The Air Gap Myth in OT Security: Why "Isolated" Industrial Networks Aren't Actually Isolated (2026)
No — a network labeled "air-gapped" is rarely as isolated as the label implies, and treating it as a verified, self-maintaining state instead of a claim that has to be continuously checked is the mistake this piece is about. In practice, three vectors repeatedly bridge networks that were designed and documented as physically isolated: removable media (USB drives), engineering workstations that quietly become dual-homed bridges, and vendor remote-access connections opened for diagnostics that never fully close. Honeywell's 2024 USB Threat Report found that 51% of malware targeting industrial environments is now purpose-built to spread via removable media, up from 9% in 2019 — a shift that tracks how OT networks are actually used, not how the "air gap" label suggests they're used. This isn't a segmentation how-to or a Zero Trust rollout guide — see IEC 62443 Zones and Conduits Explained and Zero Trust OT Industrial Networks for those — this is why the underlying assumption needs to change before either of those frameworks matters.
By The Whitepaper Skeptic — found 'temporary' vendor bridges that were never removed
Quick Facts
| Question | Answer |
|---|---|
| Does a true air gap still exist in most OT environments? | Rarely as a verified state — security researchers and vendors describe physical isolation eroding since ERP/MES integration began, and it has kept eroding since [attributed as vendor/industry framing, not a measured statistic] |
| What are the three main ways an "isolated" network gets bridged? | Removable media (USB), engineering workstations treated as informal bridges, and vendor/contractor remote-access connections |
| How much industrial malware now targets removable media? | 51%, per Honeywell's 2024 USB Threat Report, up from 9% in 2019 |
| How many organizations fully audit vendor remote-access sessions? | 43%, per Secomea's "State of Industrial Remote Access 2026" survey of 400 senior industrial leaders |
| Is Stuxnet still the reference case for air-gap bridging? | Yes — the 2010 USB-based compromise of a genuinely air-gapped facility remains the canonical proof that physical isolation alone isn't a complete control |
Why "Air-Gapped" Became a Myth, Not a Design Choice
Most OT networks that get called "air-gapped" today were never built with a formal, audited isolation boundary in the first place — they were built assuming isolation, at a time when connecting a plant floor to anything else wasn't operationally useful yet. Waterfall Security Solutions, an industrial cybersecurity vendor, has characterized true physical air gaps as having largely disappeared by the late 1990s, once ERP and MES integration started pulling production data into business networks — a vendor's framing of the trend, not a measured statistic, but one that lines up with how most plants actually evolved. The isolation didn't get breached from the outside in a single dramatic event; it eroded from the inside, one integration project and one "just this once" connection at a time.
That distinction matters for how you think about the risk. An air gap that gets breached once is a security incident. An air gap that was never really intact — because a data historian needed a feed to the corporate network, or a vendor needed a way to check on their equipment remotely — isn't a breach at all. It's a network that was mislabeled from the start, and the mislabeling is the actual vulnerability: teams stop asking "how do we verify this is isolated" once the label says "air-gapped," and that's exactly when the informal bridges accumulate unnoticed.
The Three Real Bridges Across an "Isolated" Network
| Vector | How It Bridges the Gap | Reference Case |
|---|---|---|
| Removable media (USB) | Malware executes on contact once a USB drive crosses from an infected system into the isolated network | Stuxnet (2010) |
| Engineering workstations | A single machine gets a second connection — a vendor tool, a contractor's laptop, an LTE modem — and becomes a permanent, undocumented bridge | Common in security architecture reviews, rarely publicized |
| Vendor remote access | Diagnostic or maintenance access opened for a specific window stays open indefinitely, often without full session logging | Secomea's 2026 survey found only 43% of organizations report full audit trails of vendor sessions |
Vector 1: USB Drives and Removable Media
The canonical case for this vector is still Stuxnet, which in 2010 compromised a genuinely air-gapped Iranian uranium enrichment facility by riding in on infected USB drives carried by contractors and engineers who had legitimate physical access. Stuxnet proved something that's easy to forget fifteen years later: an air gap stops network-based attacks, but it does nothing against a threat that travels on physical media someone is authorized to carry across the boundary.
The pattern hasn't gone away — it's grown. Honeywell's 2024 USB Threat Report found that malware specifically engineered to spread via removable media accounted for 51% of malware targeting industrial environments, up from 9% in 2019, and that 82% of the malware found on USB drives in industrial facilities was capable of causing operational disruption — loss of view or loss of control. Security researchers have also documented dedicated air-gap-crossing malware frameworks that rely on USB as their primary infection vector. ESET's GoldenJackal research describes a state-linked group that built two separate USB-based toolsets to reach air-gapped systems — one used against a South Asian embassy in Belarus starting in 2019, and a more modular one deployed against a European Union government organization between May 2022 and March 2024 — and situates that finding against ESET's own broader count of roughly 17 documented air-gap-crossing malware frameworks as of its December 2021 "Jumping the Air Gap" research. That count has grown since: Zscaler ThreatLabz disclosed a North Korean APT37 (ScarCruft) campaign it calls "Ruby Jumper," discovered in December 2025 and detailed in Zscaler's own February 2026 research, which uses a USB-based implant to bridge air-gapped network segments. The throughline across all of these: none of them require a network path. They require someone with legitimate physical access and a USB port.
Vector 2: Engineering Workstations Treated as Temporary Bridges
This is the vector most generic "air gap myth" coverage skips in favor of just citing Stuxnet again, and it's the one most consistent with what actually shows up in a real plant environment. An engineering workstation is usually the single most privileged machine on an OT network — it has the software and access needed to program PLCs, push firmware, and troubleshoot control logic. It's also the machine most likely to end up with a second connection that was never supposed to be permanent: a vendor's remote-support tool installed to resolve one ticket, a contractor's laptop bridged in over Wi-Fi or a USB Ethernet adapter for a single commissioning task, or a cellular modem added so a system integrator could dial in without driving to site.
None of these get added with malicious intent, and none of them get documented as a permanent change to the network's isolation status — they get logged, if at all, as a temporary exception tied to a specific work order. The problem is that "temporary" access on an engineering workstation routinely outlives the reason it was granted, because removing it requires someone to notice it's still there, confirm it's no longer needed, and take the time to pull it — and on a production floor, that's rarely anyone's job. The network diagram still says "air-gapped." The engineering workstation says otherwise.
The "rarely publicized" entry in that table's Reference Case column is carrying real weight, so here is one case that never got written up anywhere: on a customer network documented and internally defended as air-gapped, the engineering workstation was running a vendor remote-support client installed against a work order that had closed months earlier, and no one in the room could name who would have been responsible for removing it. What I got wrong there was the order I looked at things — I read the network diagram first and the workstation's installed-software list second, when the diagram is only the claim and the software list is the check.
Vector 3: Vendor Remote Access That Never Really Closes
The third vector is the most quantifiable, and the numbers describe an access-management gap more than a technical one. Secomea's "State of Industrial Remote Access 2026" survey of 400 senior industrial leaders found that only 43% of organizations have full audit trails of vendor remote-access sessions, which means a large share of "isolated" networks are routinely opened to third parties in ways that aren't even fully logged, let alone air-gapped. Separately, the 2025 Imprivata/Ponemon Institute "State of Third-Party Access in Cybersecurity" report found that 42% of manufacturing organizations experienced a third-party-related breach in the prior year, and 46% named remote access their weakest security point. Similarly, Fortinet's 2025 State of Operational Technology and Cybersecurity Report found that roughly 50% of organizations experienced one or more OT cybersecurity incidents in the past year — but the $5.56M average breach cost sometimes cited alongside that figure is not a Fortinet number; it's IBM's Cost of a Data Breach 2024 industrial-sector average, and IBM's 2025 edition puts the industrial-sector average closer to $5.0M, so the two shouldn't be conflated.
Whatever the precise numbers turn out to be once verified, the shape of the problem is consistent across every source in this space: vendor and integrator remote access is treated as a maintenance convenience, not a standing connection that needs the same access controls as anything else on the network. If your organization is trying to size how much of this exposure is coming specifically from third-party vendor access rather than USB or engineering-workstation bridging, OT Security Vendor Comparison 2026: Dragos vs. Claroty vs. Nozomi Networks covers the network monitoring platforms built to give you visibility into exactly that kind of traffic once you stop assuming the network is isolated.
What This Means for Your OT Security Model
None of this is an argument to stop trying to isolate OT networks — physical and logical isolation still meaningfully reduces attack surface and should stay part of the design. It's an argument to stop treating "air-gapped" as a verified, self-maintaining state and start treating it as a claim that has to be continuously validated against USB policy, engineering-workstation configuration, and vendor remote-access logs. That's also why the other pieces in this cluster exist as separate, more prescriptive guides rather than being folded into this one: IEC 62443 Zones and Conduits Explained covers how to actually design segmentation boundaries once you accept the network isn't truly isolated, and Zero Trust OT Industrial Networks covers how CISA's 2026 framework applies per-request verification inside those boundaries, including for the vendor and engineering-workstation access this piece describes. A deeper operational walkthrough of the vendor remote-access controls that address Vector 3 specifically — identity-based access, time-bound sessions, session recording — is covered in OT Remote Access Security Explained.
CISA's ICS advisories are a useful ongoing check against this framing in practice — several documented incidents in CISA's advisory archive involve exactly this kind of informally bridged access rather than a novel network-based exploit, the same sourcing pattern used in PLC Cyberattacks 2026: How Iranian Hackers Exploit Legitimate Engineering Software, which documents attackers using legitimate engineering software rather than a network-level breach of an isolated boundary.
FAQ
Q: Does an air gap protect ICS from cyberattacks?
A: Not reliably, and often not at all in practice. A true air gap — a network with zero physical or logical connection to any other network — does stop remote, network-based attacks that require an internet-reachable path. But most networks labeled "air-gapped" aren't actually fully isolated: they're bridged by USB drives, engineering workstations with a second connection, or vendor remote-access tools installed for diagnostics and never removed. The label describes an intent, not a verified, ongoing state.
Q: How do attackers bridge an air-gapped network?
A: The three vectors that show up repeatedly across incident reporting and vendor research are removable media (USB drives carrying malware built to execute on contact), engineering workstations that get dual-homed through a vendor's remote-support tool or a contractor's laptop, and vendor or integrator remote-access connections opened for maintenance that stay active long after the maintenance window ends.
Q: Is Stuxnet still relevant to air gap security in 2026?
A: Yes, as the reference case rather than the current threat. Stuxnet (2010) demonstrated that a genuinely air-gapped facility could still be compromised via infected USB drives carried in by contractors and engineers with legitimate physical access — proof that isolation alone isn't a complete control. ESET had documented roughly 17 such frameworks as of its December 2021 research, and newer cases since then — including GoldenJackal's EU-government campaign and Zscaler's December 2025 discovery of a North Korean APT37 USB implant — suggest the technique has been refined, not retired.
Q: What's the difference between an air gap and Zero Trust in OT security?
A: An air gap is a network-topology claim — this network has no connection to any other network. Zero Trust is a verification model that assumes no implicit trust regardless of network location, including inside a segmented or supposedly isolated zone. They answer different questions: air gap asks "is there a path in," Zero Trust asks "should this specific request be allowed, right now, regardless of path." See Zero Trust OT Industrial Networks for how CISA's 2026 framework applies that model inside OT networks that already assumed they were isolated.
Q: Should manufacturers stop trying to isolate OT networks?
A: No — physical and logical isolation still meaningfully reduces attack surface and should stay part of the design. The point isn't to abandon isolation; it's to stop treating "air-gapped" as a verified, self-maintaining state and start continuously validating it against actual USB policy, engineering-workstation configuration, and vendor remote-access logs.
Sources
- Honeywell, "2024 USB Threat Report" (April 30, 2024)
- Secomea, "The State of Industrial Remote Access 2026" (March 2026)
- Fortinet, "2025 State of Operational Technology and Cybersecurity Report"
- Imprivata / Ponemon Institute, "The State of Third-Party Access in Cybersecurity" (2025), manufacturing-sector breakout (42% third-party-related breach rate, 46% citing remote access as weakest link)
- IBM, "Cost of a Data Breach Report" (2024 and 2025 editions), industrial-sector average breach cost
- ESET, "Jumping the Air Gap: 15 Years of Nation-State Effort" (December 2021)
- ESET, "GoldenJackal APT group, with air-gap-capable tools, targets systems in Europe to steal confidential data" (October 2024)
- Zscaler ThreatLabz, "APT37 Adds New Tools For Air-Gapped Networks" — campaign discovered December 2025, research published February 26, 2026
- Symantec (now Broadcom), "W32.Stuxnet Dossier" — primary retrospective on Stuxnet's USB-based compromise of an air-gapped facility (2010; original Symantec URL is dead post-Broadcom-acquisition, linked via Wayback Machine archive)
- Waterfall Security Solutions — vendor commentary characterizing true air gaps as having largely disappeared by the late 1990s [explicitly attributed as vendor framing, not a measured statistic]
- CISA ICS advisories referencing air-gap-adjacent access vectors [cross-referenced with the sourcing pattern already used in the plc-living-off-the-land-attacks-2026 spoke]
Author Bio
The Whitepaper Skeptic has direct experience with OT cybersecurity in industrial and smart-factory environments, including customer-facing security architecture reviews where a network that was documented and defended internally as "air-gapped" turned out to have an engineering workstation with a vendor-installed remote-access tool, or a diagnostic laptop connection, that had been logged as a "temporary" exception months or years earlier and never removed. That gap between the network diagram and what was actually plugged in is the exact pattern this piece is built around, not a hypothetical.
Related Posts
- OT Cybersecurity 101: Why Smart Factories Need a Different Security Model Than IT
- IEC 62443 Zones and Conduits Explained: How to Actually Segment an OT Network in 2026
- Zero Trust OT Industrial Networks: How to Apply CISA's 2026 Framework Without Breaking Production
- PLC Cyberattacks 2026: How Iranian Hackers Exploit Legitimate Engineering Software
- OT Remote Access Security Explained
- GICSP vs. ISA/IEC 62443 Certification: Which OT Security Credential Should You Get in 2026?
Tags
air gap myth, OT cybersecurity, ICS security, industrial network segmentation, vendor remote access

Comments
Post a Comment