Blog Zscaler
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
From Air Gaps to Always Connected: The Uptime Challenge Security Must Solve
The idea that a factory is secure because it's disconnected is, frankly, a 2005 mindset. Connectivity is now core to how manufacturing operates. It’s not bolted on, not optional, uptime depends on it. The air gap isn't a security strategy anymore, it's just a constraint waiting to be worked around.
But if the factory floor has evolved from isolated to ‘always connected’, what does that mean for security?
The problem isn't connectivity itself. Most factories need more of it, not less. The challenge is that many of the control models used to govern those environments were designed for a world that was easier to see, easier to predict, and easier to lock down. That world is gone.
Why Workarounds Become the Default
The gap between connectivity and control creates real operational friction, and traditional security models, built for a more isolated era, are often the bottleneck. What we’re seeing is engineers waiting on manual approvals for urgent remote access. Third-party vendors needing to troubleshoot equipment with no secure mechanism to do so. Security teams making decisions without a complete picture of who's connecting, from where, and to what.
When that's the reality, security teams default to restriction. Understandable, but when those decisions directly affect uptime, the factory floor finds its own solutions.
I visited one of the world's biggest consumer-goods manufacturers and sat in on a conversation between their CISO and head of factory about exactly this problem. Their fix for a downed production line? Pull a SIM from a phone, stick it in a hotspot, connect it to the production controller, and let the remote specialist do their thing. It works. It also drives the CISO quietly mad. Nobody was trying to bypass security; they were just trying to keep the line moving. But the result is an unmanaged path straight into their production environment. That trade-off is precisely why this has become a leadership problem, not just a security one.

Why Control Is Getting Harder
More connectivity means more devices, more access paths, more remote users, more third-party maintenance windows, and more machine-to-machine interactions. That's not inherently a problem, it's often what keeps operations running. The harder question is whether anyone can still see the web of connections, govern them, and understand the dependencies that come with them.
This is where traditional approaches break down. Production teams optimise for uptime. Warehouse teams optimise for throughput. Factory teams optimise for output. And legacy security models? Well, they weren't designed to keep pace with these pressures, and the friction shows up in unexpected places.

Take handheld scanners used for warehouse logistics. Credentials required, security box ticked. That’s great, except half the floor is wearing gloves or has oil on their hands from the machinery. Logging in is a hassle; logging out so a colleague can use the same device feels like unnecessary admin when a line is waiting. The result: one device, one login, twelve people on shift. Identity becomes meaningless. Visibility evaporates. That's not a technology failure. That's a governance model that never accounted for the reality of the shop floor.
Questions Every Leadership Team Should Be Asking
Security must be frictionless to be effective. If it's complicated, people will route around it, not out of recklessness, but out of operational necessity. And that’s when every workaround becomes a visibility gap. And, if governance and control models are still rooted in the air-gap era, more tooling won't solve this problem.
The better starting point is an honest assessment of where the gaps actually are. Where are operations genuinely dependent on connectivity, and where have workarounds quietly filled the gaps? Where are third parties accessing operational systems, and through what mechanisms? And, critically, which security controls are improving visibility, and which are simply creating the friction that drives people around them?
The answers tend to reveal whether security is built around how work actually happens, or how leadership assumes it happens. Those are often very different things.
The issue was never that these environments were air gapped. It's that the security models built for that era were never redesigned when the era ended. The organisations best placed for what comes next aren't necessarily the ones with the most tools. They're the ones who understood where connectivity became essential and where visibility was lost. They’re the ones who chose to close that gap before it became a business failure.
The threats to connected factories aren't theoretical. IoT attacks on critical industries jumped 40% last year, and most environments still lack the visibility to see them coming.
Get the full picture: Download the ThreatLabz 2025 Mobile, IoT & OT Threat Report →
Cet article a-t-il été utile ?
Clause de non-responsabilité : Cet article de blog a été créé par Zscaler à des fins d’information uniquement et est fourni « en l’état » sans aucune garantie d’exactitude, d’exhaustivité ou de fiabilité. Zscaler n’assume aucune responsabilité pour toute erreur ou omission ou pour toute action prise sur la base des informations fournies. Tous les sites Web ou ressources de tiers liés à cet article de blog sont fournis pour des raisons de commodité uniquement, et Zscaler n’est pas responsable de leur contenu ni de leurs pratiques. Tout le contenu peut être modifié sans préavis. En accédant à ce blog, vous acceptez ces conditions et reconnaissez qu’il est de votre responsabilité de vérifier et d’utiliser les informations en fonction de vos besoins.
Recevez les dernières mises à jour du blog de Zscaler dans votre boîte de réception
En envoyant le formulaire, vous acceptez notre politique de confidentialité.



