<img src="https://secure.leadforensics.com/97241.png" style="display:none;">

What Is an Air-Gapped Network and How Do You Monitor It?

On July 28, 2026, CISA, the Australian Signals Directorate, the FBI, and international partners published CI Fortify, joint guidance that tells critical infrastructure operators to prepare to isolate their most vital operational technology (OT) systems from every other network. For many organizations, that means running an air-gapped network, which raises a question most guides skip: once a network is cut off from everything else, how do you see what's happening inside it?

An air-gapped network has no physical or logical connection to the internet or to any other untrusted network. Data only crosses the boundary by hand, under human control. That blocks remote attacks, but it doesn't stop infected USB drives, insiders, or accidental connections, and it won't tell you when they happen.

You monitor an air-gapped network by building your visibility infrastructure entirely inside the gap. Passive network test access points (TAPs) copy every packet without creating a path back into the network. A network packet broker inside the enclave filters that traffic and sends it to locally hosted security tools. If alerts need to leave, they leave through a strictly one-way channel.

What Is an Air-Gapped Network?

The National Institute of Standards and Technology (NIST) defines an air gap as an interface between two systems that aren't physically connected, where any logical connection is manual rather than automated. In plain terms, there's no cable, wireless link, or software tunnel to the outside world. If data needs to cross, a person carries it.

What makes a network truly air-gapped

A network only qualifies as air-gapped when it meets all of these conditions:

  • No internet connectivity: No route, proxy, or gateway connects any device to the public internet
  • No links to other internal networks: The corporate IT network, vendor networks, and cloud platforms can't reach the enclave
  • No wireless interfaces: Wi-Fi, Bluetooth, and cellular modems are removed or disabled on every device
  • Manual data transfer only: Files cross the boundary through controlled, human-operated processes
  • Physical access control: Only authorized people can reach the hardware, cabling, and transfer stations

If even one condition fails, you're running a segmented network, which needs different controls.

Types of Air Gaps

The term "air gap" gets used loosely, and each type offers a different level of protection.

Physical air gaps

A physical air gap is the strictest form. The isolated network runs on its own switches, cabling, and infrastructure, with nothing shared with other environments. The CI Fortify guidance ranks physical isolation as the most effective protection for vital OT systems.

Logical air gaps

A logical air gap uses firewalls, virtual LANs (VLANs), access controls, or encryption to separate systems that still share physical infrastructure. It's cheaper to run, but one misconfigured rule or stolen credential can reconnect what you thought was isolated. Strictly, NIST wouldn't count it as an air gap at all.

One-way connections

Some environments need data to leave the enclave, such as logs for a central security team. A data diode is hardware that physically lets data travel in only one direction, keeping most of the protection of a physical air gap while allowing controlled export.

The type of air gap you run changes what you need to watch:

  • Physical air gaps: Monitor for anything that shouldn't exist, such as new devices, unexpected protocols, or outbound connection attempts
  • Logical air gaps: Watch the boundaries closely, because firewall rule changes and routing errors can quietly reopen paths
  • One-way connections: Verify that traffic only ever flows in the permitted direction

Who Uses Air-Gapped Networks?

Organizations reserve air gaps for systems where a breach would be catastrophic, including:

  • Government and defense: Classified networks and weapons systems that handle national security information
  • Energy and utilities: Control systems for power generation, transmission, and water treatment
  • Oil, gas, and manufacturing: Industrial control systems (ICS) and safety instrumented systems
  • Financial services: Payment and settlement systems, plus offline backups that ransomware can't reach

Why isolation is back on the agenda

For years, OT networks drifted toward connectivity. Persistent state-sponsored campaigns against critical infrastructure have pushed that trend into reverse. CI Fortify asks operators to map every connection to their vital systems and build isolation points in advance, so they can disconnect quickly and keep running for an extended period. Industrial Cyber's summary of the guidance points out that it pairs routing checks with continuous network monitoring to catch unintended paths back into isolated environments. The agencies asking you to isolate also expect you to keep watching.

How Data Moves In and Out of an Air-Gapped Network

Even the most isolated network needs software patches, antivirus signatures, configuration files, and occasional data exports. Every one of those transfers deliberately bridges the gap, so well-run environments follow a strict process.

A typical controlled transfer works like this:

  1. Request and approve: A named person requests the transfer and a second person approves it
  2. Prepare on a clean system: Files are downloaded or exported on a dedicated, hardened workstation
  3. Scan and sanitize: A media scanning station checks both the files and the removable drive for malware
  4. Transfer and log: An authorized user carries the media into the enclave and records what moved, when, and who moved it
  5. Verify inside the enclave: The receiving system checks file integrity before anything is installed or opened

Removable media and one-way devices

USB drives and external disks are the most common transfer method, and also the most common attack method. Where regular export is needed, CI Fortify recommends data diodes or cross-domain solutions for high-assurance transfers instead.

Benefits and Drawbacks of Air-Gapped Networks

An air gap is one of the strongest security controls available, but it has real operational costs.

What air gaps do well

  • Block remote attacks: Attackers can't exploit a vulnerability, guess a password, or use stolen credentials over a connection that doesn't exist
  • Contain incidents: Malware on the corporate network can't spread into the enclave on its own
  • Protect backups: Isolated copies of critical data stay out of reach of ransomware

The trade-offs

  • Slower patching: Every update has to be carried in, so isolated systems often fall behind
  • Manual workflows: Moving data takes time and people, which encourages risky workarounds
  • Limited tooling: Cloud-based security platforms, live threat intelligence feeds, and remote vendor support don't work inside the gap
  • False confidence: Teams sometimes assume isolation equals safety and stop watching

That last point is the most dangerous. An air gap reduces the number of ways in. It doesn't tell you when someone has found one.

How Attackers Breach Air-Gapped Networks

Stuxnet, which sabotaged centrifuges at Iran's Natanz enrichment facility and is widely reported to have crossed the air gap on infected USB drives, is the best-known example.

Infected removable media

When ESET researchers analyzed 17 malicious frameworks built to attack air-gapped networks, they found that every one of them used USB drives to move data in and out. The threat is growing in industrial environments too. Honeywell's 2024 USB Threat Report found that 51% of the malware it analyzed was designed to spread via USB, up from 9% in 2019.

Insiders and the supply chain

A contractor with legitimate access, a maintenance laptop, or a tampered replacement part can all carry threats across the gap.

Accidental bridges

Some of the most common failures are unintentional:

  • Dual-homed devices: A workstation connected to both the enclave and another network
  • Forgotten wireless: A Wi-Fi or cellular module left enabled on an industrial device
  • Temporary remote access: A vendor connection set up for troubleshooting and never removed
  • Shared services: Directory, time, or backup servers that quietly link isolated and corporate networks

Hidden dependencies like these are exactly what CI Fortify asks operators to find and remove.

Covert channels

Researchers have shown that malware inside an air-gapped network can leak data using sound, heat, light, or electromagnetic signals. One technique, LANTENNA, uses the network's own Ethernet cables as antennas, driven by malware-generated network activity. These attacks are slow, but some of them happen on the wire, where you can watch for them.

Why Air-Gapped Networks Still Need Monitoring

Every breach path above ends the same way: something happens on the internal network. Malware moves between hosts, a new device appears, or a compromised machine tries to reach a server it can't find. If you aren't watching internal traffic, none of that shows up until the damage is done.

What internal monitoring catches

Continuous traffic monitoring inside the enclave helps you:

  • Spot new or unknown devices: Any MAC or IP address that isn't on your asset list deserves investigation
  • Detect outbound connection attempts: In a true air gap, nothing should try to reach an internet address, so every external DNS lookup or connection attempt is a red flag
  • Identify lateral movement: Unusual connections between workstations, servers, and controllers can reveal an attacker spreading through the network
  • Catch unauthorized changes: Unexpected engineering commands or configuration uploads to industrial controllers stand out clearly

Air-gapped traffic is easier to baseline

With no web browsing, cloud services, or software checking in with vendors, air-gapped traffic is small and predictable. That makes anomalies far easier to spot than on a typical corporate network, where malicious traffic hides among millions of legitimate connections.

The Monitoring Challenges Unique to Air-Gapped Networks

Standard monitoring approaches often clash with the rules of an isolated environment.

Cloud-based tools can't reach in

Many detection platforms send telemetry to the cloud. Inside an air gap, every tool runs on-premises, and updates arrive through the same controlled transfer process as everything else.

SPAN ports add risk and miss traffic

Switch port analyzer (SPAN) ports, also called mirror ports, copy traffic from a switch to a monitoring tool. They're convenient, but their drawbacks matter more inside an air gap:

  • Dropped packets: Switches give mirrored traffic low priority and drop it under heavy load, so your tools see an incomplete picture
  • Configuration changes: Every SPAN session means logging into production switches and changing how they're set up
  • Limited sessions: Many switches support only a small number of SPAN sessions, forcing trade-offs between tools
  • Missing errors: SPAN ports often discard malformed packets and physical layer errors

Every new device is a potential bridge

A monitoring tool with a management interface on the wrong network, or a sensor that expects to reach a vendor portal, can undo the isolation you worked to build.

How to Monitor an Air-Gapped Network

The principle is simple: keep every part of your visibility infrastructure inside the boundary, and make sure nothing you add can send traffic back into the network you're watching.

  1. Map the network: Document every link, switch, and critical asset inside the enclave so you know where to capture traffic
  2. Install TAPs on key links: Place TAPs at the core, at zone boundaries, and on links to critical controllers or servers
  3. Aggregate traffic with a packet broker: Combine TAP feeds and send each tool only the traffic it needs
  4. Run detection tools locally: Host intrusion detection, network detection, and packet capture tools inside the enclave
  5. Baseline normal behavior: Record typical traffic patterns so deviations stand out
  6. Control what leaves: If alerts must reach a central security team, send them out through a one-way device only

Use passive TAPs for traffic access

A TAP copies every packet on a link, including errors, to a monitoring port. Passive fiber TAPs suit air-gapped networks especially well. They split the optical signal with no power, no software, and no configuration, so there's nothing to hack or misconfigure. Their one-way design prevents data flowing from your tools back into the live network, and they keep capturing traffic even during a power outage.

For copper links, Ethernet TAPs give you the same complete copy of traffic. They leave no visible footprint on the monitored network, so an attacker scanning the enclave can't find them, and our failsafe copper modules keep live traffic flowing if a TAP loses power.

Aggregate and filter traffic inside the enclave

A packet broker collects feeds from multiple TAPs and prepares them for your tools:

  • Aggregation: Combines traffic from many links so one tool can watch all of them
  • Filtering: Sends each tool only the protocols, VLANs, or address ranges it needs
  • Load balancing: Spreads high traffic volumes across several instances of the same tool
  • Payload masking: Hides sensitive data inside packets before it reaches tools and analysts

Our hybrid TAP and packet broker platforms, such as the SmartNA-XL, combine passive, active, and bypass TAP modules with packet broker functions in a single rack unit (1RU) chassis. That keeps the hardware footprint small in space-constrained enclaves.

Keep the management plane inside the gap

Your visibility hardware needs management, and that path must never become a back door:

  1. Isolate management ports: Connect the dedicated out-of-band management port to a management network that stays inside the enclave
  2. Use the local console when needed: Use the serial console for initial setup and emergency access
  3. Authenticate inside the boundary: Use local accounts or enclave-hosted RADIUS or TACACS+ servers, never a directory shared with the corporate network
  4. Lock down SNMP: Use Simple Network Management Protocol version 3 (SNMPv3) and point it only at an enclave-based management system

Drag-n-Vu, our graphical configuration engine, runs through the packet broker's own web interface, so you can build filters and port maps with no outside connection. It warns you before you create a path that isn't allowed, and one-click rollback reverses mistakes quickly.

Export alerts one way only

If your security operations center (SOC) needs visibility of the enclave, send alerts out through a data diode. Never give the SOC an inbound path to your tools.

What to Watch For on an Air-Gapped Network

Focus detection on activity that should never happen in an isolated environment:

  • External DNS queries or connection attempts: Malware often tries to contact its operators as soon as it runs, even when no route exists
  • New MAC addresses: Unknown hardware may be a rogue device, a contractor laptop, or a wireless bridge
  • New protocols or ports: Remote desktop, file sharing, or web traffic that has never appeared before
  • Traffic at unusual times: Activity outside maintenance windows or normal shift patterns
  • Changes to industrial controllers: Program downloads, firmware updates, or mode changes that weren't scheduled
  • Activity after media transfers: New connections or traffic spikes shortly after a USB drive was used

Correlate these alerts with your transfer logs. A new connection minutes after a USB transfer tells a very different story than one during planned maintenance.

Air-Gapped Network Monitoring Best Practices

Technology only works if the processes around it hold up.

Treat monitoring equipment as part of the boundary

Apply the same physical security and change control to TAPs, packet brokers, and tools as to the systems they monitor.

Keep detection tools current

Bring in signature and software updates on a fixed schedule, or tools inside the gap fall months behind.

Test isolation regularly

Don't assume the gap is still there:

  1. Scan for unexpected interfaces: Look for enabled wireless radios or extra network ports on enclave devices
  2. Review routing tables: Find static routes or default gateways that point outside the enclave
  3. Compare traffic to your asset list: Confirm every device seen on the wire is known and approved
  4. Match transfer logs to traffic: Check that every change in network behavior lines up with an approved activity

Frequently Asked Questions

Is an air-gapped network completely secure?

No. Air gaps block remote network attacks, but attackers can still get in through removable media, insiders, supply chain compromise, or accidental connections. Continuous internal monitoring is how you find out when that happens.

Can you use SPAN ports to monitor an air-gapped network?

You can, but SPAN ports drop packets under load and need configuration changes on production switches. Passive TAPs give you a complete copy of traffic without touching switch settings.

Does adding monitoring tools break the air gap?

Not if they stay entirely inside the enclave and export data one way only. Problems start when a tool or its management interface connects to an outside network.

How Network Critical Can Help

An air gap keeps attackers out, but it can't tell you when one gets in. To get its full value, you need passive traffic access and local analysis inside the boundary. Since 1997, we've built network visibility hardware for government, defense, energy, and financial organizations that can't afford blind spots, and every product is managed locally, so it fits naturally inside isolated environments.

Depending on the size and speed of your enclave, you can build your air-gapped monitoring architecture from:

  • SmartNA: A 1G modular TAP and packet broker with hot-swappable modules, ideal for smaller enclaves and remote sites
  • SmartNA-PortPlus: Scalable from 48 to 194 ports of 1G to 100G visibility, starting from a single 1RU unit
  • SmartNA-PortPlus HyperCore: 32 ports of up to 400G in 1RU for high-speed data center cores

Where your vital systems rely on logical isolation, INVIKTUS adds a zero trust security layer with no IP or MAC address, so intruders can't see it to attack it. Our team can help you design visibility that strengthens your air gap instead of weakening it.