Trust But Verify: Why Every Air-Gap Claim Deserves Scrutiny

Trust But Verify: Why Every Air-Gap Claim Deserves Scrutiny

🎙 Dino Busalacchi and Jim Cook 👥 192 📅 July 14, 2026 ⏱ 30 min 👁 37 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

air gapOT securityremote accesszero trustvisibility

Summary

In this episode of Industrial Cybersecurity Insider, hosts Dino Busalacchi and Jim Cook debunk the myth that OT environments are air-gapped and therefore secure. They share real-world examples from plant floors where cellular modems, guest Wi-Fi connections, and VPN concentrators create hidden connectivity, often without IT’s knowledge. The discussion highlights the organizational divide between IT and OT, with plant managers prioritizing uptime over security, leading to shadow IT practices. They emphasize that point-in-time assessments are insufficient and that continuous visibility is essential. The hosts also explore the limitations of zero trust in industrial settings, the challenges of securing legacy systems, and the importance of involving third-party experts to uncover the true state of network connectivity. They conclude by advocating for a ’trust but verify’ approach, combined with ongoing monitoring and collaboration between IT, OT, and external specialists.

137 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical, real-world grounding. The hosts provide concrete examples of how air-gap assumptions fail, such as finding cellular modems in machine centers and third-party technicians connecting to guest Wi-Fi. They effectively argue that the problem is both technical and organizational, emphasizing the lack of communication between IT and OT teams. The argumentation is solid, built on years of field experience, though it relies heavily on anecdotal evidence rather than empirical data. The hosts make a compelling case for the need for continuous visibility and third-party verification, but they do not delve into specific methodologies or tools, which could strengthen their argument.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The hosts are credible practitioners, but they do not cite specific studies, standards, or frameworks. The discussion is based on personal experience, which is valuable but not easily verifiable. The title accurately reflects the content, focusing on the need to scrutinize air-gap claims. The sources provided in the description are mostly links to the podcast and LinkedIn profiles, which do not directly support the technical claims. No comments were provided for analysis.

200 words

Title / Content Match

The title accurately reflects the content, which focuses on challenging the assumption of air-gapped OT networks and advocating for verification and continuous monitoring.

Quality & Reliability

7/10

The hosts are experienced practitioners in industrial cybersecurity, providing concrete examples from real plant floors. However, the discussion is largely anecdotal and lacks citations to specific studies or standards, limiting its verifiability.

Key Moments

Cited Sources

Concurring Sources

  • NIST SP 800-82 Guide to Industrial Control Systems (ICS) Security — Provides guidance on securing ICS, aligning with the episode's emphasis on OT security.
  • Purdue Model for Control Hierarchy — A reference model for ICS network segmentation, relevant to the discussion of OT network architecture.

Contribution & Novelties

The episode provides a practitioner’s perspective on the persistent myth of air-gapped OT networks, offering real-world examples and emphasizing the need for continuous visibility and third-party verification. It highlights the organizational and cultural barriers between IT and OT, which are often overlooked in technical discussions.

Pour aller plus loin :

  • NIST SP 800-82 Guide to Industrial Control Systems (ICS) Security — Provides foundational guidance on securing ICS, relevant to the discussion of OT security.
  • Purdue Model for Control Hierarchy — A reference model for ICS network segmentation, useful for understanding OT network architecture.
  • Zero Trust Architecture (NIST SP 800-207) — Discusses zero trust principles and their applicability, including challenges in OT environments.

112 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical level, and reliability, with a slight emphasis on practical experience over academic rigor. This suggests a content that is informative and credible from a practitioner standpoint, but may lack depth in theoretical foundations.

Reliability 7/10