Skip to content
StrikeCyberStrikeCyber
Research

Field Notes: The Air Gap That Was Not There

6 August 2026·6 min readIndustry BriefingsField Notes

Ask a plant manager whether their control systems are connected to the corporate network and the answer is often an immediate no. It is air-gapped. That belief is one of the most common, and most dangerous, assumptions we test in industrial engagements. This field note describes an anonymised engagement, mining and manufacturing in character, where the operational technology environment that everyone believed was isolated turned out to be reachable from an ordinary corporate laptop. Every identifying detail has been removed. What remains is the attack path, because the pattern repeats across the sector.

The IT to OT attack path we followed was not clever. It relied on three ordinary weaknesses that accumulate quietly in almost any industrial operation: a flat network, a host with a foot in both worlds, and credentials that worked in more places than they should have.

The Setup

The organisation ran a substantial physical operation, with a corporate IT environment for the usual business functions and a separate operational technology environment running the industrial control systems that kept production moving. On the architecture diagram, the two were clearly divided. The OT side was described as air-gapped, and the people responsible for it believed that description without reservation.

The engagement was scoped with safety as the first principle. Operational technology is not a corporate network. The systems control physical processes, and an outage or an unexpected command can have real-world consequences for equipment and for people. So the rules of engagement were strict. No intrusive scanning against live controllers, no exploitation that could disturb the process, and plant operators on hand throughout with the authority to stop the work instantly. Our objective was to map and prove the path from corporate IT toward OT, not to touch the process itself.

We began, as an attacker would, from a position of assumed compromise on the corporate network, standing in for a phished laptop or a foothold gained through any of the routine methods that put an adversary inside the IT environment.

The Attack

The first surprise came quickly. The corporate network was flat in the places that mattered. Segmentation existed on the diagram, but the enforced boundaries between the business network and the systems that touched operations were far weaker in reality. From our foothold we could see and reach hosts that should have sat on the far side of a controlled boundary.

The pivot point was a dual-homed host. This was a management server that, for reasons of operational convenience added at some point in the past, had one network connection into the corporate environment and another into the OT environment. It bridged the two worlds. To an attacker, a dual-homed host is a doorway, and this one was not locked. It was reachable from where we stood, and it had a route onward into the environment that was supposed to have no route at all.

The third weakness completed the chain. Credentials were shared and reused across the boundary. An administrative account that operated on the corporate side was also valid on systems that led into OT. We did not need to crack anything. The same keys that opened the front office opened the door to the plant. Using access we already held, we authenticated our way across the bridge.

Throughout, we kept strictly to the safe testing rules. We proved reachability and access using passive observation and careful, authenticated checks. We did not scan or exploit the live controllers, and the process was never disturbed.

What We Reached

Following the path, we crossed from the corporate IT network into the operational technology environment that had been described as air-gapped. We reached the network segment where industrial control systems and their supporting infrastructure lived, the layer from which an attacker with hostile intent could begin to interact with the systems that govern physical production.

We deliberately stopped at proving access. We want to be precise and avoid overstating the outcome. We did not send commands to controllers, and we did not test the limits of what could be done to the process, because doing so would have breached the safety-first rules and risked real harm. The finding was qualitative and it was serious enough on its own: an intrusion beginning with an ordinary corporate laptop had a clear, unbroken path to the environment that ran the physical operation. The air gap existed on paper. It did not exist in the network.

Impact

For an industrial operator, this is the scenario that keeps risk owners awake. The distance between a routine IT compromise and an operational or safety incident was far shorter than anyone believed. An attacker who gained the same corporate foothold, without the restraint of an agreed scope, would have been positioned to disrupt production, damage equipment or endanger people.

The business consequences of an OT incident are not measured only in data. They are measured in downtime, in physical safety, in environmental exposure and in the trust of regulators and communities. The gap here was not caused by a single dramatic failure. It was the slow accumulation of convenient decisions, each reasonable on its own, that together dissolved the separation the organisation counted on.

How to Prevent This

The path we followed can be closed, and none of the remedies are exotic.

Segment the network and enforce it. Place the OT environment behind boundaries that are actually enforced, not just drawn. A recognised reference architecture puts a demilitarised zone and brokered data exchange between the enterprise and control networks, so that only a small set of known, authenticated and monitored flows can cross. Treat any traffic between IT and OT as something to define explicitly and watch closely.

Eliminate uncontrolled bridges. Find and remove dual-homed hosts that span both environments. Where a connection is genuinely required, route it through a hardened, monitored broker or jump host rather than a machine quietly wearing two hats. Inventory these bridges regularly, because they tend to reappear as operations solve new problems.

Separate credentials across the boundary. Accounts that operate in the corporate environment must not be valid in OT. Use distinct identities, strong authentication and least privilege, so that a compromise on one side does not hand an attacker the keys to the other. Shared and reused credentials were the link that completed our chain, and removing them breaks it.

Test the separation, safely. The only reliable way to know whether an air gap is real is to have experienced operators try to cross it under strict, safety-first rules. OT testing is not a standard corporate penetration test, and it must be run by people who understand that availability and physical safety come first. Passive analysis, careful scoping and close coordination with plant operators let you prove the attack path without ever disturbing the process.

If your organisation runs industrial or control systems and relies on an air gap that has never been independently verified, this is the assumption worth testing before an attacker tests it for you. Our team runs safe, carefully scoped OT-aware engagements. Explore penetration testing for operational environments, threat-led red team testing of the IT to OT path, or get in touch to scope it together. If you are dealing with a live incident, our incident response team can help.

Frequently asked questions

What is an IT to OT attack path?

An IT to OT attack path is the route an attacker takes from a corporate information technology network into the operational technology environment that runs physical processes such as production lines, plant equipment or industrial control systems. In theory these environments are separated, often described as air-gapped. In practice they are frequently connected through management links, historians, remote access tools or dual-homed hosts. An IT to OT attack path is significant because an intrusion that starts with something ordinary, like a phished laptop, can end at systems that control physical safety and production if the separation is weaker than assumed.

What is an air gap and why do so many fail?

An air gap is a claimed physical or logical separation where the operational technology network has no connection to the corporate network or the internet. Air gaps fail because operations need data and access to function. Production reporting, remote maintenance, vendor support, patching and monitoring all create connections over time, often added quietly to solve an immediate problem. A single dual-homed host with a network card in each environment, a shared jump box or a forgotten management link is enough to defeat the gap. Many organisations believe they have an air gap that ceased to exist years ago.

How can OT and ICS environments be tested safely?

Operational technology testing must prioritise safety and availability above all else, because these systems control physical processes. Safe testing avoids intrusive scanning or exploitation against live production controllers. Instead it favours passive traffic analysis, careful and clearly scoped assessment, testing against offline or replica systems where possible, and close coordination with plant operators who can halt the work instantly. The goal is to map and prove the attack path from corporate IT toward OT without ever disturbing the process itself. Experienced operators treat OT engagements very differently from a standard corporate penetration test.

Why is network segmentation important for OT security?

Segmentation is the primary control that stops an ordinary IT intrusion from becoming an operational or safety incident. Proper segmentation places the operational technology environment behind enforced boundaries, so that traffic between IT and OT is limited to a small set of known, monitored and authenticated flows. A recognised reference model places demilitarised zones and brokered data exchange between the enterprise and control networks. Without segmentation, a flat network lets an attacker who compromises a laptop move directly toward industrial controllers, which is exactly the scenario this field note describes.

What are the most common IT to OT weaknesses found in engagements?

The recurring weaknesses are flat or poorly segmented networks that let corporate and control traffic mix, dual-homed hosts that bridge both environments, and shared or reused credentials that work across IT and OT. Remote access tools installed for vendor maintenance, unmonitored management links and out-of-date jump boxes add to the exposure. None of these are exotic. They accumulate quietly as operations evolve, and each one chips away at the separation an organisation believes it has, until the air gap exists only on the diagram rather than in the network.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation