Blog da Zscaler

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

News & Announcements

From Air Gaps to Always Connected: The Uptime Challenge Security Must Solve

image
ALEX FRAY
August 05, 2026 - 4 Min. de leitura

The idea that a factory is secure because it's disconnected is, frankly, a 2005 mindset. Connectivity is now core to how manufacturing operates. It’s not bolted on, not optional, uptime depends on it. The air gap isn't a security strategy anymore, it's just a constraint waiting to be worked around.

But if the factory floor has evolved from isolated to ‘always connected’, what does that mean for security?

The problem isn't connectivity itself. Most factories need more of it, not less. The challenge is that many of the control models used to govern those environments were designed for a world that was easier to see, easier to predict, and easier to lock down. That world is gone.

Why Workarounds Become the Default

The gap between connectivity and control creates real operational friction, and traditional security models, built for a more isolated era, are often the bottleneck. What we’re seeing is engineers waiting on manual approvals for urgent remote access. Third-party vendors needing to troubleshoot equipment with no secure mechanism to do so. Security teams making decisions without a complete picture of who's connecting, from where, and to what. 

When that's the reality, security teams default to restriction. Understandable, but when those decisions directly affect uptime, the factory floor finds its own solutions.

I visited one of the world's biggest consumer-goods manufacturers and sat in on a conversation between their CISO and head of factory about exactly this problem. Their fix for a downed production line? Pull a SIM from a phone, stick it in a hotspot, connect it to the production controller, and let the remote specialist do their thing. It works. It also drives the CISO quietly mad. Nobody was trying to bypass security; they were just trying to keep the line moving. But the result is an unmanaged path straight into their production environment. That trade-off is precisely why this has become a leadership problem, not just a security one.

image 1

 

 

 

 

 

 

 

 

 

 

 

 

Why Control Is Getting Harder

More connectivity means more devices, more access paths, more remote users, more third-party maintenance windows, and more machine-to-machine interactions. That's not inherently a problem, it's often what keeps operations running. The harder question is whether anyone can still see the web of connections, govern them, and understand the dependencies that come with them.

This is where traditional approaches break down. Production teams optimise for uptime. Warehouse teams optimise for throughput. Factory teams optimise for output. And legacy security models? Well, they weren't designed to keep pace with these pressures, and the friction shows up in unexpected places.

 

image 2

Take handheld scanners used for warehouse logistics. Credentials required, security box ticked. That’s great, except half the floor is wearing gloves or has oil on their hands from the machinery. Logging in is a hassle; logging out so a colleague can use the same device feels like unnecessary admin when a line is waiting. The result: one device, one login, twelve people on shift. Identity becomes meaningless. Visibility evaporates. That's not a technology failure. That's a governance model that never accounted for the reality of the shop floor.

Questions Every Leadership Team Should Be Asking

Security must be frictionless to be effective. If it's complicated, people will route around it, not out of recklessness, but out of operational necessity. And that’s when every workaround becomes a visibility gap. And, if governance and control models are still rooted in the air-gap era, more tooling won't solve this problem. 

The better starting point is an honest assessment of where the gaps actually are. Where are operations genuinely dependent on connectivity, and where have workarounds quietly filled the gaps? Where are third parties accessing operational systems, and through what mechanisms? And, critically, which security controls are improving visibility, and which are simply creating the friction that drives people around them?

The answers tend to reveal whether security is built around how work actually happens, or how leadership assumes it happens. Those are often very different things.

The issue was never that these environments were air gapped. It's that the security models built for that era were never redesigned when the era ended. The organisations best placed for what comes next aren't necessarily the ones with the most tools. They're the ones who understood where connectivity became essential and where visibility was lost. They’re the ones who chose to close that gap before it became a business failure.

 

The threats to connected factories aren't theoretical. IoT attacks on critical industries jumped 40% last year, and most environments still lack the visibility to see them coming. 

Get the full picture: Download the ThreatLabz 2025 Mobile, IoT & OT Threat Report →

 

 

 

 

form submtited
Obrigado por ler

Esta postagem foi útil??

Aviso legal: este post no blog foi criado pela Zscaler apenas para fins informativos e é fornecido "no estado em que se encontra", sem quaisquer garantias de exatidão, integridade ou confiabilidade. A Zscaler não se responsabiliza por quaisquer erros, omissões ou por quaisquer ações tomadas com base nas informações fornecidas. Quaisquer sites ou recursos de terceiros vinculados neste post são fornecidos apenas para sua conveniência, e a Zscaler não se responsabiliza por seu conteúdo ou práticas. Todo o conteúdo está sujeito a alterações sem aviso prévio. Ao acessar este blog, você concorda com estes termos e reconhece que é de sua exclusiva responsabilidade verificar e utilizar as informações conforme apropriado para suas necessidades.

Receba as últimas atualizações do blog da Zscaler na sua caixa de entrada

Ao enviar o formulário, você concorda com nossa política de privacidade.