaters or compute platforms.

Garland Technology Network TAPs and Network Packet Brokers do not replace the controls used to disconnect or isolate these environments. Their role is to provide the visibility layer around those controls.

Garland Technology can support the architecture by providing:

  • Passive access to traffic on critical network links
  • Independent packet visibility at isolation boundaries
  • Aggregation and distribution of monitoring traffic
  • Physically enforced one-way data movement
  • Continued visibility before, during and after isolation

This helps operators maintain access to the network data their monitoring tools need without introducing another bidirectional connection into the protected environment.


Building the capability before it is needed

CI Fortify is not asking operators to produce an isolation plan that only exists on paper. ASD recommends building, testing and regularly reviewing the capability to isolate vital systems while maintaining critical services.

Garland Technology can help design the visibility and one-way data movement components of that capability.

The design should start with several practical questions:

  1. Where are the vital systems and network boundaries?
  2. Which connections must be removed during isolation?
  3. What monitoring must continue?
  4. Where are the monitoring tools located?
  5. What information still needs to leave the isolated environment?
  6. Can those data flows operate without acknowledgements or return traffic?
  7. How will the organisation confirm that isolation remains effective?

Answering these questions early allows Network TAPs, Network Packet Brokers and Hardware Data Diodes to become part of the isolation architecture before an incident occurs.

Looking to adhere to the Australian Signals Directorate’s CI Fortify guidance, but not sure where to start? Join us for a brief network Design-IT consultation or demo. No obligation - it’s what we love to do.

See Everything. Secure Everything.

Contact us now to secure and optimized your network operations

Heartbeats Packets Inside the Bypass TAP

If the inline security tool goes off-line, the TAP will bypass the tool and automatically keep the link flowing. The Bypass TAP does this by sending heartbeat packets to the inline security tool. As long as the inline security tool is on-line, the heartbeat packets will be returned to the TAP, and the link traffic will continue to flow through the inline security tool.

If the heartbeat packets are not returned to the TAP (indicating that the inline security tool has gone off-line), the TAP will automatically 'bypass' the inline security tool and keep the link traffic flowing. The TAP also removes the heartbeat packets before sending the network traffic back onto the critical link.

While the TAP is in bypass mode, it continues to send heartbeat packets out to the inline security tool so that once the tool is back on-line, it will begin returning the heartbeat packets back to the TAP indicating that the tool is ready to go back to work. The TAP will then direct the network traffic back through the inline security tool along with the heartbeat packets placing the tool back inline.

Some of you may have noticed a flaw in the logic behind this solution!  You say, “What if the TAP should fail because it is also in-line? Then the link will also fail!” The TAP would now be considered a point of failure. That is a good catch – but in our blog on Bypass vs. Failsafe, I explained that if a TAP were to fail or lose power, it must provide failsafe protection to the link it is attached to. So our network TAP will go into Failsafe mode keeping the link flowing.

Glossary

  1. Single point of failure: a risk to an IT network if one part of the system brings down a larger part of the entire system.

  2. Heartbeat packet: a soft detection technology that monitors the health of inline appliances. Read the heartbeat packet blog here.

  3. Critical link: the connection between two or more network devices or appliances that if the connection fails then the network is disrupted.

NETWORK MANAGEMENT | THE 101 SERIES