Air Gap Myth vs Reality: Segmenting IT and OT in Practice

Many industrial networks are described as air gapped but are not. Learn what true separation requires and how to segment IT and OT networks sensibly.

3 min readBy Ironfield Cyber Team

Ask many operators whether their control network is connected to the internet and the answer is a confident no. It is air gapped. Then a closer look finds a cellular modem for remote monitoring, an engineering laptop that moves between the plant and the corporate network, a historian server that feeds data to the business side and a vendor VPN that nobody remembers approving.

The air gap is one of the most persistent beliefs in industrial security. This post separates the myth from the reality and describes practical segmentation.

The myth

The myth is that control systems are isolated from the internet and therefore safe. The idea had more truth decades ago, when plants ran closed proprietary networks. Today, business needs push in the other direction: production data for managers, remote troubleshooting for vendors, scheduling and inventory integration, cloud analytics and remote operations.

The reality

A true air gap means no connection of any kind, including removable media and portable devices. That is rare, and even where it exists, malware has historically crossed air gaps through USB drives and laptops. Most environments labeled air gapped actually have narrower paths that are poorly documented. Those paths, not the label, determine your risk.

Why segmentation is the realistic goal

Because connection is usually necessary, the goal shifts from isolation to controlled separation. Segmentation divides a network into zones and limits what can pass between them. If an attacker compromises the office network, segmentation makes it much harder to reach the control system. If something goes wrong in one part of the plant, it slows spread to others.

ISA/IEC 62443 frames this idea through zones and conduits: group assets with similar security needs into zones, and carefully control the conduits that connect them. The Purdue model, a commonly used reference architecture, expresses a similar layered view from field devices up to enterprise systems.

A practical segmentation design

The IT and OT boundary

Place a firewall between corporate IT and the control network, and add a demilitarized zone (DMZ) in between. Systems that need to exchange data, such as a historian replica or a patch server, sit in the DMZ. Direct connections from IT into the control network are not allowed.

Rules that default to deny

Define which devices may talk to which, on which ports, in which direction. Everything else is blocked. Document each rule with a business reason and an owner.

Separate zones inside OT

Where feasible, divide control networks by function or site, such as separate cells, safety systems and supervisory systems. A flat control network lets a single compromised device reach all the others.

Remote access through a controlled path

Route vendor and employee remote access through a single gateway with multifactor authentication and logging, rather than through ad hoc modems.

Wireless and cellular

Treat cellular gateways and wireless access points as network entry points. Inventory them, secure them and place them in appropriate zones.

Handling removable media and laptops

Where connections are limited, people become the bridge. Set rules for USB drives and engineering laptops. Use dedicated, scanned and controlled equipment for OT work, and avoid using the same laptop on both networks.

How to start without breaking anything

Industrial environments value uptime, so approach segmentation carefully:

  1. Inventory and map. Learn the current traffic flows, preferably passively.
  2. Prioritize. Begin with the highest-impact boundary, usually IT to OT.
  3. Design with operations. Engineers must approve rules that affect process communications.
  4. Test in a controlled window. Use maintenance periods where possible, with a rollback plan.
  5. Monitor. Watch for blocked traffic that reveals forgotten dependencies.
  6. Refine over time. Segmentation is a program, not a single project.

Signs your segmentation is weaker than you think

  • Anyone on the office network can reach controllers directly
  • A single firewall rule allows all traffic between IT and OT
  • Control devices have internet access for updates or time services
  • Vendors use their own cellular modems
  • Nobody can produce a current network diagram

Measure what matters

Track how many paths exist between IT and OT, how many are documented and approved, and how many remote access methods are in use. Fewer, documented paths are the goal.

How Ironfield Cyber helps

Ironfield Cyber offers OT security assessments and segmentation planning for energy services firms, industrial contractors and small utilities, designed around operational uptime. If your network diagram says air gap, we can help you verify what is really connected.