The Myth of the Air-Gap: Why 'Dark Sites' and Critical Infrastructure Must Tighten OT Security
A deep dive into remote telemetry vulnerabilities, transient device vectors, and the physical realities of modern industrial connectivity.
1. The Illusion of Absolute Isolation
For decades, operators of critical infrastructure - including power grids, water treatment plants, and manufacturing facilities - relied on a simple and comforting defense mechanism: the physical air-gap. The logic was straightforward. If an operational technology (OT) network is physically disconnected from the corporate IT network and the public internet, it is inherently safe from cyber threats. These "dark sites" were treated as secure by default, operating under the assumption that a remote attacker could not cross a physical void.
In 2026, this assumption is not only obsolete, but it is also actively dangerous. The physical air-gap has largely vanished, replaced by a complex, distributed web of necessity-driven connections. Modern operations require real-time data visibility, predictive maintenance, and remote engineering access to function efficiently. Even when an asset owner believes a facility is completely dark, a closer technical audit of the network perimeter almost always reveals a highly connected reality.
2. The Distributed Reality: Remote PLCs, RTUs, and Multi-Path Telemetry
The primary reason true air-gaps do not exist in modern critical infrastructure is the sheer physical scale of distributed operations. Water distribution networks, oil and gas pipelines, electrical grids, and smart campuses do not exist in single, isolated buildings. They rely on thousands of remote Direct Digital Controllers (DDCs), Programmable Logic Controllers (PLCs), and Remote Terminal Units (RTUs) scattered across hundreds of remote geographic sites to monitor and control physical processes.
Connecting each of these distributed remote sites back to a central control center via a physically wired, secure local network is often impossible due to extreme costs or physical geographic barriers. To bridge this gap, critical infrastructure operators utilize a variety of telemetry pathways:
- Cellular WAN gateways (3G/4G/5G): Edge routers are widely deployed at remote sites to act as gateways, providing internet connectivity so local devices can communicate with central SCADA or cloud-management systems.
- Satellite links: Used for highly isolated facilities, such as offshore platforms, remote substations, or mountain reservoirs, where cellular coverage is unavailable.
- Leased lines and microwave telemetry: Private leased telecommunication lines and radio-frequency microwave towers are used to transmit telemetry packets over long distances, but these ultimately terminate at edge gateways connected to operational servers.
Each of these remote communication links acts as a logical conduit that pierces the supposed air-gap. A physical read or write command originating from a remote RTU must travel across public or semi-private telecommunication infrastructure, crossing multiple trust boundaries before reaching the core control system.
3. The Edge Device Vulnerability Vector
Because distributed OT subnets must rely on cellular and satellite edge routers to connect, these edge gateways have become a prime target for modern adversaries. Threat actors do not need to physically infiltrate a dark site if they can compromise the edge router that connects it to the outside world.
A major vulnerability analysis by Claroty's Team82 highlighted the critical risks embedded in these edge gateways. Investigating widely deployed 4G edge routers (such as the ConnectedIO ER2000), researchers uncovered a catastrophic exploit chain:
- Insecure device claiming: The cloud-based management platform relied on non-cryptographic, predictable hardware identifiers (like sequential IMEI numbers and MAC addresses) to register and assign device ownership.
- Hardcoded clear-text credentials: The device firmware stored hardcoded, clear-text MQTT broker credentials that were shared across every manufactured router.
- Broker misconfiguration and sniffing: Because all routers shared a single credential set, any connected device could subscribe to the global status topic, allowing researchers to sniff private heartbeat messages from thousands of other routers worldwide, leaking their private Wi-Fi SSIDs, passwords, and IMEIs.
-
Command-as-a-service RCE:
The router communication protocol contained an unauthenticated, root-privileged command opcode (
Opcode 1116/CVE-2023-33374) that executed arbitrary operating system shell commands directly on the device.
By chaining these vulnerabilities, an attacker could remotely execute root-level code on any connected edge gateway, completely bypassing local firewall rules and gaining an immediate, unrestricted foothold inside the local physical control network. This demonstrates that the gateways used to enable remote connectivity represent a massive, fragile attack surface that completely invalidates the concept of an isolated air-gap.
4. Bypassing the Network: The Sneakernet Threat
Even in rare scenarios where an OT network has absolutely no external cellular, satellite, or leased telecommunication lines, it remains highly vulnerable to physical data transit. In industrial settings, the physical movement of data - known as the "sneakernet" - is an operational necessity.
Industry studies indicate that transient devices, such as USB drives and contractor engineering laptops, account for nearly 27% of all OT security incidents. This vector is highly effective because it completely bypasses network-based firewalls, intrusion detection systems, and perimeter defense stacks. When an external field technician or vendor plugs a maintenance laptop directly into a PLC's local physical port to update configuration files or load firmware, any dormant malware on that laptop is introduced directly into the Level 1 control zone.
Once inside a dark site, legacy protocols like BACnet, Modbus, and FOX offer no defense. Because they were engineered decades ago for isolated networks, they feature zero native authentication or encryption. An attacker with local network access can easily send unauthenticated control packets to alter critical process loops, manipulate temperature setpoints, or disable physical safety alarms.
5. The Consequences of the OT Visibility Crisis
Compounding these remote telemetry and physical entry vectors is a severe "visibility crisis" across the industry. According to Fortinet's 2026 State of Operational Technology and Cybersecurity Report, OT professionals report having visibility over only half of their active OT environments. Furthermore, 56% of organizations cannot see traffic below the IT/OT network boundary.
This lack of visibility creates an ideal operating environment for sophisticated threat actors. Nation-state adversaries (such as VOLTZITE, KAMACITE, and Sandworm) have progressed to Stage 2 of the ICS Cyber Kill Chain, moving past simple network reconnaissance to actively mapping physical control loops (such as HVAC networks, electrical grids, and water systems) to execute targeted physical sabotage.
These threats are actively manifesting in the field:
- The December 2025 Poland grid attack: Russian state-linked threat actors compromised internet-facing edge devices with default passwords, moved laterally to local HMIs and RTUs, and deployed destructive wiper malware that corrupted device firmware, resulting in a physical loss of view and control for distribution system operators.
- Precautionary production halts: Because IT and OT networks are increasingly converged, an attack contained strictly to the IT layer can force a complete operational shutdown. During the May 2025 Nucor Steel incident, IT-system compromises forced a complete cease in steel production simply because the organization lacked the granular segmentation and visibility to verify whether the OT network was safe. On average, an OT-affecting breach now costs $4.56 million, making operational blind spots highly expensive.
6. Securing the Air-Gap: A Modern Defensive Blueprint
Critical infrastructure operators can no longer afford to treat their dark sites as self-defending castles. Securing a modern, distributed OT architecture requires implementing rigorous, consequence-led technical controls:
A. Hardware-Enforced Network Segregation
For highly sensitive dark sites where remote monitoring is required but external command injection is unacceptable, operators must deploy hardware-enforced data diodes. Unlike software firewalls that can be misconfigured, a data diode physically restricts data flow to one direction. This ensures that operational data can be safely exported to the cloud or enterprise network, while physically preventing any external inbound traffic from reaching the production controllers.
B. Hardened Edge Gateways and Outbound-Only Tunnels
When bidirectional communication is operationally required for remote control, the edge-to-cloud conduit must be heavily secured. Gateways should be configured to establish outbound-only tunnels (typically using MQTT over TLS on TCP Port 8883) back to the central broker. By initiating the connection from inside the isolated OT subnet, the facility requires zero inbound firewall rules and no open ports, rendering the gateway invisible to public internet scans.
C. Secure "Sneakernet" Controls
To secure the physical data transfer pathway, organizations must deploy transient device sanitization kiosks at all facility entry points. No external USB drive or vendor maintenance laptop should be permitted to connect to a Level 1 or Level 2 control device without first undergoing rigorous configuration and malware scanning. Furthermore, engineering laptops must be heavily hardened with least-privilege policies, and removable media exceptions must be strictly logged and approved.
D. Continuous Passive Monitoring
Given the persistent visibility crisis, operators must deploy non-intrusive, passive network monitoring tools that analyze network traffic mirrors in real time. Passive discovery can identify unexpected assets, unapproved remote access sessions, and anomalous protocols without injecting active packets that could destabilize fragile, legacy PLCs.
By moving away from the static, passive security of the air-gap and adopting an active, consequence-led, and zero-trust defensive posture, critical infrastructure operators can ensure their distributed physical processes remain resilient against both remote and physical threat vectors.