Air gaps: network isolation and its limits — article header image
Cyber Warfare

Air gaps: network isolation and its limits

· By Archivo Bélico Editorial Team

An air gap physically separates sensitive systems from other networks, but Stuxnet showed why isolation should never mean assumed invulnerability.

What is an air gap?

An air gap is a boundary between systems with no direct physical connection. NIST defines it as an interface where logical transfers are performed manually under human control. Defence, intelligence and industrial operators use it where remote compromise could have exceptional consequences.

Why organisations use isolation

  • Separating classified information from open networks.
  • Reducing the remote attack surface of industrial control systems.
  • Protecting critical functions where availability outweighs connectivity.
  • Creating auditable boundaries for highly sensitive transfers.

Why isolation is not invulnerability

Separated systems still need maintenance, updates and sometimes file exchange. Removable media, service equipment and human mistakes can cross the boundary. An air gap removes pathways; it does not remove risk.

Stuxnet: the landmark case

Stuxnet, discovered in 2010, targeted Iranian industrial systems and included mechanisms capable of reaching isolated environments. Public investigations widely attribute it to the United States and Israel, although the full account has never been officially confirmed. The incident made air-gap security a global strategic issue.

Defence in depth

Isolation is strongest as one layer alongside asset inventories, media controls, authentication, monitoring and maintenance procedures. This article explains the concept and historical record without detailing methods for bypassing protected systems.

Frequently asked questions

What does air-gapped mean?
A system is physically separated from external networks and transfers require controlled procedures.
Can removable media cross an air gap?
It creates a transfer path and therefore requires strict controls; historical malware campaigns have exploited such media.
Who created Stuxnet?
Public reporting widely attributes it to the United States and Israel, but every operational detail has not been officially confirmed.

Sources and references

  • NIST CSRC Glossary, Air Gap: https://csrc.nist.gov/glossary/term/air_gap
  • ESET Research, Jumping the Air Gap (2021): https://web-assets.esetstatic.com/wls/2021/12/eset_jumping_the_air_gap_wp.pdf
  • Mordechai Guri, Mind the Gap (2024): https://doi.org/10.48550/arxiv.2409.04190