
Bridging the Air Gap: Controlled OT/IT File Transfer Without Compromising Isolation
In a power plant, a refinery, a manufacturing line, or a defense environment, the operational technology network is deliberately walled off from the corporate IT world. The air gap exists for a good reason: keep the systems that run physical processes away from the threats that roam ordinary networks.
But isolation is not the same as silence. Those OT environments constantly need files, including updated configurations, firmware, engineering drawings, and reports flowing the other way. The data has to cross. How it crosses is, in too many facilities, the weakest link in an otherwise hardened design.
The USB Problem
When there’s no governed path between IT and OT, people invent one.
- Removable media risks: Usually it’s removable media: a USB drive carries the file across the gap by hand.
- Security vulnerabilities: It works, and it’s a well-documented way that malware enters supposedly isolated environments. Some of the most serious industrial incidents on record began with a file crossing the air gap on portable media that nobody inspected.
- Control bypass: The ad-hoc workaround doesn’t just bypass the isolation. It bypasses every control you’d want applied to a file entering a critical environment. There is no content inspection, no malware scanning, and no record of what crossed or who moved it.
A Governed Crossing, Not an Open Door
The goal isn’t to remove the air gap. It is to give it a single, controlled crossing point where files move under policy and inspection, replacing the uncontrolled human routes around it.
FileOrbis supports controlled OT/IT file transfer designed around the air gap rather than against it. Files that need to cross do so through a governed path where the platform’s full content awareness applies. Files can be:
- Classified
- Inspected
- Policy-checked before allowed through
Crucially, the same security pipeline that protects the rest of the estate applies here. Files crossing into OT can be routed through:
- Anti-malware
- CDR (Content Disarm and Reconstruction)
- Sandbox controls
These use sequential scanning so a file clears multiple engines before it’s trusted, turning the crossing into a checkpoint rather than a blind spot. CDR is especially relevant for industrial environments, where stripping active content from a file before it enters can neutralize a threat the engineering team would otherwise never see.
Direction Matters Too
Air-gap risk runs both ways.
- Entering OT: Files carry the malware risk.
- Leaving OT: Operational data, telemetry, and reports headed to corporate analytics or AI systems carry a confidentiality and integrity risk.
A governed crossing applies policy in both directions: inspecting what comes in, and controlling and logging what goes out, so the isolation’s value isn’t quietly eroded by an unmanaged export path.
Evidence for the Regulator
OT environments increasingly fall under explicit regulatory scope.
- The NCA’s controls in Saudi Arabia include specific requirements for industrial control systems and operational technology.
- EU regimes like NIS2 pull critical infrastructure into formal obligations.
A governed crossing produces what a managed USB process never can: a record of exactly what crossed the gap, in which direction, when, and after which controls. That audit trail is the difference between asserting your air gap is sound and being able to prove it.
The Takeaway
The air gap is a sound design that is often undermined by the unofficial ways people move files around it. You don’t fix that by isolating harder. You fix it by giving the gap one deliberate, inspected, logged crossing and closing the rest.
Controlled OT/IT transfer keeps the isolation that makes these environments safe, while giving the data a path that’s governed instead of improvised.
Moving files in and out of OT environments? Talk to FileOrbis about a controlled crossing.
Emre Demiray
Founder – FileOrbis
Subscribe to our Newsletter
About FileOrbis
Aiming to manage the user and file relationship within an institutional framework, FileOrbis is constantly being developed in order to meet different industry and customer needs in terms of file management and sharing. Since 2018, FileOrbis continues to be developed with the excitement of the first day. FileOrbis focuses on high security, rich integration, ease of use and integrated management criteria.

