Debunking the Air Gap Myth and Other OT Security Realities

▼ Summary
– Benjamin Bachmann, Director Group Information Security at Bilfinger, discusses industrial plant defense with Help Net Security.
– Attackers aim to control operations rather than steal data.
– The air gap, a traditional security measure, is largely considered a myth.
– Bachmann provides insights on why operational control is the primary target.
– The interview covers distinct aspects of industrial cybersecurity threats and defenses.
Benjamin Bachmann, Director of Group Information Security at Bilfinger, sat down with Help Net Security to challenge long-held assumptions about protecting industrial facilities. His central message is clear: attackers are no longer interested in simply stealing data. Instead, they aim to take control of operations, making traditional defenses like the air gap largely obsolete.
Bachmann argues that the air gap myth persists because it offers a comforting illusion of safety. In reality, modern industrial networks are far more connected than most realize. Maintenance laptops, vendor connections, and remote access tools routinely bridge the gap, creating unseen vulnerabilities that sophisticated adversaries exploit. The real threat, he emphasizes, is operational disruption, not data theft. A targeted attack on a plant’s control systems can halt production, damage equipment, or even endanger lives.
To counter this, Bachmann advocates for a shift in mindset. Operational Technology (OT) security must move beyond perimeter-based defenses and embrace continuous monitoring, segmentation, and rigorous access controls. He stresses that visibility into the industrial control system (ICS) environment is paramount. Without it, organizations are blind to the very pathways attackers use to bypass outdated security models.
The interview underscores a critical reality for plant operators: the battlefield has changed. Protecting industrial assets now requires acknowledging that air gaps are fiction and that proactive, layered defenses are the only viable path forward.
(Source: Help Net Security)




