Skip to content
Knowledge base Updated: February 5, 2026

The Air Gap Myth: Industrial Network Security in the Age of IT/OT Convergence

Do you believe your production network is secure because it is physically isolated from the rest of the world? This is one of the most dangerous myths in industrial cyber security. The truth is that the

For decades, the world of industrial cyber security has been ruled by one powerful protective spell: “air gap,” or air gap. The idea was simple and elegant - the network that controls manufacturing processes (OT) is completely, physically isolated from the corporate network (IT) and, by extension, the Internet. Since there are no cables connecting the two worlds, no outside threat can penetrate. This belief gave managers and engineers a sense of comfort and allowed them to treat OT security as a largely solved problem.

Unfortunately, this comfort has proven to be an illusion. In today’s reality, driven by the need for optimization, data analytics and remote access, the “air gap” is no longer a myth. The advancing convergence of IT/OT, the growth of the Industrial Internet of Things (IIoT) and, just as importantly, day-to-day operational practices, have created countless, often invisible bridges connecting the once isolated islands of OT to the global ocean of the Internet. Maintaining faith in mythical isolation is not only a mistake - it is a strategic oversight that opens the door to catastrophic cyberattacks.

Shortcuts

What is the mythical “air gap” and why did it provide a sense of security?

The “air gap” concept dates back to the days when industrial control systems were simple, closed ecosystems. It defines a situation in which a computer network or device is physically isolated from other, unsecured networks, such as a corporate network or the public Internet. Physical isolation means the absence of any connections - either wired (Ethernet cables) or wireless (Wi-Fi, Bluetooth). The only way to transfer data to such a network was to use a physical medium, such as a floppy disk or CD.

The sense of security provided by the “air gap” was fully justified in that era. If a network had no connection to the outside world, it was immune to remote attacks. A hacker sitting thousands of miles away had no technical ability to get into the PLCs or SCADA system. The threat could only come from within - in the form of malware brought on physical media by an employee or service technician.

This simplicity and obviousness made the “air gap” the gold standard and almost dogma in OT security. Engineers were able to focus on the reliability and physical security of the process, assuming that the digital fortress was protected by the most powerful of firewalls - that is, the air gap. It was this belief in absolute isolation that allowed the need to implement more complex cyber security mechanisms inside the industrial network itself to be ignored for years.

📚 Read the complete guide: OT/ICS Security: Bezpieczeństwo systemów OT/ICS - różnice z IT, zagrożenia, praktyki

Why has IT/OT convergence become a business necessity?

The industrial world is not standing still. The pressure to increase productivity, reduce costs and respond more quickly to market changes has forced companies to look for new ways to optimize. It quickly became apparent that the most valuable yet untapped resource was the data generated by machines and manufacturing processes. To harness them, they had to be extracted from isolated OT networks and made available to analytical systems in the IT world.

Thus was born IT/OT convergence - the process of gradually merging and integrating these two, previously separate, technological worlds. The business case for this process cannot be disputed. Integration makes it possible to monitor production performance in real time, predict machine failures (predictive maintenance), optimize energy consumption or automate the supply chain through direct communication of ERP systems (in IT) with MES systems (in OT).

This transformation, known as Industry 4.0, is absolutely necessary from a business perspective to remain competitive. Companies that would have remained with fully isolated systems would have doomed themselves to stagnate and lose in the race for efficiency. Business necessity thus became the main driver that began to systematically and deliberately tear down the wall of the “air gap,” creating new digital bridges in the name of progress and profit.

What business benefits are driving the merging of industrial networks with the IT world?

The decision to combine OT and IT networks is never taken lightly; it is a conscious strategic choice motivated by specific, measurable benefits. One of the most important is the optimization of manufacturing processes. By transmitting sensor data to advanced analytics platforms, companies can identify bottlenecks, analyze the causes of downtime and make improvements that directly translate into increased production volumes and reduced costs.

Another huge benefit is predictive maintenance. Instead of replacing machine parts on a rigid schedule, artificial intelligence algorithms analyze data on vibration, temperature or energy consumption, predicting an upcoming breakdown well in advance. This allows service to be scheduled at a convenient time, avoiding costly unplanned downtime and maximizing the life of expensive components.

The third key driver is remote monitoring and management. Global corporations can centrally monitor the performance of their factories spread around the world. Machine manufacturers can offer remote diagnostics and service to their customers, significantly reducing response times to problems and lowering travel costs. All of these benefits - from optimization to prediction to remote management - require one thing: a constant and reliable flow of data between the physical world (OT) and the analytical world (IT).

What are the most common intentional connections between IT and OT networks?

Demolishing the “air gap” most often starts with the creation of purposeful, authorized connections to serve specific business goals. One of the most classic examples is the combination of an enterprise resource planning (ERP) system with a manufacturing execution system (MES). This connection allows production orders to be automatically sent from the business system directly to the production floor and to receive feedback on progress and raw material consumption.

Another common connection is a historian server, or historical database. This is a system that collects huge amounts of process data (e.g., temperature readings, pressures, flows) from SCADA systems and makes them available for analysis to engineers and analysts on the corporate network. To make this possible, the Historian server must be connected to both networks, becoming a de facto bridge between them.

Connections related to remote access for third-party service companies and system integrators are also increasingly common. Machine manufacturers require constant access to their equipment to monitor its condition and provide support services. These connections are usually made through VPNs, but if improperly configured, they can be an open gateway to the entire industrial network.

What are the “hidden bridges” that unknowingly tear down the OT network’s isolation?

In addition to intentional connections, there is a whole category of “hidden bridges” - unintentional and often undocumented connections that completely undermine the concept of isolation. It is very common that an engineering station, used for PLC programming, is equipped with two network cards. One is connected to an isolated OT network, and the other - for the engineer’s convenience - is connected to the IT office network so that he can access the Internet and mail. Such a computer becomes an unprotected router through which threats from IT can enter OT unhindered.

Another example is cellular modems (LTE) connected directly to devices on the OT network. These have been installed by an outside company to provide remote service, and no one in the organization is aware of their existence. Such a modem creates a direct connection to the Internet, completely bypassing any company firewalls and security systems.

This problem also applies to auxiliary systems, which are often overlooked in security analyses. Access control systems, video surveillance (CCTV) or even air conditioning controllers, while not directly part of the manufacturing process, are often connected to both OT and IT networks. Compromising one of these seemingly insignificant systems can serve an attacker as a jumping-off point to attack key control infrastructure.

Typical ways to unintentionally break the “Air Gap”

MethodDescription of the problemPotential consequencesComputer with two network cardsWorkstation connected simultaneously to the IT network (internet) and OT network (controllers).Creating an uncontrolled bridge through which malware can cross from IT to OT.Unauthorized LTE/Wi-Fi modemConnect a modem directly to a device on the OT network to provide remote access.Bypassing all corporate security measures and exposing the device to direct attack from the Internet.Improper firewall configurationOverly liberal rules on the firewall separating IT from OT (e.g., the “any-any” rule).Allowing uncontrolled communication and the spread of attacks between segments.Auxiliary systemsSystems such as CCTV or access control connected to both networks.Using a less secure auxiliary system as an entry point into the OT network.

How can a service technician’s laptop and a flash drive with an update create a digital highway for attackers?

Even if the network is theoretically fully isolated, the “air gap” can be breached using portable media and devices. The most classic example is the use of an infected flash drive. A service technician arrives with a new software version for a PLC. Unaware that his flash drive was previously infected with malware, he connects it to an engineering station on the OT network. At this point, the “air gap” is overcome and the malware can spread throughout the seemingly secure network. This is exactly how the famous Stuxnet worm worked.

An external service technician’s laptop poses a similar threat. Such a laptop is regularly connected to various networks at multiple clients, as well as to the public Internet, making it an ideal vector for transmitting threats. When a service technician connects his laptop directly to an OT network to diagnose a problem with the machine, he may inadvertently introduce malware into the machine.

This problem does not only apply to external companies. Internal maintenance employees who use the same laptops to work on the office network (browse the Internet, receive mail) and to connect to the production network pose identical risks. Any device that crosses the boundary between the IT and OT worlds is a potential Trojan horse.

How did the Industrial Internet of Things (IIoT) finally bury the idea of the “air gap”?

If IT/OT convergence was the process of tearing down the “air gap” wall, then the Industrial Internet of Things (IIoT) is its ultimate razing. IIoT is the concept of equipping a huge number of industrial devices - from individual sensors to entire machines - with the ability to communicate directly with the Internet and cloud platforms. The goal is to collect granular data on a massive scale and make it available for analysis anywhere in the world.

IIoT devices, by definition, break the idea of isolation. They are designed to connect directly to the cloud, often bypassing the traditional hierarchical network architecture. A new smart sensor on the production line can send its data over the cellular network directly to the manufacturer’s servers for analysis. From a security perspective, this means creating hundreds or even thousands of new individual connections to the outside world, each of which must be separately secured.

The rise of IIoT devices is dramatically increasing the attack surface. Many of these devices, especially the cheaper ones, have very weak built-in security, default passwords that cannot be changed, and software full of vulnerabilities. Managing security and updates in such a distributed and heterogeneous environment is a gigantic challenge, and ultimately proves that the concept of building security on physical isolation is now completely obsolete.

What new attack vectors arise when physical isolation disappears?

The disappearance of the “air gap” makes OT networks vulnerable to the same types of attacks that have plagued the IT world for years, but with potentially much more dangerous, physical consequences. Attackers can now remotely scan industrial networks for vulnerable devices and services exposed to the Internet, such as HMI panels or SCADA servers with an unsecured remote desktop.

One of the most serious threats is ransomware. Criminal groups that gain access to OT networks can encrypt key control systems, such as SCADA servers or engineering stations. In such a situation, the company faces a dire choice: pay the ransom, risking not recovering the data anyway, or face weeks of downtime for the entire plant and attempt to rebuild the systems from scratch, which can be extremely difficult or even impossible.

The combination of IT and OT also opens the door to multi-stage attacks. Attackers can first compromise a less-protected office network with classic phishing, and then use it as a beachhead to move slowly and cautiously toward the OT network (lateral movement). Once they gain access to the industrial network, they can stay hidden for months, mapping the infrastructure and preparing for the final strike, the goal of which may not only be to steal data, but to sabotage and cause physical damage.

Why is it necessary to move from the “I trust because isolated” mindset to “I assume a breach has already occurred”?

Since the myth of the “air gap” has collapsed, the entire philosophy of OT security must change. Relying on perimeter defense - that is, a single, strong border wall - no longer makes sense in a world where borders are virtually non-existent anymore. The modern approach must be based on a much more pessimistic yet realistic assumption, known as “assume breach.”

The “assume breach” philosophy means that we design our security systems on the assumption that the attacker is already inside our network or will be soon. Instead of focusing all our energy on preventing him from entering, we focus on making it as difficult as possible for him to operate once he is inside. The goal is to detect the intruder early, limit the damage he can do, and quickly remove him from our environment.

Such a shift in thinking has fundamental consequences. It leads to a move away from building a single, fragile line of defense to creating a multilayered architecture in which the compromise of one element does not lead to the collapse of the entire system. It forces the implementation of mechanisms that have hitherto been rare in the OT world: continuous monitoring, network segmentation and strict control over what happens inside the network, not just at its borders.

How does inventory and connection mapping become the foundation of a new strategy?

The first step in building a new security strategy based on the assumption of a breach is to answer the fundamental question, “what do I really have on my network?” You can’t protect something you don’t know about. Therefore, it becomes an absolute foundation to create and maintain an accurate, up-to-date inventory of all assets connected to the OT network.

This process must include not only a list of devices, such as PLCs, HMI stations or network switches, but also detailed information about them: manufacturer, model, firmware version, installed software and known vulnerabilities. Equally important is a thorough mapping of all connections - both those inside the OT network and those going out to the IT network or the Internet.

Only by having such a map can we begin to make informed decisions about risk. We can identify critical assets that need special protection, locate unauthorized “hidden bridges” that need to be removed, and understand what the potential attack paths are in our infrastructure. Without this foundation, any further security efforts will be mere guesswork.

What to replace the “air gap,” or the role of segmentation and monitoring in a modern OT network?

If the “air gap” no longer works, what should replace it? The answer is a combination of two key concepts: segmentation and monitoring. Network segmentation involves dividing a large, flat network into smaller, isolated zones using firewalls. This way, even if an attacker compromises one device, his ability to move around the network and attack other systems is greatly reduced. The firewall will block his path.

Properly implemented segmentation creates a series of “virtual air gaps” inside the network. For example, you can create a separate zone for each critical production line, and limit communication between these zones to only the absolute minimum. This approach, following the Purdue model, is one of the most effective ways to stop the spread of attacks such as ransomware.

Segmentation alone, however, is not enough. It must be accompanied by continuous monitoring of network traffic. Specialized OT network monitoring systems can passively analyze communications between devices and detect anomalies that may indicate an attack. They can alert you to an attempt to exploit a known vulnerability, an unauthorized attempt to program a PLC, or the appearance of a new, unknown device on the network. Monitoring allows you to see what’s going on inside your network and respond to threats in real time.

How to control the necessary connections to minimize risks?

Modern industry cannot function without connections between IT and OT. So the challenge is not to eliminate them altogether, but to control them tightly. Any connection between zones with different levels of trust, and especially between IT and OT networks, must pass through a demilitarized zone (DMZ), which acts as a controlled lock.

Intermediary servers are placed in the DMZ to prevent direct communication between a computer on the office network and a controller on the factory floor. All data exchange is strictly filtered by firewalls, which only allow authorized traffic through on specific ports and protocols. All traffic passing through the DMZ should be logged and monitored in detail.

Special attention should be paid to remote access. Instead of allowing service technicians to connect directly to machines via VPN, jump host solutions or privileged access management (PAM) systems should be implemented. The user first logs into a secure proxy server, and only from there does he or she gain controlled and monitored access to a specific device on the OT network. Each remote session should require multi-factor authentication (MFA) and be recorded for later analysis.

Is the “air gap” dead and what should the new OT security philosophy look like?

Yes, the concept of the “air gap” as the only and sufficient means of protecting the industrial network is definitely dead. Maintaining faith in its effectiveness in the era of Industry 4.0 is not only naive, but also extremely dangerous. The new OT security philosophy must accept that interconnections exist and will continue to exist, and that threats can arise at any point in our infrastructure.

The new philosophy must be based on the principles of defense-in-depth and zero trust. Defense-in-depth means building multiple, overlapping layers of security so that the failure of one layer does not lead to disaster. Zero trust means abandoning the idea of a secure “inside” of the network and verifying every communication attempt, regardless of its origin.

In practice, this means that the foundation of security becomes visibility (I know what I have on my network), segmentation (I limit the potential range of an attack) and monitoring (I detect when something bad is happening). Instead of building one high wall around the entire factory, we build many smaller, internal walls and install cameras and motion sensors in every room. This is the modern, realistic and effective approach to protecting critical industrial infrastructure in the 21st century.

Learn key terms related to this article in our cybersecurity glossary:

  • Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
  • Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
  • NIST Cybersecurity Framework — NIST Cybersecurity Framework (NIST CSF) is a set of standards and best…
  • Wireless Networks — Wireless networks are communication systems that enable data transmission…
  • 0-Day Exploit — A 0-Day Exploit (zero-day exploit) is a security vulnerability in a computer…

Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:


Cybersecurity for Your Industry

Learn more about cybersecurity in your industry:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist