As agencies migrate to the cloud, security teams are reassessing the risks and limitations of data secured in air-gapped environments.

IT teams rely on air-gapped networks to store sensitive and critical data because they’re not connected to the internet, only allowing localized access to the protected information. This makes physical security an active component of cybersecurity. However, this can sometimes foster a false sense of security, hiding vulnerabilities and gaps that clever attackers or malicious insiders can exploit.

As agencies continue to maintain critical systems and data on air-gapped servers or systems running end-of-life operating systems, they must focus on key threats like data transfers from external storage media, as well as maintaining security so that threats that do penetrate that seemingly unbreakable air-gap can’t run wild once inside. At a recent FedInsider webinar, thought leaders from government and industry discussed how security professionals are reevaluating and mitigating the risks associated with cloud-based and air-gapped systems in an ever-evolving threat landscape.

Featured Experts:

Mark Krzysko, Retired Principal Deputy Director, Enterprise Information, U.S. Department of Defense

Mark Krzysko
Retired Principal Deputy Director,
Enterprise Information, DOD
Garrett Lee, Regional Vice President, Enterprise Security Group, Broadcom (ESG)

Garrett Lee
Regional Vice President, Enterprise
Security Group, Broadcom
Carlos Soto, Senior Industry Consultant, Radix

Carlos Soto
Senior Industry Consultant,
Radix

The State of Air-Gapped Networks

Air-gapping involves physically or logically isolating networks and systems from the internet. Some of these environments are fully air-gapped, some are partially air-gapped and some allow for intermittent or unidirectional internet connectivity.

Air-gapping is a common strategy in U.S. defense, warfighting and intelligence agencies to protect mission-critical data, and it is also seen in energy and critical manufacturing systems, according to Garrett Lee, Regional Vice President of the Enterprise Security Group at Broadcom. “It involves limiting external conductivity and relying on isolation to protect data and systems,” he added.

Use cases are diverse, but the practice is common in sensitive environments handling classified information, weapon systems, mission-critical storage, nuclear operating systems, crypto operations, financial systems, digital forensics, biohazard safety facilities and systems that require isolation from catastrophic physical consequences (like water treatment facilities).

“These are a lot of the reasons why some systems require sensitive data to be safeguarded. Some of those include shrinking the attack surface as much as possible, guarding against unwanted change, or for maintaining system integrity,” Lee said.

While some organizations are beginning to experiment with hybrid air-gapped environments, traditional air-gapped environments, like those used by the Defense Department, pose an additional operational challenge because those environments are meant to provide absolutely no external access to fully secured data, Lee added.

According to Carlos Soto, Senior Industry Consultant at Radix, most places will probably need to operate with some sort of a balance in their air-gapping strategy. For example, critical infrastructure environments or industrial control systems can be air-gapped, but also require data to occasionally move to other locations so that people who work offsite, like data scientists, engineers or facility operators, can analyze and use it. “It is a careful balance there,” Soto said.

The Gaps in Air-Gapping

From a federal perspective, air-gapping may make sharing data difficult, especially as technology advances. “We keep seeing technology and operations converge,” said Mark Krzysko, retired Principal Deputy of Acquisition Policy and Innovation Director of Enterprise Information for the Department of Defense.

Air-gapping is one technique, but securing federal environments in a way that doesn’t negatively impact operations is also important. “We need to collaborate across federations, services, components and the intelligence community. We have to ask how we can do that better,” Krzysko said.

And while air-gapping reduces remote access risks, it’s not immune to attack. Lee said that having an air-gapped network can create a false sense of security because known vulnerabilities can still exist inside of those air-gapped environments. Should an attack take place because of something like a malicious insider or simply a configuration mistake, those air-gapped systems could be defenseless against it unless security and monitoring is maintained.

For example, many air-gapped environments rely heavily on removable media like USB drives, DVDs, CDs, SSDs and portable hard drives to move data around or to get patches into air-gapped environments. This has historically also been an attack vector that can introduce unwanted executables in the environment, or used as a way to exfiltrate data. As such, all of those pathways should be monitored.

“You need the right level of logging and telemetry to understand what’s going on in the environment to spot things like lateral movement and potential data exfiltration,” Lee said. But many security technology solutions on the market today that do that are cloud-based, and thus require a persistent internet connection. Operating them inside an air-gapped environment can be a big challenge. You need monitoring and protection that can work without a cloud connection.

And it’s not just about monitoring the environment and then using key drives to upload patches and system configurations. According to Soto, true security in government also requires you to go back to the supply chain to make sure that the drives being used have not been altered or tampered with. “That’s a big deal in government,” Soto said, “because you need to sanitize the supply chain for that hardware and make sure the organization does its due diligence. If you don’t then you risk becoming a victim to tampering or external threats, because that is one way a clever adversary could gain entry.”

According to Krzysko, one solution to that whole situation involves solid governance for air-gapped environments that balances protection with the ability to share information when needed. That’s how agencies can meet their operational security needs with the strict controls required to work in air-gapped networks. “We are now in a world where balance has got to be key, or else we may not see everything because maybe we are air-gapping data that someone else needs to examine,” Krzysko said.

To make that work, it first requires breaking down silos and understanding what data needs to be properly deployed in air-gapped networks. That way agencies can properly deploy and protect their data, working operationally with air-gapped networks – and not against them, Krzysko said.

Ensuring Air-Gapped Network Protection

The goal of employing capabilities in an air-gapped environment is to secure them similarly to how internet-facing capabilities are secured, but in a way that allows those capabilities to operate without an internet connection. You also need to have timely patching and as much cyber hygiene as possible. According to Lee, that includes continuous monitoring, observability, analysis, logging, policy-based data protection and a zero-trust mentality.

Deciding which of those parameters and protections to deploy and how strongly will depend on what needs protecting and why, which means that first you have to fully understand your data. “You need to make sure there’s rigor around the classification of data,” Lee said. “And then all of the decisions you make should be tailored to the environment with respect to the mission,” Lee said.

Soto agreed that having a good data architecture strategy was key. And, according to Soto, that means more than just creating a logical air-gapped database, data warehouse or data lake. “A lot of it is also knowing how to move data quickly and securely out of an air-gapped environment when needed,” Soto said. “You need to have a plan to do that, and the tools to make it happen.”

For many agencies, getting to the point where they can strike a balance between locking data down with air-gapping and also being able to share or move it when needed will require partnering with industry to acquire the right tools and solutions to move faster and safer. Krzysko pointed to the recent Adaptive Acquisition Framework as a good guide to start more efficiently leveraging commercially available tools and techniques.

“We have to find ways to move faster,” Krzysko said. “We need to empower program managers, contracting officers and technologists to work together to say what we can do and how to find the right solutions.”

FI-Symantec-CB-Broadcom-Carahsoft-CPS-Logos