Air-Gapped Network
An air-gapped network has no outbound connectivity to the internet or to corporate systems. Air-gapping is common in rail signaling and reduces exposure, but it does not eliminate risk: maintenance laptops, removable media and vendor access remain entry points, and monitoring must work without cloud connectivity.
How it works
An air-gapped system is physically or logically isolated so that no network path exists between it and external networks. Updates, logs and data are moved by controlled means such as removable media, one-way data diodes or supervised maintenance connections. In rail, many signaling and interlocking networks are operated this way.
Security tooling for air-gapped environments must be deployed fully on-premises, receive threat intelligence and software updates offline, and never depend on a cloud service to function.
Why it matters for security
Air gaps are frequently assumed rather than verified: undocumented connections, maintenance access and infected media have compromised nominally isolated systems. Continuous monitoring inside the air-gapped network is the only way to confirm the isolation holds and to detect threats that enter by other paths.
Related solution
Building a rail security operations center
Fully on-premises monitoring that confirms isolation holds and catches what enters by other paths.
See the solution →

