惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
博客园 - 【当耐特】
人人都是产品经理
人人都是产品经理
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
aimingoo的专栏
aimingoo的专栏
Jina AI
Jina AI
小众软件
小众软件
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
I
InfoQ
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Martin Fowler
Martin Fowler
P
Proofpoint News Feed
MyScale Blog
MyScale Blog

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026
The Journey towards Logically Air-Gapped Deployment
Michele Festuccia · 2026-07-24 · via Security @ Cisco Blogs

The need and ability to face the challenge with a clear plan

In today’s technological landscape, organizations managing critical infrastructure face a complex paradox: how to leverage the agility of cloud-native environments while maintaining the absolute control and security typical of a traditional isolated, or “air-gapped,” infrastructure. Simultaneously, the intensification of regulatory pressures such as GDPR, NIS2, and DORA reinforces the need for digital autonomy. This document proposes a “logically air-gapped” governance model designed to address this challenge by extending the principles established by AWS and IBM for Data Vault scenarios across the entire application stack and its associated workflows, enabling organizations to capture cloud-native benefits while ensuring complete, autonomous, and authoritative governance of their data and infrastructure.

This model of autonomy is built upon three core requirements that serve as the foundation for the proposed framework:

  • Data Residency: ensuring full control over where information is stored, who can access it, and the governing legal framework.
  • Technological Autonomy: mitigating vendor lock-in by embracing open standards and independent infrastructure.
  • Operational Autonomy: maintaining the ability to manage digital services independently, free from the interference of third parties.

The central challenge remains the tension between cloud agility and the necessity for such autonomy, as traditional air-gapping—which requires the physical disconnection of systems—is often incompatible with the dynamic nature of modern containerized applications. Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter. At the heart of this innovation lies eBPF, or extended Berkeley Packet Filter, a Linux-based technology that enables high-performance, low-impact security and observability at the kernel level, effectively transforming the infrastructure into an environment that remains invisible and inaccessible to unauthorized entities.

Reference Books

A concrete example of this approach’s efficacy is OpenAI, which has adopted the Isovalent networking platform—powered by Cilium—as the standard for its Kubernetes stack. This choice has provided OpenAI with a unified foundation for managing CNI, IPAM, and L4/L7 filtering, ensuring operational consistency across both cloud and bare-metal environments.

It is worth noting that Isovalent was acquired by Cisco in 2024.

Cilium leverages eBPF in a structured and organic manner, translating the raw capabilities of the kernel into an orchestrated platform capable of managing complex data flows, transparent encryption, and network segmentation with high efficiency and scalability.

For a rapidly scaling organization, this uniformity is crucial. It supports security and compliance by eliminating the need to treat each environment as a siloed networking challenge, thereby significantly streamlining troubleshooting for platform teams.

eBPF acts as a fundamental catalyst, providing deep, real-time visibility into network traffic and application behavior, while enabling granular, dynamic security policy enforcement directly at the kernel level.

This “Logically Air-Gapped” governance model reaches its full operational potential through the implementation of “Live Protect.” As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution. While segmentation and encryption define the perimeter, Live Protect utilizes eBPF within the kernel to monitor, detect, and mitigate threats in real-time as they attempt to bypass perimeter controls. This approach effectively evolves the infrastructure from a merely “protected” environment into a “self-defending” one.

Isovalent Reference Stack

In bare metal scenarios, the solution reaches its peak, extending eBPF capabilities to provide a logically isolated environment that represents the closest digital equivalent to a physical airgap. By eliminating dependency on third-party hypervisors, the company achieves total “governance” through a private control plane and superuser administration functions across the entire application stack. This approach allows for a drastic reduction in the attack surface, ensuring that even non-containerized workloads benefit from granular segmentation, secure host networks, and end-to-end protection managed with total autonomy.

Reference Architecture

Digital autonomy is thus exercised by shifting network and security control into the operating system kernel. This tool enables deep observability without modifying source code, an essential aspect for demonstrating regulatory compliance. Isovalent, through Cilium Enterprise, extends these capabilities with transparent encryption such as WireGuard or IPsec and Egress Gateways, which force traffic toward internal checkpoints, preventing unauthorized exfiltration and ensuring that sensitive information never leaves the defined jurisdiction.

Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a unified security model that covers containerized, virtualized, and bare metal environments. Thanks to the integration between Cilium and systems like SPIRE, the infrastructure assigns unique cryptographic identities to workloads, eliminating dependence on the cloud provider’s proprietary IAM. The integration between Hubble and analytics platforms allows for real-time flow mapping, enabling operators to identify bottlenecks or unauthorized connection attempts in seconds, drastically reducing resolution times.

To ensure technical rigor, this governance model is based on established industry standards. The model aligns with global standards such as NIST SP 800-210, the Gaia-X trust framework, and ENISA’s EUCS requirements, integrating trusted execution environments as recommended by the Confidential Computing Consortium.

In conclusion, digital autonomy does not represent a static state, but a continuous process of control, trust, and resilience. By adopting a “presume breach” mentality and leveraging the combined power of eBPF and Cisco’s governance tools, enterprises can embrace innovation with confidence, while maintaining the rigorous autonomy required to protect critical infrastructure in a transparent and scalable way.

References: