Glossary · simply explained

Air gap

An air gap is the deliberate separation of a system or network from all other networks — literally a gap of air: no cable connection, no WLAN, no routing. What is not reachable cannot be attacked remotely. Classic fields of use are offline backups, highly critical OT plants and especially sensitive environments.

In practice, logical air gaps dominate today: separation through strict segmentation, unidirectional gateways or temporary connections opened only for defined operations. They trade absolute isolation for operability — and are only as strong as their enforcement.

Physically vs. logically separated

The physical air gap is uncompromising: tape in the safe, offline systems, separate cabling. It protects maximally but turns every data exchange into a manual operation — and exactly there the real weakness arises: USB media and maintenance access have compromised highly isolated plants before. An air gap therefore needs strict media and maintenance processes.

The logical air gap separates by architecture: dedicated credentials and administration domain, no trust relationships, connection initiated only from inside and only for defined time windows — say when the backup repository fetches data and decouples afterwards. Combined with immutability, this yields a backup copy an attacker in the network can neither find nor change.

Where air gaps are used

  • Backup: the last copy offline or logically decoupled — core of modern 3-2-1-1-0 strategies.
  • OT/production: highly critical control networks without direct connection to IT — transitions only controlled.
  • High-security areas: development of sensitive goods, authorities, forensics workstations.
  • Key management: offline CAs and hardware security modules beyond any network reach.

Frequently asked questions about Air gap

Is an air gap truly insurmountable?

No — prominent cases show: removable media, maintenance notebooks and supply chain manipulation bridge air gaps. An air gap shifts the risk to the remaining transitions; without strict media control, vetted maintenance devices and monitoring it remains theory.

What is the difference between air gap and immutable backup?

The air gap makes the copy unreachable, immutability makes it unchangeable: the former severs the path, the latter blocks the operation at the target. Against ransomware they complement each other — the most robust last line is a copy that is separated and immutable.

How does a logical air gap work concretely for backup?

The backup target lives in its own security domain: dedicated credentials without AD connection, MFA, no inbound connections from production. The connection is established only by the backup system itself for the copy operation and severed afterwards — outside these windows the target is simply not addressable in the network.

Are OT networks still protected by air gaps today?

Less and less completely: remote maintenance, data analytics and IIoT demand connectivity. The realistic state is the controlled transition model — zones and conduits per IEC 62443, data diodes for one-way flows, remote access only via brokers with recording. The true air gap remains reserved for the most critical cells.

Does segmentation replace an air gap?

For most protection needs yes: microsegmentation with default deny achieves very high isolation at full operability. The air gap is the escalation tier above — for the last backup copy and systems whose compromise would be existential. The sensible approach is tiering: segment broadly, air gap for the crown jewel.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.