Highlights:

  • Connected, integrated and interoperable applications can make it more difficult to maintain effective virtual air gaps around operational technology
  • Zero-trust cybersecurity can help protect operational technology from cyber threats while preserving the connectivity required for smarter building operations
  • Identity-based access, microsegmentation and encryption can help reduce the attack surface and limit the spread of cyber threats

The original concept of an air gap in technology was literal: physically disconnecting critical systems from the internet to protect them from cyberattacks. But over time, cloud computing and the need for remote access made that approach untenable. What emerged in its place was the virtual air gap, which allows systems to be connected to the internet while using cybersecurity controls to keep them isolated.

Many organizations assume these virtual air gaps are enough to protect their operational technology. In practice, those boundaries are often weaker than expected. In fact, a 2022 report by the U.S. National Security Telecommunications Advisory Committee (NSTAC) offered a stark assessment of this approach: “in most environments, the air gap is a myth.”

According to the report, risk assessments frequently found that OT systems their owners assumed were air-gapped were not as isolated as they believed. Among the reasons:

  • Employees find ways around controls that create inefficiencies
  • Organizations lose track of which devices reside on which networks, allowing systems to “accidentally converge”
  • Shadow IT can introduce systems or modifications without formal IT oversight

For building owners, the consequences are operational, not merely technical. A compromised connection can disrupt critical equipment, interrupt building services and expose systems that were never designed to operate in a connected threat environment. Those effects can lead to disrupted occupant comfort, delayed maintenance operations, increased operational costs and undermined business continuity.

Those weaknesses have become harder to ignore as intelligent building solutions connect more devices, systems and applications. Protecting critical assets now requires more than a logical boundary between IT and OT. It requires an identity-based, zero-trust approach that verifies every connection and limits what authorized users and devices can reach.

Explore CRE cybersecurity trends in the AI & Digitalization in Facilities Management Report

Download report

Replacing assumed trust with verified identity

A virtual air gap is only as strong as the controls used to establish and maintain it. Effective zero-trust cybersecurity restricts communication based on the identity of users and devices, rather than simply assuming that anything inside a network perimeter can be trusted.

OpenBlue Airwall is a purpose-built zero-trust cybersecurity solution for protecting connected IT, OT, IoT, cloud and remote environments. It creates encrypted private overlay networks and applies identity-based policies so authorized endpoints can communicate without exposing protected devices to unauthorized users.

The result is a virtual air gap that does not depend on physical disconnection or presumed network boundaries to protect critical assets.

Reducing the attack surface and limiting lateral movement

Keeping unauthorized users out is only part of the challenge. Organizations also need to consider what happens if a device or credential is compromised.

Microsegmentation divides a network into smaller, tightly controlled segments and restricts communication between them. That can reduce the attack surface while helping contain an intrusion before it spreads to other critical systems.

OpenBlue Airwall uses identity-based microsegmentation to control communication at the device or workload level. Protected assets can also be “cloaked,” making them invisible to unauthorized users and devices. End-to-end encryption protects communications between authorized endpoints, while segmentation helps prevent malware and ransomware from moving laterally through the network. This helps reduce cyber risk, limit operational disruption and protect critical building services while maintaining secure connectivity.

These protections can be particularly valuable for legacy OT and IoT devices that may not support modern security controls themselves. OpenBlue Airwall can isolate these devices and make them reachable only by authorized endpoints, without requiring organizations to replace the underlying equipment.

This architecture gives security teams a practical way to support connected operations while reducing unnecessary exposure.

Making secure connectivity part of building intelligence

For intelligent buildings, connectivity is essential to getting more value from building data. But as more systems, devices and applications become connected, organizations also need to manage the cybersecurity risks those connections can introduce.

OpenBlue Intelligence, for example, connects building management systems, HVAC equipment, energy meters, occupancy sensors and other sources through a secure, BMS-agnostic platform. Its underlying OpenBlue Data Platform harmonizes that information into a structured data layer that supports analytics, AI applications and automation. Secure, scalable infrastructure and zero-trust cybersecurity help protect the connections that make those capabilities possible.

That illustrates why returning to physical isolation isn't a practical answer. As organizations connect more building systems to support remote operations, automation and AI, cybersecurity needs to enable those connections without unnecessarily exposing the systems behind them.

OpenBlue Bridge shows how secure connectivity and building intelligence can work together. It connects on-premises systems and subsystems to OpenBlue Cloud through an Airwall Gateway. The gateway creates a virtual air gap by cloaking protected devices, encrypting communications and using microsegmentation to control data moving between devices and from the building site to the cloud.

How can buildings stay connected without weakening OT security?

As building systems become more interconnected, the traditional idea of a virtual air gap must evolve. Simply establishing logical boundaries between IT and OT is no longer enough. Those boundaries need to be actively reinforced with controls that determine which users and devices can communicate, protect the data moving between them and limit how far a threat can travel.

As intelligent buildings bring IT and OT closer together, organizations need visibility into what is connected and cybersecurity architectures that continuously control how those systems communicate. Identity-based access, microsegmentation, cloaking and encryption can reinforce the virtual air gap while allowing data to flow securely and applications to deliver their full value and functionality.

There is no going back to yesterday’s disconnected building. Organizations need a security model that preserves the protective value of isolation while allowing authorized data, devices and applications to connect. A zero-trust architecture makes that possible by verifying every connection and limiting the impact of a compromised user, device or credential.

Create a virtual air gap for connected OT with identity-based zero trust

Explore OpenBlue Airwall

FAQs

  • What is an air gap in operational technology?
    An air gap traditionally refers to the physical separation of operational technology (OT) from the internet or other connected systems. Today, organizations can use virtual air gaps to isolate OT while maintaining the connectivity required for remote access, cloud applications and other intelligent building capabilities.
  • What is a virtual air gap?
    A virtual air gap uses cybersecurity controls rather than physical disconnection to isolate critical systems and assets. Effective virtual air gaps can use technologies such as identity-based access, microsegmentation, cloaking and encryption to control which users and devices can communicate and help prevent threats from moving between systems.
  • Why is zero-trust cybersecurity important for operational technology?
    Zero-trust cybersecurity does not assume that a user or device should be trusted simply because it is inside a network perimeter. Instead, access is based on identity and defined permissions, helping organizations protect connected OT while allowing authorized users and devices to communicate.
  • How does OpenBlue Airwall protect operational technology?
    OpenBlue Airwall is a purpose-built zero-trust cybersecurity solution that creates private, encrypted overlay networks across existing infrastructure. It uses identity-based policies, microsegmentation, cloaking and end-to-end encryption to restrict access to protected assets and help limit lateral movement if a cyber threat enters the environment.
  • Can legacy OT and IoT devices be protected without replacing them?
    Yes. OpenBlue Airwall can protect legacy OT, ICS and IoT devices that do not support modern security controls. It can cloak the devices, segment their communications and limit access to authorized endpoints without requiring replacement of the underlying equipment.