
Keep your most sensitive systems defended when the network is gone
Off-grid cybersecurity
Overview
Security architectures for environments that must operate without reliable connectivity. Protection and assurance for isolated, air-gapped and remote systems.
A cybersecurity architecture built for isolated, air-gapped and remote environments: detection, integrity assurance and response that work without a live cloud console or a vendor's update feed, for defence ministries and infrastructure owners whose most critical systems are precisely the ones that cannot phone home, delivered by an independent team with no foreign reporting line.
Key capabilities
- Detection and monitoring architected to run with no reliable connectivity, so the disconnected estate is not the least protected part of the enterprise.
- Integrity assurance for air-gapped and isolated systems that holds through disruption and re-establishes cleanly once contact returns.
- Update and patch mechanisms designed for intermittent links or manual delivery, rather than a constant stream from a vendor's servers.
- Response procedures the on-site team executes independently, matched to environments where help is far away.
- Everything stays inside the buyer's boundary, with no telemetry or findings flowing to foreign infrastructure.
- The same discipline applied across command sites, remote installations and classified enclaves that share the disconnected pattern.
- Delivered under the buyer's flag alone, so the systems most worth protecting are never exposed to a foreign reporting line.
Performance envelope
| Connectivity assumption | Designed for air-gapped and intermittent operation |
| Detection model | Configuration-dependent, local, no external dependency |
| Update mechanism | Subject to mission profile, intermittent or manual delivery |
| Environment classes | Multiple isolation classes available |
| Response model | On-site, operator-executable |
| Integration surface | Integrated to existing systems on assessment |
| Data boundary | Everything remains inside the buyer's environment |
| Detailed methods | Available under controlled briefing, not published |
Qualitative envelope only. Exact figures are configuration-dependent and shared under a controlled briefing against your requirement: never published.
In depth
Off-grid cybersecurity is not a product bolted onto a live feed but an architecture that assumes the link will fail. Protection is designed into the disconnected estate itself and sustained through one accountable team, so integrity holds through disruption rather than depending on a connection that will not be there.
Local detection
Monitoring and detection that run entirely on site, tuned to the isolated or air-gapped environment, so threats are surfaced without reaching an external service or streaming telemetry off the boundary.
Integrity assurance
Mechanisms that verify systems remain trustworthy through periods without connectivity: baselining, integrity checking and controlled update paths that work over intermittent links or by hand.
Response procedures
Drilled, documented procedures the on-site team can execute alone, so containment and recovery do not wait for a remote analyst who may be hours or days away.
Update and re-connection path
A disciplined way to receive updates late, by intermittent link or physical transfer, and to re-establish external assurance cleanly once contact returns, without opening the estate to what it was isolated from.
On-site operator
The person at the edge is the last line. Training, doctrine and drills build operators who can run detection and response with no reachback, and who understand the architecture rather than merely watch it.
Integrations
Interfaces to the existing control, command and site-security systems already present in the isolated environment, so the capability augments what is there instead of forcing a connected rebuild.
Operational problems it addresses
- Protecting command bunkers, forward sites and deployed networks that must stay defended when links to any external service drop.
- Securing air-gapped industrial control islands and classified enclaves that were deliberately kept off the network and cannot be exposed to reach a security cloud.
- Maintaining system integrity through extended periods of intermittent or absent connectivity, then re-establishing assurance cleanly once contact returns.
- Equipping an on-site team to detect and respond alone, when support is distant and no analyst is watching a remote dashboard.
- Closing the gap adversaries exploit between connected security tooling and the disconnected reality of the systems most worth protecting.
- Ensuring the telemetry and findings from sensitive environments never leave the buyer's own boundary.
Deployment configurations
Why Unstrat: the difference
Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.
Versus cloud-dependent security tooling
Conventional tooling assumes constant connectivity, a cloud console and a stream of vendor updates, none of which exists at the edge. Building protection on that assumption leaves the most sensitive systems the least defended. This architecture starts from the opposite premise: that the link will drop and the system must remain trustworthy in the meantime.
Versus a foreign-hosted managed service
A managed service that watches your estate from foreign infrastructure sees your telemetry first and may carry obligations about what it does with it. For isolated command and classified systems, that exposure is unacceptable. An independent team keeps everything inside the buyer's boundary, accountable to the buyer's flag alone.
Versus assuming an air gap is enough on its own
Isolation reduces exposure but does not by itself detect, assure or recover a system under threat. Air-gapped estates still need monitoring, integrity checking and drilled response, designed to work without the connection that a bolted-on tool would demand.
Versus a single-vendor connected platform
One-vendor connected platforms lock the buyer into a model that only functions online and only under the vendor's terms. Architecting for disconnection, and integrating with the systems already present in the isolated environment, avoids a connected rebuild and keeps the estate defensible on its own.
Versus relying on remote analysts alone
When support is distant and links are down, a remote analyst cannot act in time. Drilled on-site procedures and locally executable response put the capability in the hands of the operator who is actually there, rather than one who may never reach the system.
How it reaches you
Sovereignty & localisation
- Buyer ownership of all operational data and findings, which never leave the isolated environment.
- Local control of detection configuration, integrity baselines and response procedures.
- Options for local assembly and integration of the deployed architecture.
- In-region maintenance and sustainment rather than remote, supplier-gated support.
- Operator training and train-the-trainer programmes so the on-site team can run the capability alone.
- Progressive technology transfer and component localisation, scoped per programme.
- A path towards independent sustainment so the disconnected estate stays defended without outside reachback.
Integration
- Existing control and command systems inside the isolated environment, augmenting them rather than forcing a connected rebuild.
- In-service site-security and monitoring systems already present at the remote or air-gapped site.
- Existing operator procedures and response chains, keeping human decision-making on site and in the loop.
- Controlled update and data-transfer paths suited to intermittent or absent connectivity.
- Mission and operations software already in use at the command site.
- Site infrastructure, including power, siting and physical isolation, assessed as part of configuration.
Procurement & delivery
- Engagement begins with the operating reality of each environment, from connectivity to staffing and classification, and builds the architecture around it.
- Export-control position and end-user-certificate chain are confirmed before any configuration is represented.
- Assessment, architecture, deployment and acceptance follow the standard programme path, with verification tested against the loss of connectivity itself.
- Operator training, sustainment and in-region support are part of the same accountable engagement.
Off-grid cybersecurity: questions
How can you monitor a system that has no network connection?
Detection runs entirely on site rather than reaching a cloud console. Monitoring, baselining and integrity checking are designed to operate within the isolated environment, so threats are surfaced locally without streaming telemetry off the boundary. That is the whole point of an off-grid architecture rather than a connected tool pointed at a disconnected estate.
How do systems stay patched and updated when links are unreliable?
Update and patch mechanisms are built for intermittent links or manual delivery, not a constant vendor feed. Updates can arrive late, over an occasional link or by controlled physical transfer, with a disciplined path to apply them and re-establish assurance cleanly, without opening the estate to what it was isolated from.
Does any of our telemetry or findings leave our environment?
No. Everything stays inside the buyer's boundary by design. There is no foreign reporting line and no telemetry flowing to external infrastructure, so the systems most worth protecting, such as command sites and classified enclaves, are never exposed to reach a security service.
What happens during a long period with no connectivity at all?
Continuity is the design case. Integrity is maintained through the disruption using techniques that do not depend on an external service, the on-site team can detect and respond alone, and external assurance is re-established cleanly once contact returns rather than the security failing when the link does.
Isn't an air gap enough on its own?
Isolation reduces exposure but does not detect, assure or recover a system under threat. Air-gapped estates are still attacked, often precisely because they are assumed safe. This capability adds local monitoring, integrity verification and drilled response to the isolation, designed to work without the connection a bolted-on tool would demand.
Can the on-site team run this without a remote analyst?
Yes, that is the requirement it is built for. Response procedures are drilled and documented so the operator at the edge can contain and recover alone, and training and train-the-trainer programmes build a team that runs the architecture with no reachback.
What can you tell us about the specific detection methods?
Multiple isolation classes are supported and the approach is configuration-dependent. The detailed detection and integrity methods are shared under a controlled briefing against your specific environment, covering connectivity, staffing and classification, rather than published.
Next step on this capability
Related capability
View all →Applications it supports
Capability comparisons
Questions buyers ask
What is off-grid cybersecurity?
It is security for systems that cannot rely on a live connection: isolated control rooms, air-gapped enclaves and remote sites. The work is protection and assurance rather than a box on a wall, because the thing that fails in a disconnected estate is usually the boundary discipline, not the wire. Our engagements run on estates already in service, delivered by the same team that runs our defensive operations.
See: Off-grid cybersecurity in the catalogueAir-gapped vs connected security, explained
How do you secure an air-gapped network?
Three jobs have to be filled. Control what crosses the boundary on removable media, make the network path one-way wherever data has to leave, and then verify repeatedly that the gap is still real. The first two are hardware purchases, from OPSWAT and Waterfall among others. The third is a service, it is the one most operators skip, and it is ours.
Air-gapped network security suppliers
The market splits into appliance vendors and assurance providers. OPSWAT sells removable-media scanning kiosks and Waterfall sells unidirectional gateways, both with published throughput and certification figures. We sell the assurance layer for disconnected estates, from an independent, non-aligned supplier with no reporting line to a foreign government.
See: What we publish and what we do not, against OPSWAT and WaterfallOT security as a discipline
Who audits the air gap in a power station control room?
Somebody independent of the people who maintain it, and often enough that the audit catches ordinary drift rather than an incident. Air gaps erode through routine work: a commissioning link left in place, a vendor laptop on rotation, a new remote-monitoring contract nobody in security saw. That review of people, process and configuration is the engagement we sell, and it is run by the team that also defends live grid and finance estates.
See: Off-grid assurance in detailCritical infrastructure resilience
Is a data diode better than a firewall for OT networks?
For traffic that only ever travels outward, yes. Waterfall's WF-500 puts a fibre laser in the transmit module and nothing else, so a reverse connection is physics rather than a rule that can be misconfigured, at 1 Gbps standard with over 100 commercial connectors. A firewall is a rule set, and rule sets drift. The limitation is honest: a diode does not solve two-way requirements, does not inspect content and tells you nothing about what is happening inside the protected network.
Removable media control for a site that cannot buy from a US supplier
OPSWAT is the reference product here, with more than 30 anti-malware engines, a stated detection rate above 99% of known malware and Common Criteria EAL4+ on the Tower 5. If procurement rules put that out of reach, the practical route is to pair whatever media-control hardware your rules permit with an independent assurance partner. We do not sell a like-for-like appliance and will not pretend to.
Security assessment for remote sites with intermittent connectivity
Assessment has to assume the link is absent, not merely slow. Our off-grid work covers isolated, air-gapped and remote systems, and the sustainment model is that the same in-region team returns rather than an offshore queue answering tickets. That matters because a signature-based scanning appliance loses value the moment its updates stop arriving.
How often should an air-gapped system be reassessed?
We do not publish a fixed cadence, and any supplier quoting one without seeing your site is guessing. Set it against how frequently external engineers reach the enclave, and treat every maintenance visit as a boundary event. The gap is eroded by ordinary work far more often than by attack.
Our SCADA network is supposedly air-gapped, but contractors bring laptops on site every month. What should we actually buy?
Buy the audit before the hardware. Media control and one-way gateways solve the two paths you already know about; the contractor laptop that spends alternate weeks on the corporate network is the path nobody wrote down. Our engagement looks for exactly that class of failure across people, process and configuration, on estates that are running now rather than in a test rig. Once the real boundary is mapped, the appliance decision becomes straightforward.
Can a security service work for us if our systems can never connect back to the supplier's cloud?
That is the premise of the service. Off-grid engagements are built for environments that must operate without reliable connectivity, so nothing in the model assumes a live tunnel to a vendor console. Sustainment runs through one accountable team in region, from first briefing through delivery, rather than through a support portal your engineer cannot reach from the control room.
See: Off-grid cybersecurityHow our model differs from an appliance purchase
Our isolated enclave still has to accept quarterly updates from a foreign equipment vendor. How do we manage that without breaking isolation?
Treat the maintenance window as the primary threat, because it is. The update path needs a defined boundary crossing, a media or one-way route that is inspected, and an assurance review after the visit rather than only before it. We assess that whole sequence, and we have no obligation to report what we find in your enclave to any government.
Can an off-grid assessment give us evidence for NERC CIP or IEC 62443 compliance?
We do not publish a compliance mapping for this service, and inventing one would not survive an audit. For comparison, OPSWAT does map kiosk use to NERC CIP-010-2 R4 transient cyber asset and removable media requirements in its deployment guide, which is worth knowing if the media route is your gap. Ask us in writing which frameworks your engagement can evidence and you will get either the answer or a plain statement that we do not hold it.
Who can assess our air-gapped defence enclaves without reporting the findings to their own government?
That question narrows the field quickly, because most of the recognised suppliers sit inside a major-power ecosystem. OPSWAT is a United States company and Waterfall's own profile states headquarters in Israel. Our origin is independent and non-aligned, with no political exposure to any major-power ecosystem and no reporting line behind us. For a ministry, that term usually matters more than a detection statistic.
See: Origin and exposure, supplier by supplierOff-grid cybersecurity capability
We already own media kiosks and a unidirectional gateway. What is left for an assurance partner to do?
Confirm that the architecture you drew is the architecture you have. A kiosk controls media, a gateway enforces direction, and neither can tell you whether a second modem appeared during a refit or whether the historian behind the diode is now reachable another way. Our work is that verification, run repeatedly, by people who also defend live grids, payment platforms and fleets at sea.
How do you sustain security at a remote site nobody visits for months at a time?
Plan for decay. Signature-based scanning stacks lose value as soon as updates stop arriving, and gateway connectors need maintenance as the systems behind them change, so somebody senior has to own the update path in writing. Our answer is in-region sustainment by the team that did the assessment, rather than a ticket queue in another time zone. OPSWAT, by contrast, publishes four support tiers with phone access only on the upper two.





