惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
B
Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V
Visual Studio Blog
S
SegmentFault 最新的问题
腾讯CDC
博客园 - 叶小钗
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
Jina AI
Jina AI
A
About on SuperTechFans
博客园 - 司徒正美
C
Check Point Blog
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
N
Netflix TechBlog - Medium
T
Tenable Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
小众软件
小众软件
Spread Privacy
Spread Privacy
阮一峰的网络日志
阮一峰的网络日志
Know Your Adversary
Know Your Adversary
NISL@THU
NISL@THU
K
Kaspersky official blog
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
D
DataBreaches.Net
A
Arctic Wolf
I
InfoQ
量子位
IT之家
IT之家
Security Latest
Security Latest
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Google DeepMind News
Google DeepMind News
The Hacker News
The Hacker News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
Google Developers Blog
P
Proofpoint News Feed
P
Privacy International News Feed
T
Threatpost
L
Lohrmann on Cybersecurity
P
Proofpoint News Feed
G
GRAHAM CLULEY
V
Vulnerabilities – Threatpost
Martin Fowler
Martin Fowler
C
Cyber Attacks, Cyber Crime and Cyber Security
PCI Perspectives
PCI Perspectives
F
Full Disclosure

Security @ Cisco Blogs

Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026 Uplevelling Black Hat Threat Hunters Making Workflow Runs Explain Themselves: AI-Powered Run Summaries in Cisco XDR Automate Independent Testing Confirms Secure Email Threat Defense’s Email Security Strength Defenseclaw for On-Prem AI SOC Workflow at Black Hat Asia Cisco Secure Access with MCP Infrastructure at Black Hat Asia 2026 The Essence of Black Hat – Collaboration with Partners Black Hat Asia 2026: A Decade in Singapore Black Hat Asia 2026: Threat Hunters’ Corner Unveiling the Power of Integration: XDR, Splunk, Corelight, Arista and Palo Alto Networks in Action at Black Hat Asia Security in the Post-Mythos Era Cisco SASE with Meraki: Get in the Fast Lane to SASE Extending Zero Trust Across the Agentic AI Workflow Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense Cisco Secure Access and Microsoft Edge for Business Integration Why Network Segmentation Projects Fail: Four Patterns Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files AI-generated reporting: Lessons learned from Cisco Talos Incident Response Inside the SOC: AI-powered DNS defense against ransomware Security Insights: A Threat-First View for the Platform That Enforces Access From Strategy to Architecture: How Cisco is Building a Quantum-Safe Future AI-Ready, Simpler, and More Secure WAN: Cisco SD-WAN Innovations Designing for What’s Next: Securing AI-Scale Infrastructure Without Compromise Preparing for Post-Quantum Cryptography: The Secure Firewall Roadmap Mobile World Congress 2026: AI-powered Network Security Powering MWC Barcelona – Building a Unified SOC and NOC with Splunk in Record Time AI-powered Network Security at the Mobile World Congress 2026 SNOC Inside the Mobile World Congress 2026 SOC: Detecting Shadow Traffic with Firepower 6100 Data Optimization in Security: A Splunk Architect’s Perspective Inside the Talos 2025 Year in Review: A discussion on what the data means for defenders Zero Trust for Agentic AI: Safeguarding your Digital Workforce The Agent Trust gap: What Our Research Reveals About Agentic AI Security Meet Your Incident Responders
The Journey towards Logically Air-Gapped Deployment
Michele Festuccia · 2026-07-24 · via Security @ Cisco Blogs

The need and ability to face the challenge with a clear plan

In today’s technological landscape, organizations managing critical infrastructure face a complex paradox: how to leverage the agility of cloud-native environments while maintaining the absolute control and security typical of a traditional isolated, or “air-gapped,” infrastructure. Simultaneously, the intensification of regulatory pressures such as GDPR, NIS2, and DORA reinforces the need for digital autonomy. This document proposes a “logically air-gapped” governance model designed to address this challenge by extending the principles established by AWS and IBM for Data Vault scenarios across the entire application stack and its associated workflows, enabling organizations to capture cloud-native benefits while ensuring complete, autonomous, and authoritative governance of their data and infrastructure.

This model of autonomy is built upon three core requirements that serve as the foundation for the proposed framework:

  • Data Residency: ensuring full control over where information is stored, who can access it, and the governing legal framework.
  • Technological Autonomy: mitigating vendor lock-in by embracing open standards and independent infrastructure.
  • Operational Autonomy: maintaining the ability to manage digital services independently, free from the interference of third parties.

The central challenge remains the tension between cloud agility and the necessity for such autonomy, as traditional air-gapping—which requires the physical disconnection of systems—is often incompatible with the dynamic nature of modern containerized applications. Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter. At the heart of this innovation lies eBPF, or extended Berkeley Packet Filter, a Linux-based technology that enables high-performance, low-impact security and observability at the kernel level, effectively transforming the infrastructure into an environment that remains invisible and inaccessible to unauthorized entities.

Reference Books

A concrete example of this approach’s efficacy is OpenAI, which has adopted the Isovalent networking platform—powered by Cilium—as the standard for its Kubernetes stack. This choice has provided OpenAI with a unified foundation for managing CNI, IPAM, and L4/L7 filtering, ensuring operational consistency across both cloud and bare-metal environments.

It is worth noting that Isovalent was acquired by Cisco in 2024.

Cilium leverages eBPF in a structured and organic manner, translating the raw capabilities of the kernel into an orchestrated platform capable of managing complex data flows, transparent encryption, and network segmentation with high efficiency and scalability.

For a rapidly scaling organization, this uniformity is crucial. It supports security and compliance by eliminating the need to treat each environment as a siloed networking challenge, thereby significantly streamlining troubleshooting for platform teams.

eBPF acts as a fundamental catalyst, providing deep, real-time visibility into network traffic and application behavior, while enabling granular, dynamic security policy enforcement directly at the kernel level.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution. While segmentation and encryption define the perimeter, Live Protect utilizes eBPF within the kernel to monitor, detect, and mitigate threats in real-time as they attempt to bypass perimeter controls. This approach effectively evolves the infrastructure from a merely “protected” environment into a “self-defending” one.

Isovalent Reference Stack

In bare metal scenarios, the solution reaches its peak, extending eBPF capabilities to provide a logically isolated environment that represents the closest digital equivalent to a physical airgap. By eliminating dependency on third-party hypervisors, the company achieves total “governance” through a private control plane and superuser administration functions across the entire application stack. This approach allows for a drastic reduction in the attack surface, ensuring that even non-containerized workloads benefit from granular segmentation, secure host networks, and end-to-end protection managed with total autonomy.

Reference Architecture

Digital autonomy is thus exercised by shifting network and security control into the operating system kernel. This tool enables deep observability without modifying source code, an essential aspect for demonstrating regulatory compliance. Isovalent, through Cilium Enterprise, extends these capabilities with transparent encryption such as WireGuard or IPsec and Egress Gateways, which force traffic toward internal checkpoints, preventing unauthorized exfiltration and ensuring that sensitive information never leaves the defined jurisdiction.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a unified security model that covers containerized, virtualized, and bare metal environments. Thanks to the integration between Cilium and systems like SPIRE, the infrastructure assigns unique cryptographic identities to workloads, eliminating dependence on the cloud provider’s proprietary IAM. The integration between Hubble and analytics platforms allows for real-time flow mapping, enabling operators to identify bottlenecks or unauthorized connection attempts in seconds, drastically reducing resolution times.

To ensure technical rigor, this governance model is based on established industry standards. The model aligns with global standards such as NIST SP 800-210, the Gaia-X trust framework, and ENISA’s EUCS requirements, integrating trusted execution environments as recommended by the Confidential Computing Consortium.

In conclusion, digital autonomy does not represent a static state, but a continuous process of control, trust, and resilience. By adopting a “presume breach” mentality and leveraging the combined power of eBPF and Cisco’s governance tools, enterprises can embrace innovation with confidence, while maintaining the rigorous autonomy required to protect critical infrastructure in a transparent and scalable way.

References: