Air gap: secure your sensitive or disconnected environments with Cyberwatch

As cyber threats become more sophisticated and remote attacks multiply, some organizations are making a choice that may seem radical, but is gaining traction: completely isolating their critical systems from the rest of the digital world.

This strategy is based on a simple principle: eliminate all external network communication to reduce the attack surface. This is known as a physically isolated, or "air-gapped," environment.

What exactly is it? Why is this approach gradually becoming the standard in certain sectors? And what concrete solutions are available in Cyberwatch to analyze sensitive or isolated machines and perform vulnerability assessments despite the lack of network connectivity?

We cover everything in this article.

Understanding the air gap: definition, benefits, and use cases

What is an air-gapped environment?

An air-gapped environment refers to an information system that is intentionally isolated from any other uncontrolled network, particularly the Internet.

In its strictest definition, an isolated system has:

  • No Internet connection,
  • No routing to an external network,
  • No VPN tunnel,
  • No persistent interconnection with a third-party system.

The isolation is generally physical, rather than merely logical.

What does this mean? Simply that the machines in question are not connected via cable, Wi-Fi, fiber, or any other network technology to external environments.

It is important to note that:

  • A private network isolated by a firewall is not necessarily air-gapped,
  • A partitioned VLAN is not necessarily air-gapped,
  • A system without Internet access but connected to other networks is also not necessarily air-gapped.

The main takeaway is that a true air gap implies the absence of active network communication to the outside world.

Why implement an air gap?

An air gap drastically reduces the remote attack surface. It does this not by fixing vulnerabilities one by one, but by eliminating exposure altogether.

To understand why, you have to look at how attackers actually operate.

The most common attacks exploit what is accessible from the outside:

  • Exposed services,
  • Application vulnerabilities,
  • Configuration errors,
  • Authentication flaws,
  • Compromised remote access.

According to the Kaspersky incident analysis report published in 2025, public-facing applications were the primary initial attack vector (39.2% of cases), and compromised accounts served as the entry point in 31.4% of incidents. Both of these vectors have one thing in common: they rely on something being accessible from the outside.

That is exactly what an air gap eliminates. By cutting off all external network connectivity, you remove the surface area that these techniques rely on.

That said, physical isolation is not an absolute protection.

Removable media, uncontrolled physical access, or supply chain compromises remain valid vectors, which is precisely why vulnerability management remains essential, even in an air-gapped environment.

In what contexts is an air gap typically used?

Physical isolation cannot be improvised: it is a response to specific regulatory or security requirements.

It is primarily found in environments where a compromise would have critical consequences:

  • Industrial systems (ICS/SCADA),
  • Critical infrastructure (energy, transport, healthcare),
  • Classified or military systems,
  • Cryptographic signature environments,
  • Certain sensitive production environments.

For some organizations, this requirement is also regulatory. Operators of Vital Importance (OIV) and Operators of Essential Services (OSE) are subject to strict compartmentalization obligations: any communication with an external network is either prohibited or subject to strict control.

In all these contexts, the acceptable risk is near zero, making an air gap the obvious architectural solution.

The operational challenges of air gapping

In exchange for a near-zero attack surface, air gapping creates significant operational constraints. Isolated systems cannot receive automatic updates, be monitored by connected security tools, or transmit logs to a centralized SIEM.

This poses a structural challenge for vulnerability management: how can you analyze machines that cannot communicate directly with a security platform? How do you maintain a current patch level without network flow? How do you detect risk without telemetry?

It is precisely to address these constraints that Cyberwatch has developed an operating mode tailored to isolated environments. Here is how it works.

How to scan and report vulnerabilities via Cyberwatch in isolated environments?

The principles of air-gapped scanning with Cyberwatch

Unlike a standard scan, which takes place via a direct connection between Cyberwatch and the target machine, the air-gap scan relies on an offline model:

→ Analysis scripts that can be executed locally on the isolated machine are provided by Cyberwatch; they are the same as those used for Agent and Agentless scans.

→ These scripts collect the technical information required to identify the software components present (OS, packages, versions, configurations).

→ The generated results can be exported as structured text files using declarative data.

→ These files can then be imported manually into the connected Cyberwatch instance, or via automated tools (API / CLI) that potentially allow for protocol breaking.

This process requires no communication flow between the isolated environment and Cyberwatch.

The collected data is exported and then transferred according to the procedures defined by the organization.

This method allows data from disconnected machines to be integrated into centralized vulnerability management while respecting infrastructure isolation constraints.

Let's now look at how to set this up, step by step.

Implementing air-gapped scanning with Cyberwatch: the step-by-step process

Downloading and copying the scan scripts

The first step for an air-gapped scan is to download the provided scripts. You have two options:

  • From the Cyberwatch interface, under the Asset management > Air-gapped assets > Addsection, a ZIP package containing the scan scripts can be retrieved.
  • From the Cyberwatch API available on GitHub, which can be installed via Python using the following command: cyberwatch-cli airgap download-scripts.

If you choose the second option, you will need to have generated an API key from your user profile in the interface and have a connection between a machine and the Cyberwatch solution.

Regardless of the method used, you must then transfer the downloaded scripts to the offline equipment (via the ZIP file or folder).

Executing scripts on the isolated machine

The scripts are organized by supported system families. On the isolated machine, you must execute the script corresponding to the operating system:

  • Windows example: execute via PowerShell (.\run.ps1).
  • Linux example: execute via the provided Bash script (.\run.sh).

The script will produce a text output that can be sent to a file (> output.txt), which will contain system information structured as declarative data (operating system, list of components, versions, etc.).

This file will serve as the basis for vulnerability analysis in Cyberwatch.

Transferring results and importing into Cyberwatch

Once the script has been executed, the output file must be transferred out of the isolated environment according to the methods authorized by your security policy, and then imported into Cyberwatch.

Again, there are two options:

  • Via the interface: Asset management > Air-gapped assets > Add, then import the generated text file.
  • Via the API, using the command cyberwatch-cli airgap upload. This option allows you to automate scans and avoid installing an agent on critical assets.

Please note: when importing, if an asset with the same hostname already exists in the same project, Cyberwatch will update its information. Otherwise, a new asset is created. History is preserved in both cases.

Supported formats:

You can find a more detailed description of how to use air-gapped mode, as well as the various sources and methods available, in our dedicated documentation.

Mapping your isolated assets with declarative discovery

Once your machines have been scanned and imported, a question arises: do you have a complete view of your isolated infrastructure?

This is where declarative discovery comes in.

In Cyberwatch, discoveries allow you to map your assets according to different perimeters (network, infrastructure providers, etc.) and measure the proportion of assets that are actually being monitored.

For environments with multiple isolated machines, declarative discovery allows you to add a list of assets based on their hostnames, IP addresses, or domain names. The import is performed from a text file (.txt), CSV, or Excel file (.xlsx), with no network connection required.

Cyberwatch then links these to the assets already being monitored and displays the proportion of discovered-only machines compared to those already registered, giving you a precise view of your actual coverage, including any potential blind spots on your offline machines.

Learn more

Prioritizing vulnerabilities in an air-gapped environment

Identifying vulnerabilities on an isolated system is just the first step. You still need to know which ones to prioritize for remediation.

In a connected environment, teams often rely on standard criticality scores (CVSS, EPSS, etc.) to guide their remediation efforts. However, in an air-gapped context, this approach quickly reaches its limits.

A vulnerability classified as critical because it is remotely exploitable via the network does not necessarily carry the same level of risk on a machine completely disconnected from the internet and any external network. Conversely, certain vulnerabilities exploitable locally or via removable media can remain highly impactful despite the system's isolation.

This issue is all the more critical because update operations are often more complex in isolated environments: limited maintenance windows, production downtime, specific validation procedures, or regulatory constraints. Under these conditions, the goal is not to fix as many vulnerabilities as possible, but to precisely identify those that pose a real risk to the asset in question.

To address this challenge, Cyberwatch allows you to define a prioritization policy tailored to the context of the monitored equipment. The risk score is then recalculated using the BTE (Base, Threat, Environment) method, taking into account the specific characteristics of the asset, particularly its level of exposure.

In an air-gapped environment, critical vulnerabilities whose exploitation relies exclusively on network access can be downgraded, while flaws that are truly relevant in an isolated context automatically move up in priority.

The result: prioritization that more accurately reflects real risk, better allocation of maintenance resources, and remediation efforts focused where they provide the most value in terms of risk reduction.

Managing compliance in air-gapped environments with Cyberwatch

Vulnerability scanning is not the only analysis that can be performed on isolated equipment: Cyberwatch also allows you to conduct compliance audits, following the same offline principle.

The process takes place in three steps, using the Cyberwatch REST API and CLI:

1. Download compliance scripts from a device connected to the server: cyberwatch-cli airgap download-compliance-scripts

2. Transfer and execute the scripts locally on the isolated equipment.

3. Send the results to the Cyberwatch server: cyberwatch-cli airgap upload-compliance

Note: The corresponding asset must have been created in Cyberwatch beforehand, as explained in the previous section.

Prefer PowerShell? The full procedure is available in our dedicated documentation.

Declarative data syntax

Do you want to understand the detailed format of data collected during an air-gapped scan, or create an asset manually without using scripts? The documentation dedicated to declarative syntax is designed for this.

It provides a complete list of keys that can be used in an air-gapped environment and covers two use cases: understanding the structure of data exported from your assets, and manually creating an asset from the air-gap addition page.

In the latter case, rather than importing a file, you have an editable text area to declare asset properties directly using the declarative syntax. This is particularly useful for equipment not natively supported by scripts, such as certain industrial devices or Android and iOS mobile terminals.

Finally, you can consult the complete list of equipment supported by Cyberwatch, including those monitored via the air-gap method.

Conclusion

Air-gapped environments address very specific cybersecurity challenges, but they are far from rare: in defense, industry, energy, or healthcare, they are often the norm.

Cyberwatch has been supporting organizations operating in these environments for several years.

This field experience, gained working with stakeholders facing some of the highest security constraints, has led us to develop concrete and proven mechanisms to meet the specific challenges of air-gapped systems: offline analysis scripts, multi-format imports, and centralized vulnerability management without network traffic.

If you manage isolated environments and would like to learn more about how Cyberwatch can assist you, our team is available to discuss it.

FAQ

What is an air-gapped environment?

An air-gapped environment is an information system intentionally isolated from any external network, including the Internet. The isolation is physical: no cables, Wi-Fi, or other network connections link these machines to the outside world.

What is the difference between a firewall-isolated network and a true air gap?

A firewall filters traffic, but the network connection still exists. A true air gap eliminates this connection by design: there is simply nothing to intercept or compromise remotely.

Does an air gap protect against all cyberattacks?

No. It neutralizes the vast majority of remote attacks, but vectors such as removable media (USB drives), unauthorized physical access, or supply chain compromises remain real threats.

How do you scan for vulnerabilities on an air-gapped machine?

Cyberwatch provides analysis scripts that can be executed locally on the isolated machine. The results are exported to a file, transferred manually, and then imported into Cyberwatch, with no network flow required.

Is it possible to perform compliance scans in an air-gapped environment?

Yes. Cyberwatch offers downloadable compliance scripts to be executed locally on the isolated equipment and then re-imported into the platform via CLI or PowerShell.

Thanks for submitting the form.