Security & Threats
Why Air-Gapped Isn't Automatically Secure
· 10 minute read
Air-gap is a real control when it is real. It is not a personality. Insiders, USB, jump hosts and fat grants walk across gaps every year.
The minutes said the estate was air-gapped, therefore secure, therefore ready for a write-capable agent. The rack was in a cage. The cage had a contractor with a pocket. The pocket had a personal drive. The drive had a model file from a messaging group. The gap was a feeling.
Air-gap is a network architecture: no general path to an untrusted network. That is worth buying when the data class demands it. It is not a synonym for secure. It never was, in OT or in classified shops, and it is not now because a language model sits on the rack.
This is an opinion for CIOs who are being sold a gap as a personality. Dated 17 August 2026. Prcept AI builds air-gapped agents. We still write this, because a dishonest gap is worse than a documented connected estate. A documented connected estate at least knows it is connected.
CISA and every serious OT guide will tell you that gaps fail through people, media, and the one jump host that everyone promised was temporary. Indian CERT-In duties still apply to the ICT you run inside the room. DPDP still applies to the personal data in the room. The room is not a statute-free zone.
What a gap is and is not
A gap is the absence of a general routed path. It is not the absence of risk. It is not an accreditation. It is not a reason to skip least privilege, logging, or a threat model.
A VLAN with a proxy is not a gap. A 'private link' to a model API is not a gap. A Mumbai region is not a gap. If packets can leave when a feature flag flips, you have a product, not a gap. Say the true sentence: isolated, or firewalled, or dedicated host. Words matter on the file.
A true gap still has supply chain. Weights, containers, and firmware enter somehow. That entry is now your highest-bandwidth attack path. Treat it as one.
The three walkers
Insiders. Privileged contractors, unhappy officers, helpful officers who want the demo to succeed. They already have a badge. The gap does not see them. The insider article in this cluster is the long form.
Media. USB, approved transfer appliances that became shared, laptops that sync when they go home, phones that photograph screens. Every update path is a media path. If you cannot name the scanned stick and the dirty-out procedure, you have a corridor, not a gap.
Misconfiguration. The jump host that still has internet 'for patches'. The NTP that goes outside. The licence dongle that phones home. The monitoring box that was never in the diagram. Gaps die in the exception that nobody redrew.
| Claim | Test | If it fails, say instead |
|---|---|---|
| Fully air-gapped | No outbound path from any node, including licence, NTP, telemetry, jump | Isolated with listed exceptions |
| Therefore secure | Insider, media and grant tabletop | Gapped and still in scope for 27001 / CERT-In / DPDP |
| Updates are safe | Checksum, provenance, scanned media, two-person rule | Updates are the crown path |
| No CERT-In duty | Read the 2022 directions | Logs and incidents still exist in the room |
Agents make gaps sharper, not safer
An agent concentrates privilege. A fat grant on a gapped rack is an insider amplifier with no SaaS kill-switch from a vendor SOC — which is good for sovereignty and bad if you had outsourced attention. You must supply the attention.
Retrieval corpora inside a gap still poison. Prompt injection still works. Denial of wallet becomes denial of rack: a loop that cooks GPUs until someone walks to the cage. Caps still matter.
Telemetry is the sovereignty loophole on connected estates. On gapped estates the loophole is the update channel and the engineer laptop. Different door, same weather.
- Write the true network sentence.
- Threat-model the update path as a primary path.
- Keep least privilege. The gap is not a grant.
- Keep 180-day logs in the room, in India — which the room already is, if the gap is real.
- Practise media hygiene as if it were the firewall, because it is.
When to buy the gap anyway
Buy it when the data class or the policy forbids general egress, and you can staff the room. A gap you cannot operate will grow a secret jump host. That secret is worse than a documented firewall.
Buy it when you are tired of third-party model APIs and telemetry arguments. Then still do the grant table and the media procedure. Prcept will help you run that room. We will not tell you the room is magic.
Do not buy it as a personality for a public FAQ that could have lived on a certified page. That is a cost argument, and it is also a security argument: you will have created a high-value cage for a low-value unit.
Objections you will hear — and what to do with them
These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.
If it cannot route, it cannot be hacked.
It can be walked, copied, mis-granted and mis-updated. Routing is one path. It is not the only path that has ever mattered.
Classified networks have always been gapped.
And classified networks still have insider programmes, media control and configuration control. Copy their seriousness, not their adjective.
Our vendor certified the air-gap.
A vendor cannot certify your contractor's pocket. Ask for the media procedure and the jump-host diagram. Then test both.
This opinion undermines sovereign on-prem.
It protects it. A gap that is honest will survive audit. A gap that is a sedative will become a case study. We would rather sell fewer sedatives.
A two-week honesty pass
If the estate is connected, say so. If it is gapped, prove the three walkers are controlled.
- Day 1–3: packet-level proof of outbound paths, including licence, NTP, telemetry, jump, out-of-band.
- Day 4–5: rewrite the file sentence to match the proof.
- Day 6–8: media procedure, scanner, two-person rule, checksum book.
- Day 9–10: insider and misconfig tabletop. Time detection.
- Day 11–12: grant table and GPU-loop cap inside the room.
- Day 13–14: CISO signs 'gapped' or 'isolated with exceptions'. No third word.
How this shows up in the file
Subject: Network posture — agent estate [name] — honesty note.
Posture: air-gapped / isolated with listed exceptions / connected. Exceptions: [list]. Update path: [media procedure]. Jump hosts: [none / named, dated]. Insider owner: [post]. Grant table: attached. We do not treat the posture word as a security accreditation. CERT-In logging and incident duties remain. Not legal advice.
If this note and the rack disagree, the rack wins and the note is rewritten the same day.
What we will not sell as a gap
A private link to a hosted model is not a gap. A 'sovereign region' with telemetry is not a gap. A VLAN that still has a browser jump host is not a gap. Prcept will name those architectures honestly. If you need a true gap, we will talk about media, two-person updates and a grant table inside the room — not about a personality on a slide.
If you cannot staff the room, do not buy the gap. An unstaffed cage grows a secret path. A documented firewall with a named egress list is safer than a romantic air-gap that nobody can operate on a Sunday.
CERT-In's six-hour clock and 180-day logs still apply inside the room. DPDP still applies to the personal data on the disk. The adjective air-gapped does not appear in those instruments as a waiver. Write the duties. Then write the network sentence.
This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, GFR, GeM term, CVC instruction, CERT-In direction, DPDP text, departmental manual and your counsel before you file it.
How to fail this before citizens do
“Why Air-Gapped Isn't Automatically Secure” is a path problem. A P1 CIO/CTO should be able to name the tool, the identity, the secret and the egress that would make “air gap security myths” real. If the only control is a network diagram from last year, you have a story, not a threat model.
Air-gap is a real control when it is real. It is not a personality. Insiders, USB, jump hosts and fat grants walk across gaps every year. Air-gap is not automatically secure. Prompt injection is not a conference joke when the agent can write a ticket. CERT-In still wants specified logs in India and incidents on a six-hour clock. Write those clocks into the runbook.
- Red-team the write tools, not only the chat UI.
- Kill undeclared outbound paths on staging.
- Redact personal data from logs you will actually keep.
- Scope a pentest that includes RAG and connectors.
- Cap metered spend so a loop cannot empty a budget.
Close this loop before the next CAB
Put “Why Air-Gapped Isn't Automatically Secure” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “air gap security myths” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- Is Prcept walking back air-gap?
- No. We still build it. We are walking back the idea that the word is a control. The room, the media path and the grants are the control.
- Does a gap remove CERT-In duties?
- No. You still run ICT systems. Listed incidents and 180-day logs still exist. The room being in India helps the jurisdiction point; it does not delete the directions.
- Is a unidirectional gateway a gap?
- It is a specific control. Call it that. Do not call it a personality. Threat-model the allowed direction.
- Can we skip red team because we are gapped?
- No. Red-team the update path, the grants and the insider. Skip the internet-only fantasy tests if they do not apply. Do not skip hostility.
- What is the most common lie in RFPs?
- Air-gapped as a synonym for 'private cloud with a hope'. Demand a diagram and a media procedure, or strike the word.
- Should a public FAQ live in a gap?
- Usually no. That is a cost and a security mismatch. Keep the gap for the class that earned it.
Sources
- CISA — Air-gapped networks and related cyber guidance
- CERT-In Directions under Section 70B, 28 April 2022 (PDF)
- ISO/IEC 27001 — Information security management
- Digital Personal Data Protection Act, 2023 (India Code)
- Prcept AI — on-prem / air-gapped agents
- India AI Governance Guidelines (PIB document, November 2025)