22 Aug 2026 · 5 min read
Your air gap has a vendor login
security · scada
Ask whether a plant is connected to anything and you often get the same answer, delivered with confidence: it's air gapped.
It is worth treating that sentence as a claim about the past rather than a description of the present. Somebody built it that way, once. The question is what has happened since, and the honest answer is usually that nobody has checked.
Stuxnet is the wrong lesson, told the wrong way
Everyone reaches for the same example, and most people take the wrong thing from it.
The facility was genuinely isolated. The attack still arrived, carried in on removable media. That much is well established. The part worth your attention is how it got close enough to be carried: the attackers did not go at the plant. They went at the engineering firms that worked with it — the contractors and suppliers whose people and equipment moved in and out legitimately.
This is why the usual dismissal misses. That was a nation state. That was centrifuges. That was sixteen years ago. All true, and none of it changes the lesson, which is not "sophisticated attackers can cross an air gap". It is that the sensible way in was through the people already allowed in. That door is still there, in your plant, and it is not exotic. It is a maintenance contract.
The gap does not get attacked. It gets renovated away.
Here is the thing nobody wants to hear: in most plants the isolation was not defeated by anybody. It was dismantled by people doing their jobs properly, one defensible decision at a time.
The machine vendor needs to diagnose a fault at three in the morning without flying someone in, so a remote support path appears. Finance needs production numbers in the monthly report, so a connection goes out to a business system. A new line arrives with a cellular modem already fitted, because that is how the vendor supports it, and nobody puts it on a drawing. A contractor brings a laptop to load new logic, and it is the same laptop they used at the last site.
Not one of those is a bad decision on its own. Every one of them has a business case that would survive a review. Together, over a decade, they are the reason the word "air gapped" is doing no work in that sentence.
The industry's own numbers
You do not have to take my word for the shape of this. The published surveys are unusually blunt.
Around 42% of control system environments now report direct connectivity to the internet, against roughly 12% six years earlier. Close to 88% of manufacturers permit third-party remote access into operational environments, and a majority of those grant it to more than a hundred separate outside parties. Something like 70% of assessed sites carry undocumented or poorly secured external connections, and between a third and 40% of operational assets are not on anybody's inventory to begin with.
Then the figure that ties it together. In one of the larger annual surveys of industrial operators, about half of the incidents in the past year began with unauthorised external access — frequently through third-party remote maintenance — while fewer than 15% of organisations have advanced controls on that access at all.
The most common way in is the one almost nobody is watching.
I measured my own, and it was not what I expected
I run a small industrial estate for exactly this kind of question, so rather than theorise I watched every conversation on it for a full day.
I expected the industrial equipment to be the problem. It was the opposite. The control gear was the best-behaved thing on the network — across the whole day the site and control zones between them reached exactly one destination outside.
The exposure was somewhere else entirely. One machine — the one carrying the database, the message broker and the operator screens — was reaching out to eighty different external destinations, and accepting unsolicited inbound connections from the public internet, because at some point it had quietly picked up a second job unrelated to the plant.
Nobody decided that. It was a machine that was already there and had capacity, and so it grew. If I had drawn my own boundary from memory rather than from measurement, I would have drawn it in the wrong place — and I built the thing.
What to actually do
Stop defending the word. "Air gapped" is not a control, it is a claim, and the useful version of the conversation starts by replacing it with a list of specific paths and who owns each.
Write down every way in, including the boring ones. Vendor support. The contractor's laptop. The removable drive that carries firmware. The modem in the new machine. The reporting link to the business. The list is nearly always longer than the drawing.
Assume the temporary connections are permanent, because they are. The maintenance laptop that plugs into anything is a real path with real access, and the standards expect it to be treated as its own thing rather than as an occasional visitor.
Look at who has remote access, and count them. If the honest answer is dozens of outside organisations, that is not an argument for panic — it is an argument for knowing which ones, through what, watched by whom.
Then measure, rather than asking. Watch the traffic for a day and compare it against what you believed. I did that on a network I built myself and it still surprised me, which is the most useful thing I can tell you about this whole subject.
The goal is not to restore an air gap. In most plants that ship sailed years ago and the business would not accept it back. The goal is to know exactly how many doors there are, who holds each key, and which ones anybody is actually watching.
What a day of watching my own network produced — the full flow inventory and the policy it implies — is in the segmentation piece. Why temporarily connected equipment is supposed to be its own zone, and what else the standard asks for, is in a conduit is not a cable.
One more door, found later: a gateway backup carries a working database password and the estate's own approval inside it, so the copy you restore to test the file is a machine your plant already trusts — a restore is not a rehearsal.
And the reason the doors keep multiplying is that the industry has spent twenty-five years buying tunnels when the thing it could never produce was the list — the tunnel was never the hard part.
If the plant really is isolated, the threat arrives already inside, on media or on a person, so the walls inside the plant matter more rather than less. What that looks like, room by room: one firewall is not segmentation.
Keep reading
Newsletter
New essays, by email.
SCADA, cloud, AI, and the plant floor — a short email when something new is published. No noise, unsubscribe anytime.


