CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

The air gap is a myth and other OT security truths

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2878

As cited

Copy frozen at (site build).

ot ics

The air gap is a myth and other OT security truths

Benjamin Bachmann, Bilfinger's Director of Group Information Security, discusses operational technology (OT) security misconceptions in an interview with Help Net Security. He addresses the limitations of air gap protection, the importance of visibility into legacy equipment through network monitoring, and how ransomware operators price demands based on operational downtime. The discussion covers incident containment negotiation and threat actor motivations in industrial environments.

Why it matters: OT defenders and industrial plant operators need to understand that air gaps are unreliable as a primary control and must implement monitoring, visibility, and incident response planning to detect and contain ransomware targeting production environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ot ics

The air gap is a myth and other OT security truths

Benjamin Bachmann, Director Group Information Security at Bilfinger, discusses operational technology (OT) security misconceptions including the assumption that air gaps provide adequate protection. The interview covers threat motivations in industrial environments, negotiating containment plans ahead of incidents, and using network monitoring to gain visibility on legacy equipment. Ransomware pricing in OT contexts typically reflects operational downtime rather than data value.

Why it matters: Industrial and manufacturing security teams must abandon false assumptions about air gap isolation and prepare incident response and containment strategies before attacks occur, since attackers target operational disruption over data theft.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary