Air Gap Myth and OT Security Realities Highlighted by Bilfinger Director
Operational technology security expert Benjamin Bachmann debunks the air gap myth and emphasizes attacker focus on operational control over data theft in industrial environments.

Benjamin Bachmann, Director Group Information Security at Bilfinger, shared critical insights into the realities of operational technology (OT) security, challenging common misconceptions held by executives and security professionals alike. In a discussion with Help Net Security, Bachmann underscored that the primary motivation for attackers targeting industrial control systems (ICS) is not data exfiltration, but rather gaining control over physical operations.
Bachmann explained that many executives, accustomed to IT security paradigms, mistakenly believe attackers are after sensitive data. However, in OT environments, the true prize is the ability to disrupt or control critical infrastructure. "Nobody breaks into an industrial environment to read the recipe for district heating. They want the button that makes things stop," Bachmann stated, reframing the threat model from "someone steals our secrets" to "someone else is operating your plant." This shift in perspective is crucial for prioritizing security investments that enhance resilience in sectors like refineries, chemical plants, and energy infrastructure.
The second pervasive myth Bachmann tackled is the concept of the "air gap." He described it as a "unicorn of industrial security," rarely found in practice. The reality is that OT networks often contain forgotten devices, such as LTE dongles, that create unintended pathways for attackers. This highlights the need for continuous vigilance and a realistic assessment of network segmentation and connectivity.
Addressing the perennial question of who takes precedence during a live incident—engineers focused on uptime or security teams on containment—Bachmann advocated for a proactive, integrated approach. He argued that security's goal should align with the engineers' objective: a safely running plant. "Security becomes the department that stops production, I have turned myself into a second incident," he cautioned. Bachmann emphasized that the ability to contain an incident without halting production is paramount, and this requires pre-negotiated plans, exercised in advance, that define isolation triggers and acceptable downtime costs.
Bachmann also detailed a tactical reason for this approach: preventing attackers from weaponizing the security team's response. If a security team's only recourse is to shut down operations, an attacker can achieve their objective simply by triggering that shutdown. Therefore, containment strategies must be designed to be cost-effective, ensuring that defense does not compromise safety or uptime.
When it comes to securing legacy equipment, Bachmann proposed treating the network itself as the primary witness rather than expecting outdated devices to provide security logs. "A controller from 1998 was never designed to tell you what happened. But it never lies on its own. If it starts lying, someone taught it to," he noted. By passively monitoring network traffic at key choke points and establishing robust baselines, security teams can detect anomalies more effectively. OT traffic's predictable, choreographed nature makes deviations stand out starkly against the chaotic nature of IT traffic, providing a "stranger on the dance floor" indicator.
Bachmann stressed that "defensible visibility" means being able to confidently articulate what normal operations looked like, when deviations occurred, and what systems were affected, rather than simply having a dashboard. This clarity is essential for reporting to boards, regulators, and insurers.
Finally, Bachmann discussed the evolving threat of ransomware, noting that attackers now prioritize operational disruption over data encryption due to its higher profitability. This has shifted the focus for defense strategies from merely building "higher walls" to actively disrupting the attackers' business model by minimizing downtime. Segmentation and recovery are thus intertwined, focusing on the speed at which an operation can return to a safe state without paying ransoms. The most critical capability is "degraded operation," allowing partial restarts while forensic investigations continue, thereby denying attackers the leverage of prolonged downtime.