Skip to main content

Off-grid cybersecurity: use cases

Some of the most critical systems cannot assume a network, and most security tooling quietly assumes one. The Cybersecurity Group builds security architectures for isolated, air-gapped and remote environments, providing protection and assurance where there is no reliable connectivity to lean on and no cloud console to phone home to. The most critical systems in a nation, energy sites, deployed networks and classified environments, are precisely the ones that cannot phone home to a security cloud, and adversaries target the gap between connected tooling and disconnected reality. The work here is protection and assurance rather than a box on a wall, because the thing that fails in a disconnected estate is usually the boundary discipline, not the wire. Unstrat represents the capability with a partner that has no foreign-government reporting line, so nothing about the estate flows to foreign infrastructure.

Where it is used

01
Securing an air gap is three jobs

Protecting an air-gapped network breaks into three tasks. Control what crosses the boundary on removable media, make the network path one-way wherever data has to leave, and then verify repeatedly that the gap is still real. The first two are hardware purchases from established appliance vendors; a media-scanning kiosk controls what enters and a unidirectional gateway enforces direction as physics rather than a rule that can be misconfigured. The third is a service, it is the one most operators skip, and it is the assurance layer this capability supplies, from an independent source with no reporting line to a foreign government.

02
Auditing the gap that erodes through routine work

Air gaps rarely fall to a dramatic attack; they erode through ordinary work. A commissioning link left in place, a vendor laptop on rotation, a new remote-monitoring contract nobody in security saw, each quietly bridges an isolation that a diagram still shows as intact. Somebody independent of the people who maintain the system, auditing often enough to catch drift rather than an incident, is what keeps the boundary honest. That review of people, process and configuration is the engagement, run on estates already in service rather than a test rig, and treating every maintenance visit as a boundary event is more use than any fixed audit cadence.

03
Designed for permanent disconnection

Where a network can never connect back to any supplier's cloud, a permanent air gap is a design input rather than a problem to work around. Detection, response and integrity mechanisms run locally and over intermittent links, and the procedures are ones the on-site team can execute alone without a tunnel to a vendor console. The engagement begins with the operating reality of each environment, connectivity, staffing and classification, and builds the architecture around it. Because the model assumes disconnection instead of treating it as an exception, deployed forces and remote installations sit inside the same pattern as classified enclaves.

04
Sustainment at sites nobody visits

A remote site that nobody reaches for months forces a plan for decay. Signature-based scanning stacks lose value the moment their updates stop arriving, and gateway connectors need maintenance as the systems behind them change, so someone senior has to own the update path in writing. The answer here is in-region sustainment by the team that ran the assessment, rather than a ticket queue in another time zone that an engineer cannot reach from a control room. The same in-region team returns rather than an offshore support tier, which matters most exactly where connectivity is worst.

05
Honest about what an appliance cannot do

A one-way gateway is excellent for traffic that only ever travels outward, and its limitation is stated plainly: it does not solve two-way requirements, does not inspect content and tells a defender nothing about what is happening inside the protected network. A media kiosk controls what enters but cannot confirm that a second modem did not appear during a refit. This capability does not sell a like-for-like appliance and will not pretend to; where procurement rules put a particular product out of reach, the practical route is to pair whatever media-control hardware the rules permit with an independent assurance partner.

06
One strand of a wider resilience posture

Off-grid architectures complement rather than replace the rest of a defensive posture. Infrastructure hardening reduces the attack surface of control systems, continuous defensive operations watch what can be watched, and off-grid architectures keep the isolated and air-gapped parts of the estate protected where connected tooling cannot reach. All three assemble through one accountable channel. The same approach underpins a communications backbone that must survive the network going down, where field-reconfigurable radios and resilient satellite links carry the traffic and off-grid architectures keep the nodes protected when the terrestrial network drops, with no coalition access conditions attached.

Off-grid cybersecurity
Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.