Skip to content

Air-Gap Security Can Create Physical Risk

Air gaps reduce cyber exposure but can kill visibility. Learn why critical infrastructure needs telemetry, segmentation and monitoring.

Air gaps are supposed to make critical systems safer.

Cut off the network connection. Reduce the attack surface. Keep hackers away from the systems controlling water, electricity, medical devices and other infrastructure where a cyberattack can become a physical-world event.

But Sean Satterlee sees another side of that equation.

Satterlee, senior principal consultant at Device Recon Labs and a medical device penetration tester, joined CYBR.HAK.CAST hosts Michael Farnum and Phillip Wylie for a conversation that ranged across medical device security, operational technology and the increasingly blurry boundary between cybersecurity and physical safety.

Full episode and related article:

Medical Device Security: The Air Gap Myth
Sean Satterlee explains why medical device air gaps fail and how segmentation, SBOMs and telemetry can reduce healthcare cyber risk.
Medical Device Security Doesn’t End at FDA Approval
CYBR.HAK.CAST guest Sean Satterlee explains how medical device cybersecurity is shifting toward continuous vulnerability monitoring, SBOMs, penetration testing and post-market security.

His warning was simple: You can isolate a system so effectively that the people responsible for it lose the visibility they need to know when something has gone wrong. And sometimes what goes wrong has nothing to do with hackers.

When the air gap works — and the system still fails

Satterlee pointed to a recent incident involving a municipal water system in Moore, Oklahoma.

According to Satterlee, part of the community went under a boil-water advisory after a UV filtration system failed. The water-treatment environment had been air-gapped, he said, in part because the municipality had previously suffered a ransomware incident.

From a cybersecurity perspective, the reasoning is easy to understand. Get burned badly enough and “disconnect everything” starts sounding pretty good.

“They were burned hard, so they were like, air gap it, air gap everything, make us unhackable,” Satterlee said.

There was a problem: The isolation also limited telemetry. Operators didn't immediately know the filtration system had failed.

That dramatically changes the risk equation. Once contaminated water starts moving through a distribution system, the problem isn't simply repairing the failed equipment. Water already pushed downstream has to be dealt with, pipes may need to be flushed, and the time between failure and detection becomes critical.

The cyber control may have worked exactly as intended. Nobody needed to hack the system for something bad to happen.

The organization traded one form of risk for another.

Cybersecurity isn't the same thing as safety

That distinction becomes even more important when cybersecurity touches the physical world. For Satterlee, medical devices belong in that conversation.

Medical security practitioners don't necessarily describe themselves as operational technology security professionals. Satterlee said the field often identifies more specifically as biomedical or biotech security.

Technically, however, the similarities to OT are hard to ignore.

Medical technology can monitor patients, deliver treatment or otherwise connect a networked system to something happening in the physical world. And unlike conventional IT environments, changing the underlying technology isn't always as simple as installing the latest update.

“You don't get to patch every Tuesday,” Satterlee said.

A medical device may have been tested and cleared using a particular software configuration. Change that environment and additional testing may be necessary. As a result, devices have to be handled much more carefully than the typical Windows endpoint.

“Every host is handled with kid gloves,” Satterlee said.

Farnum recalled encountering that problem firsthand in a hospital women's center, where an OS/2 server was running monitoring systems for mothers and babies. The technology was old. Replacing or modifying it wasn't trivial. And failure wasn't an ordinary IT outage.

“You're literally talking life and death,” Farnum said.

Hack the EHR, or turn off the water?

Satterlee takes the distinction even further when thinking like an attacker.

A hospital's electronic health record system is an obvious target. Take it down and the disruption can be enormous. But hospitals have spent years preparing for EHR downtime. In an emergency, clinicians can fall back to paper.

Physical infrastructure is another matter.

“If I stop the fresh water flowing, you're in the 1700s,” Satterlee said.

Compromise electrical controls and an attacker could interfere with power. Compromise HVAC and an attacker could potentially push operating rooms outside acceptable environmental conditions.

“Now you're doing field surgery,” he said. “You're at Civil War status.”

That's the cybersecurity problem that gets obscured when defenders think only in terms of data confidentiality, malware infections and compromised endpoints.

The most consequential system in a hospital may not be the one containing the most sensitive data.

It may be the system keeping the water flowing, electricity running or operating room at the correct temperature.

The systems that scare us are the systems we need to see

That creates an uncomfortable contradiction. The systems with the greatest potential physical consequences are precisely the systems organizations may be most tempted to isolate.

“The OT things that terrify us are also the most critical,” Satterlee said.

The choice, however, isn't necessarily between connecting everything and air-gapping everything.

Satterlee argued for a risk-based architecture that provides necessary telemetry while controlling connectivity through segmentation, monitoring and carefully managed ingress and egress.

“Do we leave it air-gapped and run that risk?” he asked. “Or do we modernize and get telemetry but do it correctly with zones and monitoring and ingress and egress rules?”

The problem is that doing it correctly requires expertise, architecture, time and money — resources that aren't equally available to every hospital, municipality or critical-infrastructure operator.

That helps explain why “just air gap it” remains attractive. It's conceptually simple. Real segmentation isn't.

When 135 degrees isn't a cyberattack

Satterlee offered another example of why visibility matters, this time from a gaming facility.

The facility had equipment monitoring environmental conditions in a data center. But the monitoring device went offline, and there was no direct OT monitoring of the HVAC system.

Then the chiller failed. Nobody knew.

By the time Satterlee arrived as a responder, he said the ambient temperature in the affected room had reached 135 degrees Fahrenheit.

“The raised floor was so hot it melted the soles of my sneakers,” he said.

Nothing had to burst into flames for the consequences to be serious. Every server exposed to those temperatures now had to be treated as potentially unreliable.

“You guys know all every one of those servers can never be trusted,” Satterlee said.

Again, there was no sophisticated attacker in the story. No zero-day. No ransomware crew. The failure was physical. The cybersecurity lesson was visibility.

The real-world consequences of our keystrokes

Cybersecurity has spent decades expanding its definition of what needs protecting.

First came computers. Then networks. Then cloud infrastructure, mobile devices, IoT and operational technology.

But connecting technology to physical systems changes the consequences of both attacks and defensive decisions.

Satterlee described IoT as a gateway between those worlds.

“Those of us who read Gibson and other authors like that, we dreamt of days that we could actually affect real-world change by our keystrokes,” he said.

Now we can. That's precisely why the air-gap debate needs more nuance. Connecting a critical system can expose it to attackers. Disconnecting it can reduce visibility into what that system is actually doing. Neither decision eliminates risk.

The challenge is building architectures that let defenders see enough to know when something is failing without unnecessarily exposing the systems they're trying to protect.

Because in critical infrastructure, a system doesn't have to be hacked to become dangerous.

Sometimes the security control works. And something still goes terribly wrong.

HOU.SEC.CON CTA

Latest