Isolated and Air-Gapped Networks: Hardware Implications
Isolated networks exist because some systems should not be reachable from the general network at all β process control, laboratory instruments, secure records, and equipment whose firmware cannot be updated. The hardware decisions that follow are different from ordinary infrastructure.
Isolation is a spectrum, not a switch
Being precise about what you actually have prevents a false sense of security.
Segmented means separate VLANs with controlled routing between them. Traffic can cross where policy allows. Our segmentation guide covers this, including the common failure of creating VLANs and then permitting everything between them.
Isolated means separate physical infrastructure with no routed path at all β its own switches, its own cabling.
Air-gapped means no network connection of any kind, in either direction. Data moves by removable media or not at all.
Each is more restrictive and more operationally expensive than the last. The mistake is claiming the strictest while operating the loosest β an air gap with a laptop that connects to both sides is not an air gap.
Separate switches, not shared ones
For genuine isolation, the network hardware is separate rather than logically divided.
That has practical consequences worth planning for.
You need more switches, frequently small ones, at each location where isolated equipment sits. Our switch buying guide covers what to check, including that unmanaged switches have no VLAN support at all β which matters if someone adds one to gain ports.
Isolated switches still need management, and reaching them means either being physically present or having a management path β which is itself a connection that has to be justified.
Labelling matters more. Cables and ports on an isolated network must be unmistakably distinguishable, because the failure mode is someone patching the wrong port. Our documentation guide covers conventions, and colour-coded patch leads earn their cost here.
Updates are the hard problem
Isolation removes the usual route for patches, firmware and definitions, and that has to be solved deliberately rather than ignored.
Two consequences.
Removable media becomes the transfer path, which introduces its own risk. Controlled media, scanned before use, and a defined procedure rather than whatever memory stick is available.
Systems stay on older versions longer, sometimes indefinitely. That is frequently why they were isolated β equipment running software that cannot be patched, or a validated system where changing anything requires revalidation. Our legacy platform guide covers why those systems persist.
The honest position: isolation is a compensating control for systems that cannot be kept current. It is not a substitute for patching things that can be.
Spares matter more on isolated networks
Because the equipment is frequently old, specific, and hard to replace quickly.
Isolated networks tend to accumulate the systems nobody wants to touch β the process controller, the instrument with a serial interface, the machine running software from a supplier that no longer exists.
Three things follow.
Hold spares for the isolated side specifically, weighted by what stops the process rather than evenly. Our spares guide covers building the position.
A complete spare system is frequently better than components on very old equipment β it covers every failure mode and needs no disassembly under pressure.
Record exactly what is fitted, by part number, including carrier and firmware. On these systems the documentation is frequently thinner than anywhere else and the consequence of an outage higher.
Physical access is the remaining attack surface
When the network path is removed, physical access is what remains β and it defeats everything.
Someone at the equipment can attach to a console port, use removable media, reset management credentials via a jumper or remove drives entirely.
That makes the physical layers the ones doing the work: a locked room with a per-person access record, locked racks where others legitimately enter, and control over what removable media enters. Our physical security guide covers the layers.
Also apply the usual discipline to any management interfaces on the isolated side β default credentials changed, and reachable only from within the isolated environment.
Decommissioning is stricter
Equipment leaving an isolated environment frequently held the data that justified the isolation.
Sanitise before it leaves your control, with a record identifying the device by serial, the method and who performed it. Note that overwriting is not reliable on flash, and that a drive which has failed cannot accept a sanitise command at all β where that matters, physical destruction or a keep-your-drive arrangement is the answer.
Our sanitisation guide covers method selection and our decommissioning guide covers the sequence.
Common questions
What is the difference between segmented and isolated?
Segmented means separate VLANs with controlled routing, so traffic can cross where policy allows. Isolated means separate physical infrastructure with no routed path. Air-gapped means no network connection at all, in either direction.
Does an air gap need separate hardware?
Yes β separate switches and cabling rather than logical division. And a laptop that connects to both sides is not an air gap, which is the most common way the claim stops being true in practice.
How do isolated systems get updates?
By removable media under a controlled procedure, or not at all. Systems on isolated networks stay on older versions longer β frequently that is why they were isolated, being equipment that cannot be patched or validated systems where change requires revalidation.
Why do spares matter more here?
Isolated networks accumulate old, specific equipment that is hard to replace quickly β process controllers and instruments running software from suppliers that may no longer exist. A complete spare system is frequently better than components on very old equipment.
What is the remaining attack surface?
Physical access, which defeats everything β console ports, removable media, credential resets via jumper, and drive removal. The physical layers become the controls doing the work.
Tell us what needs isolating and we will help specify the separate infrastructure and the spares to hold for it.
