Control Systems Security

Air Gap Is a Mood. Offline Is a Choice.

The case for an isolated plant that still runs, and the security checks that have to sit on every remaining doorway

Jeff Gray · 21 Sep 2026 · Control Systems Security

Industrial control room split by a broken concrete wall — cables punch through into a glowing blue network cloud. Air gap as mood, offline as choice.

The wall was supposed to be the air gap. The cables did not get the memo.

I am going to say something that makes modern OT architecture decks look faintly embarrassed.

Some plants should be offline.

Not "air-gapped" in the brochure sense. Not "segmented" with a hopeful firewall rule and a vendor VPN that nobody has the heart to revoke. Completely offline. No IP path in. No IP path out. No cellular brick under the desk "just for emergencies." No temporary bridge that somehow outlives three plant managers. If the board wants numbers, a person carries a report. If the OEM wants to help, a person walks in with tools and leaves with nothing that still talks.

That sounds weird in 2026. Good. Weird is the point. The industry is drowning in secure remote access, AI gateways, and another week of alerts about internet-facing controllers. Somebody has to keep saying the rude thing out loud. Connectivity is a design choice with a body count, not an IT default you inherit because the slide deck looked modern.

If you want a picture of unnecessary exposure that still makes my jaw hurt, start with water and a browser.

In October 2024, researchers at Censys found nearly four hundred U.S. water-facility human-machine interfaces sitting on the public internet. Same family of browser-based HMI software. Most of them were not even pretending to be locked. Roughly two hundred sixty-four could be read by anyone who found the page. About forty had no authentication at all. Full control from a browser. Pumps, valves, chemical feeds, the polite little screens operators trust on Tuesday mornings, hanging where a tourist with Wi-Fi could click around like it was a hotel thermostat.

Nobody needed that door. The plant did not get cleaner water because strangers could open the HMI from a coffee shop in another state. The operators did not get faster because the control room learned to live on the open web. What they got was a finding that had to be walked to the EPA, a vendor scramble, and a reminder that "convenience" is how you invent an attack surface out of thin air. I read that write-up with cold coffee and the same thought I get in bad assessments: we did this to ourselves on purpose.

That is the mood this article is arguing against. Not competence. Not modernity. The habit of wiring the process to strangers because the demo looked friendly.

Air Gap Is a Mood. Offline Is a Choice.

I have lost count of the plants that call themselves air-gapped while a laptop on the engineering bench still answers email, patches itself from a corporate WSUS, and docks onto the process network after lunch. The word became a feeling. You say it in a meeting and people nod, and then somebody plugs in the thing that makes the feeling false. Offline has to stay a fact, or stop using the word.

This is not a new complaint. Eric Byres called the air gap a fairy tale more than a decade ago, and he was not wrong about the fairy tale part. Sean McGurk, then leading ICS assessment work at DHS/NCCIC, told Congress what those assessments kept finding. Operations and enterprise were not cleanly separated. The average site had on the order of eleven direct connections. Not zero. Not one polite firewall. Eleven. I know that finding the long way. Sean McGurk hired me. I am not rediscovering his point from a search result. I am still arguing next to it.

An air gap, as practiced, often means "we intend not to route this to the public internet." Intention is not architecture. A completely isolated plant refuses the path on purpose. It accepts slower updates, slower vendor help, and slower data to the board, because the alternative is a permanent attack surface dressed up as convenience. That trade is uncomfortable in rooms that sell connectivity as progress. Sit with the discomfort. It is the point.

If you still need one carefully designed outward truth to a safe side, a historian feed, a compliance export, a board KPI that cannot wait for Friday's courier, unidirectional transfer is the grown-up answer. I am friends with that architecture. I will not call a diode expensive clutter. One-way diode work sits in that lane for a reason. This article is the weirder cousin. Some processes should not even have that one-way courtesy. They should run, make product or water or power, and keep their mouths shut.

How a Plant Isolates and Stays Functional

Isolation that kills the process is not security. It is a shutdown with better branding. A functional offline plant still has operators, still has maintenance, still has spare parts, still has a way to improve. It simply refuses to do those jobs over a network that also serves strangers.

I keep getting asked how that stays real without turning the plant into a museum. Sit with the floor for a minute. The answer is not a product you buy in Q3. It is a set of habits that look boring until you compare them to a ransomware week, and then they look like the only adults in the room.

The process stays local. Control loops, safety systems, and HMIs live on the plant's own networks and do not require a cloud to stay alive. If the internet dies, the plant does not notice. That is the first test, and it is a blunt one. If losing outside connectivity stops production, you were never offline. You were dependent and calling it resilience, which is a word that has done a lot of dishonest work in our industry.

People become the wide-area network. Shift turnover is verbal and written, not Slack into the control room. Work orders are local. Procedures are paper or local electronic copies that do not phone home. Training happens in the building. When corporate needs a story, operations writes one and a human carries it out. I know that sounds slow. Slow is the point when the alternative is a stranger's packet with your plant's name on it.

Vendors come to the site, or they wait. Remote OEM support is a convenience tax with compound interest. An isolated plant budgets for on-site service windows, loaner engineering stations that never leave the fence, and contracts that do not assume a persistent VPN. That costs money. So does a bad week with a ransomware crew that walked in through the "temporary" support tunnel. I have watched plants pay the second bill after they refused the first one for years, and then act surprised that the tunnel remembered how to open.

Updates become evidence, not email. Patches, firmware, antivirus definitions, and engineering project files arrive on media that is treated like evidence: known source, known hash, known custodian, known wipe-or-destroy path after use. The plant does not "just grab the latest" from a vendor portal on the same laptop that touches the PLC. If that ritual feels heavy, good. Heavy is how you know it is still a control and not a habit you perform for auditors while the real path sits under the desk.

Historians and MES stay inside. Trending, batch records, and quality data can still exist. They simply do not replicate offsite in real time. Exports are scheduled, reviewed, and carried. If that is too slow for the business model, the business model is arguing against isolation. That argument should be explicit, not smuggled in through a modem somebody loved three plant managers ago.

IT lives on a separate SAL. Corporate IT is not "the same plant with different passwords." It is a different Security Assurance Level with different consequence if it burns. Email, identity, the SOC, the help desk: that world can be loud, patched weekly, and connected. The isolated process island is quieter and colder on purpose. You do not raise the process island's SAL by piping it into IT's noise. You keep IT's SAL where IT belongs, and you keep the process island where bodies are on the line. Purdue levels are a functional map of who talks to what. They are not the security model. Zones, conduits, and SAL are. I will keep saying that until the slide decks catch up, which may be never, but saying it still matters.

Those logs move manually. OT security logs, historian extracts, and the ugly little files the SOC wants do not stream across a forever-tunnel into Splunk. A person carries them on controlled media on a schedule, or they do not leave. Same ritual as the outbound report: review, hash, custodian, no return path that turns the courier into a modem. If the SOC cannot live with daily or weekly latency, the SOC is lobbying to lower the island's isolation, and that lobbying should happen in daylight instead of as a collector that "just appeared" because the dashboard looked empty.

Spares and staging are planned. Offline plants keep more critical spares on hand because overnight drop-ship culture assumes connectivity and speed you have refused. Engineering changes are staged on dedicated machines that never browse the web. The functional trick is not magic. It is inventory, discipline, and accepting latency where latency hurts less than compromise.

I am not pretending every water plant can live like a submarine. Fleet economics, OEM warranties, and regulators will fight pure isolation. Name that fight. Then decide which islands earn it: safety trip logic, certain high-consequence units, one-off processes where a wrong bit flips from "authorized" to "people get hurt." Cosplay offline while Slack has a path to the HMI is worse than honesty about a managed connection. At least the managed connection admits it exists.

Security Checks at the Remaining Doors

Offline does not mean "no doors." It means the doors are physical, rare, and watched. Every remaining doorway needs a check, or isolation is cosplay again. I am going to walk the doors I keep finding when I sit in a plant that claims it is closed. No checklist theater. Just the doors, in the order they usually betray you.

Start at the fence with what is still allowed to exist. Before celebrating isolation, inventory every path that can carry bits: Ethernet, Wi-Fi, cellular, Bluetooth, serial-with-IP adapters, vendor appliances with their own radios, "temporary" jump hosts, and the friendly laptop that "only does engineering." If it can speak IP toward the process, it is in scope. The security check here is architectural. Remove the path, or admit you are not offline. I have watched too many inventories discover a modem somebody loved three managers ago, still blinking, still patient.

Then ask who walks in with a computer. People are the primary carrier once you kill the public wire. Badge plus escort is not enough if the guest laptop is assumed clean because the guest is nice. The check is blunt. No foreign machine on the process network. Loaner plant-owned engineering stations for visitors. If a personal or OEM laptop must enter, it enters under assume-compromise rules: inspected, limited ports, time-bounded, and never trusted as a permanent peer. Courtesy is not a malware scan. I wish more plants believed that sentence before the courtesy became the incident.

Treat every stick, disk, and card like it might be lying. USB and other removable media are the classic offline failure mode, the one that keeps surviving decade after decade because someone always has a stick in a pocket. Before mount: known custodian, write-once or freshly wiped media when possible, malware scan on a dedicated station that is not the HMI, cryptographic hash matched to the vendor's published value when one exists, and a log that says who introduced what and when. After use: wipe, destroy, or quarantine. "We scanned it on Dave's laptop" is not a control. Dave's laptop is how the story usually starts. I wish that were a joke. It is not.

Demand trust before you load an update package. Firmware and project files get a second check even after media hygiene: change ticket, two-person integrity for safety-related loads when the process warrants it, offline backup of the last known good, and a maintenance window that assumes rollback. The security check is not "antivirus said OK." It is "we can prove what we loaded, and we can undo it." That sentence has saved more pride than plants like to admit.

Remember that the engineering station is often the whole war. No general internet. No email. No browser-as-lifestyle. Local accounts with unique credentials. Patching only through the same media ritual. A clear rule that docking to the process network ends any fantasy that this box is also a home office. If the engineering station can browse and can talk to controllers, you built a bridge and called it a tool. I have named that bridge politely in meetings. It remains a bridge. Politeness does not change the physics.

Slow down at receiving when spare parts and "smart" devices arrive. New drives, new radios, new smart instruments show up with firmware and sometimes with unexpected network personalities. Verify model and firmware pedigree. Stage on an isolated bench. Only then introduce to process. A spare that phones a vendor by default is not a spare. It is a surprise modem with a purchase order attached.

Keep an outbound ritual when data leaves. Even a hard offline plant sometimes owes the outside world a number, a PDF, or a compliance export. That is still a doorway. Content review first, so you are not handing out unintended project files, credentials, or full memory dumps. Transfer on controlled media or paper. Receiving side gets no return path into the process. If you need frequent one-way electronic export, that is where unidirectional architecture earns its keep. If you need interactive remote help, you are no longer arguing for offline. You are arguing for remote access with better manners, and you should say so out loud.

Keep separate SAL and manual logs at the IT boundary. IT can watch without owning a live pipe. Name the SAL for the process island and name the SAL for corporate IT. Write the rule that log and telemetry movement is sneakernet or approved unidirectional export only. Put a receiving station on the IT side that never routes back. Keep a calendar so "manual" does not mean "whenever somebody remembers." The security check fails the moment someone "just stands up a collector" because the SIEM dashboard looked empty. An empty dashboard is the price of isolation. Fill it with carried files, not with a new conduit you will later pretend was temporary.

Watch time and drift, the quiet failure. Offline systems still need clocks, certificate expiry discipline for any local PKI you kept, and a plan for when vendor support windows close. Calendars for media-borne updates. Drills for "vendor on site only." A written acceptance that some CVEs will be lived with until the next physical service window. Pretending isolation means "we never patch" is how offline plants become museums with pumps. I would rather own the calendar than own the museum.

Kill the temporary bridge on purpose when exceptions show up. Every plant will face a night when someone begs for a temporary path. The check is governance, not technology: written exception, named owner, named kill date, and a physical or procedural act that removes the path when the kill date hits. If temporary bridges do not die on schedule, offline was a press release. I have sat in rooms where the temporary bridge had outlived the manager who authorized it. That is not isolation. That is archaeology.

Can a Modern Plant Run This Way?

Yes. Not every plant. Not every unit inside a plant. But yes.

Modern does not mean permanently online. Modern means the process still measures, controls, alarms, records, and gets maintained with today's equipment. Controllers do not need Twitter. HMIs do not need a SaaS license to open a valve. I keep saying that in rooms where people look at me like I just insulted their phone. Historians ran for decades before anyone called a cloud a strategy. What changed is the expectation that every box should phone a vendor, patch itself nightly, and stream feelings to a dashboard in another state. That expectation is a business preference wearing engineering clothes.

A modern isolated plant still buys current controllers and workstations. It still uses serious local backups. It still schedules firmware with eyes open. It simply refuses the subscription model of connectivity. Vendors who will only support you through a persistent remote tunnel are a procurement problem, not a law of physics. Write the contract for on-site windows and media-borne updates, or pick a vendor who will. I have watched procurement treat that sentence like heresy. It is still a sentence you can put in a contract, and contracts still move money.

Where it gets hard is the business envelope around the process. Corporate wants real-time KPIs. Insurance and customers want continuous telemetry. OEMs want remote diagnostics baked into the quote. Regulators sometimes want electronic reporting that assumes a pipe. Those pressures are real. They are also negotiable if you isolate islands instead of pretending the whole site is a submarine. Keep the high-consequence loop cold and offline. Let the business network and IT keep their louder SAL. Carry the few artifacts that must cross. The modern plant, in this telling, is not one sealed building. It is a set of islands with different consequences and different doors.

So: can a modern plant run this way? A modern island can. A whole enterprise that insists every sensor feed a cloud AI by lunchtime cannot, and should stop borrowing the word offline.

How It Can Still Be Hacked

Offline does not mean unhackable. It means the anonymous internet lost its vote. The remaining votes are older, slower, and often wearing a badge. I am staying high-level here on purpose. This is not a cookbook. It is a door list, and the doors are the ones you already know if you have spent enough nights in a plant.

Someone carries the problem in. Removable media is still the classic path. A stick that "only has the patch," a drive that "came from the OEM," a card in a camera that somehow gets mounted on an engineering station. If your media ritual is theater, offline collapses into USB roulette, and roulette is not a security model.

Someone walks the problem in. A technician laptop, a vendor service kit, a "loaner" that was on hotel Wi-Fi last night. Physical access plus a trusted face beats a firewall you already removed on purpose. Isolation shifts the fight to visitor control and plant-owned tools. That fight is harder in some ways, because people are harder than packets, but at least you can see the people.

The spare is already wrong. Firmware on a replacement drive, a smart instrument with a surprise radio, a "compatible" part from a gray channel. Supply chain does not need your public IP. It needs your receiving dock and a receiving ritual that is more than a signature on a packing slip.

The courier becomes a modem. Manual log movement and sneakernet exports are still doors. If outbound media is not reviewed, or if the same stick comes back in without a wipe, you built a round trip and called it procedure. Procedure without a wipe is just a polite tunnel.

The insider already has the keys. Isolation shrinks remote strangers. It does not dissolve privilege, shared passwords, or a bad day from someone who knows which engineering station talks to which controller. Unique credentials and two-person rules for safety loads still matter when there is no internet to blame. Blaming the internet was always a little too convenient anyway.

The temporary bridge forgets to die. One emergency VPN, one cellular "just for this outage," one mirrored jump host left up after the crisis. That is how offline plants become ordinary plants again. The hack here is often governance failure with malware as the afterparty. I have watched the afterparty more times than I want to count.

Pre-positioned trust is the quiet one. If the island was built from images, project files, and appliances that were compromised before the fence closed, isolation preserves the problem. First-day integrity, known-good loads, hashes, and a build you can explain, is part of offline security, not an IT luxury you postpone until the next budget cycle.

What offline does buy you is time and visibility. There is no mass scan from the far side of the planet. The attacker has to touch your doors: people, media, spares, exceptions. That is a smaller stage. It is still a stage. Pretending otherwise is how museums with pumps get surprised, and I would rather not write that surprise as a eulogy.

What This Is Not

This is not a claim that isolation stops every insider, every compromised technician, or every malicious USB in a pocket. It shrinks the anonymous internet's vote in your process. It forces attackers, and helpers, through doors you can see: badges, media logs, on-site visits, and human rituals that leave records.

This is also not anti-modern. Unidirectional gateways, local high-quality historians, and serious media control are modern. What is outdated is the superstition that a hopeful firewall rule plus the word "air gap" equals safety. I poured more coffee writing that sentence than the sentence deserved. The superstition still sells.

The Weird Conclusion

If compromise of a segment can hurt people, ask a simpler question than "which zero trust product." Ask whether that segment should speak to strangers at all.

Some plants should answer no. They should stay functional with local control, local data, on-site vendors, and updates that arrive like evidence. IT can keep its own SAL and still get the logs, carried by hand, on a schedule, with no return path. They should put security checks on every remaining doorway, people, media, packages, engineering stations, spares, outbound reports, the IT boundary, time, and exceptions, because offline is not the absence of doors. It is the decision to stop pretending the open ones are imaginary.

Air gap is a mood. Offline is a choice. Make it on purpose, or stop using the word.

---

References

  1. Eric Byres, "SCADA Security's Air Gap Fairy Tale," Automation.com, August 2011. https://www.automation.com/article/scada-securitys-air-gap-fairy-tale (quotes Sean McGurk, DHS/NCCIC, on ICS assessment findings: no true OT-enterprise separation in assessed sites; average on the order of eleven direct connections).
  2. Eric Byres, "The air gap: SCADA's enduring security myth," Communications of the ACM 56(8), 2013. https://dl.acm.org/doi/10.1145/2492007.2492018
  3. Sean McGurk, testimony before the U.S. House Subcommittee (25 May 2011), as cited in Byres 2011. Confirm hearing transcript page/timestamp before final publish.
  4. NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security (2023). Air gaps alone are not enough; unidirectional gateways and physical separation where required.
  5. Emily Austin and Mark Ellzey, Censys, "Turning Off the (Information) Flow: Working With the EPA to Secure Hundreds of Exposed Water HMIs" (findings from October 2024; remediation progress through May 2025). https://censys.com/blog/turning-off-the-information-flow-working-with-the-epa-to-secure-hundreds-of-exposed-water-hmis
  6. Ryan Naraine, SecurityWeek, "Misconfigured HMIs Expose US Water Systems to Anyone With a Browser," June 5, 2025. https://www.securityweek.com/misconfigured-hmis-expose-us-water-systems-to-anyone-with-a-browser/
  7. EPA and CISA, "Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems" (joint fact sheet), December 2024. https://www.epa.gov/system/files/documents/2024-12/joint-factsheet-epa-cisa-internet-exposed-human-machine-interfaces-508c.pdf

Educational commentary, not a runbook. Analysis based on public reporting and open-source research (Byres air-gap essays; McGurk / DHS-NCCIC findings as cited in Byres 2011; NIST SP 800-82 Rev. 3; Censys / EPA / CISA / SecurityWeek reporting on internet-exposed water HMIs, 2024–2025). The “eleven connections” finding is cited via Byres 2011 quoting McGurk; pin to the hearing transcript if primary-source armor is wanted before go-live. No active scanning, probing, or unauthorized access was performed. No specific private facilities or operators are identified.

OTFeed matches public ICS advisories to the gear a customer actually runs. otfeed.com

Analysis based solely on publicly available sources and open-source research. No active scanning, probing, or unauthorized access was performed. No specific private facilities or control systems are identified. The views expressed are the author's alone and do not represent the positions, strategies, or opinions of any government agency, department, or employer.