Back to all articles

Vulnerability management for air-gapped networks

Vulnerability management for air-gapped networks needs offline scanning, manual CVE feeds, and OT-aware prioritization, not live tools. The full 2026 playbook.

BRContent TeamSep 10, 2026 — 8 min read
Vulnerability management for air-gapped networks

Vulnerability management for air-gapped networks is the process of finding, prioritizing, and fixing software flaws on systems that have no live connection to the internet or the corporate network, without depending on cloud threat feeds or continuous scanner updates. Isolated OT floors, defense enclaves, and classified government segments need a different playbook because the internet-dependent parts of a standard vulnerability program simply don't reach them.

TL;DR
  • Vulnerability management for air-gapped networks requires offline scanners, manual CVE feed transfers, and physical chain-of-custody logging.
  • Isolation is not protection — Stuxnet crossed an air gap via USB drive in 2010 and remains the reference case for physical media risk.
  • CVSS scores above 7.0 (High) and 9.0 (Critical) still apply offline; the scoring scale doesn't require live internet access.
  • Brinqa ingests scan data from disconnected environments and correlates it against imported CVE and EPSS feeds without needing a live connection.
  • Quarterly maintenance windows, not continuous patch cadence, are the realistic remediation rhythm for most OT and classified segments in 2026.

Why vulnerability management matters for air-gapped networks

Air-gapped segments run some of the highest-consequence systems in any environment: industrial controllers, SCADA historians, classified networks, and defense enclaves. Teams running them often assume isolation equals safety, and that assumption is the single biggest gap security auditors find.

Attackers don't need a network path if they can get a USB drive, a contractor laptop, or a firmware update past the wall. Stuxnet proved this in 2010 by crossing an air gap through removable media, and the pattern hasn't changed — physical transfer is still the primary infection vector for isolated networks. Standards like IEC 62443 exist precisely because zone and conduit segmentation, not internet isolation alone, is what actually reduces exposure in OT and ICS environments.

The practical challenge is data freshness. A scanner that can't phone home can't pull new CVE definitions, EPSS scores, or exploit intelligence automatically. Every feed update becomes a manual, auditable transfer — and every gap in that transfer is a window where a known-exploited vulnerability sits undetected.

Map every asset before you scan anything

You can't run vulnerability management for air-gapped networks against an asset list you don't trust, and automated network discovery doesn't work when there's no network to sweep.

  • Build a physical inventory register by walking the floor with OT or systems engineers, not by relying on old CMDB exports.
  • Map assets to IEC 62443 zones and conduits so criticality is visible at a glance.
  • Tag every device by function (PLC, historian, jump host, HMI) and by patchability — some legacy controllers can't be patched at all.
  • Cross-check the physical inventory against change management tickets to catch shadow additions.
  • Re-walk the inventory on a fixed schedule; quarterly is typical for OT floors, since air-gapped environments change slower but still change.

Choose a scanner built for offline operation

Once the asset list is trustworthy, pick a scanning method that doesn't assume internet access. This is where most teams either build brittle manual workarounds or bring in a platform designed for the constraint.

  • Use agent-based or credentialed local scans instead of active network scans that can crash fragile OT devices.
  • Move scan definition updates in via a one-way data diode or write-once media, never a two-way connection.
  • Run scans against a schedule tied to your maintenance windows, not a continuous cadence.
  • Validate scanner output against a small pilot segment before trusting it fleet-wide.
  • Where the environment allows it, a platform like Brinqa ingests scan results from disconnected segments and correlates them centrally once the data is transferred out, cutting the manual reconciliation work down sharply.

Build a manual pipeline for vulnerability intelligence

Without live NVD or EPSS access, someone has to own the feed transfer process end to end.

  • Mirror CVE and EPSS feeds on a dedicated low-side workstation with no path back into the air-gapped segment.
  • Transfer updates via approved media — write-once discs or verified USB with checksum validation — never ad hoc file copies.
  • Set a fixed update cadence; weekly or biweekly is common for OT programs, so stale data doesn't silently accumulate.
  • Log every transfer with timestamp, operator, and checksum for chain-of-custody evidence.
  • Verify import integrity against the checksum before the data enters any prioritization workflow.

Prioritize with the data you actually have

An air-gapped segment usually has incomplete telemetry, so prioritization has to lean harder on what's confirmed rather than what's assumed.

  • Weight CVSS severity (7.0+ High, 9.0+ Critical) alongside confirmed exploit availability, not theoretical exploitability alone.
  • Treat any DMZ jump host connecting to the air-gapped segment as the highest-priority asset in the program, since it's the actual bridge point.
  • Factor in physical exposure — a controller in a locked cabinet is a different risk than one on an open factory floor.
  • Defer OT firmware CVEs that have no vendor-validated patch, and document the reason rather than leaving them unranked.
  • For classified work, defense contractors layer contract-specific control mappings on top of CVSS, which changes what counts as critical for that segment.

Patch on a scheduled maintenance window, not a live cadence

Most air-gapped OT and classified segments patch quarterly in 2026, tied to planned outages rather than a rolling SLA.

  • Batch remediation work into the next scheduled maintenance window instead of chasing per-CVE deadlines.
  • Test every patch on an offline replica or lab environment before touching production controllers.
  • Coordinate PLC and firmware patches directly with the OT vendor — unsupported changes can void warranties or break safety interlocks.
  • Define a rollback plan before applying anything, since re-establishing a known-good state offline takes longer without live backups.
  • Get sign-off from the plant or operations manager, not just the security team, before the window closes.

Document everything for the next audit

Auditors reviewing an air-gapped program care as much about the transfer process as the remediation itself.

  • Keep chain-of-custody logs for every physical media transfer in and out of the segment.
  • Maintain a formal exception register for unpatchable legacy assets, with a documented compensating control for each.
  • Map remediation evidence to the framework the segment is actually assessed against — IEC 62443, NIST 800-82, or a program-specific control set.
  • Track remediation timelines against your defined SLA, even when that SLA is 90 days rather than 30.
  • Roll findings up into a report the security lead or CISO can hand to auditors without reformatting it first.

See how Brinqa handles offline data

Check how exposure management works across disconnected and hybrid environments.

Comparing options for air-gapped vulnerability management

OptionBest forKey limitation
Manual spreadsheet trackingSmall OT footprints with a handful of assetsDoesn't scale past a few dozen devices; no chain-of-custody automation
Standalone offline scannerTeams needing local scan data without central correlationNo cross-segment risk view; still needs manual feed updates
Passive OT monitoring applianceSegments where active scanning risks disrupting controllersDetects traffic anomalies, not always CVE-level detail on firmware
Centralized exposure platform (Brinqa)Programs managing air-gapped segments alongside connected IT and cloudRequires a defined data-transfer process to bridge the gap into the platform

Verdict: Brinqa is the right fit for security teams that run air-gapped segments alongside connected IT and cloud assets and need one prioritized risk view across all of them.

Common mistakes air-gapped teams make

  • Treating isolation as protection. Stuxnet is the textbook counterexample — physical media is still the primary infection path into 2026.
  • Letting CVE feeds go stale for months. A quarterly transfer cadence beats no cadence, but teams that skip a cycle lose visibility into newly weaponized flaws.
  • Applying IT patch SLAs to OT controllers. A 30-day remediation window that works for a laptop fleet can force unsafe changes on a live production line.
  • Skipping the exception register. Unpatched legacy assets without a documented compensating control are the first thing an auditor flags.
  • Ignoring the DMZ bridge point. The jump host connecting the air-gapped segment to the rest of the network is often the least-monitored asset in the whole program.

FAQ

What is vulnerability management for air-gapped networks?

It's the process of finding, prioritizing, and remediating software flaws on systems disconnected from the internet or corporate network. It relies on manually transferred CVE data and offline-capable scanners instead of live feeds.

Can you run a vulnerability scanner on an air-gapped network?

Yes. Agent-based or credentialed local scanners work without internet access, but their signature and CVE definition files need periodic manual transfer via approved media.

How often should air-gapped systems be patched?

Most OT and classified segments patch on a quarterly maintenance window tied to planned outages rather than a rolling 30-day SLA. Testing and vendor coordination take longer offline.

Is an air-gapped network immune to malware?

No. Stuxnet crossed an air gap via USB drive in 2010, and removable media and contractor laptops remain primary infection vectors for isolated networks in 2026.

What framework applies to air-gapped OT vulnerability management?

IEC 62443 is the standard most OT and industrial control programs align to. It defines security zones and conduits that guide segmentation and prioritization decisions.

How does CVSS scoring work without internet access?

CVSS scores are static once assigned, so a 7.0+ High or 9.0+ Critical rating still applies offline. The challenge is importing the score data through your manual feed pipeline.

Does Brinqa support disconnected environments?

Brinqa ingests scan and asset data transferred out of disconnected segments and correlates it centrally alongside connected IT and cloud assets for a unified risk view.

What's the biggest audit gap in air-gapped vulnerability programs?

Missing chain-of-custody documentation for physical media transfers is the most common finding. Auditors need proof of what data moved, when, and who verified it.

One last thing

The Stuxnet incident from 2010 is still the reference point security teams cite when defending an air-gap budget, and it's worth repeating: the malware didn't breach a firewall, it rode in on a USB drive. Every control in a vulnerability management for air-gapped networks program that ignores physical media transfer is protecting against the wrong threat model. Spend the next 2026 audit cycle checking your USB and contractor-laptop policy before you spend it re-tuning CVSS thresholds.

You might also like