RaptorGRC —Self-Hosted GRC

BLOG

Running a Compliance Programme in Air-Gapped and Offline Environments

Published 14 August 2026 · By P Larner

Compliance in Practice#evidence#operational technology#air-gapped#offline#classified

Running a Compliance Programme in Air-Gapped and Offline Environments

Illustration for: Running a Compliance Programme in Air-Gapped and Offline Environments

Illustration for: Running a Compliance Programme in Air-Gapped and Offline Environments

Most compliance tooling assumes an internet connection, a cloud console and a browser. For a meaningful slice of the security community, none of those things exist where the work happens. This article covers how to run a credible compliance programme when your systems will never touch the internet, and the mistakes that undo teams who try.

Who genuinely needs to work air-gapped

Air-gapping is often dismissed as paranoia, but several sectors have no realistic alternative.

  • Defence and classified environments. Systems processing material at OFFICIAL-SENSITIVE and above, and anything at SECRET, sit on accredited networks with strict cross-domain rules. A SaaS GRC platform hosted in a public cloud is a non-starter regardless of its certifications.
  • Critical national infrastructure. Operators covered by the NIS Regulations run control systems where the safety case depends on isolation. An energy distribution operator I worked with had substation networks that had never seen a routable internet path, deliberately.
  • Operational technology. Manufacturing lines, water treatment SCADA, rail signalling. Segmentation is the primary control, and the compliance evidence lives inside that segment.
  • Research and sovereign environments. Some contracts simply prohibit data leaving a named building, let alone the country.

For these teams, “just use the cloud portal” is not advice. It is a policy breach.

Why SaaS GRC tooling is off the table

The obvious objection is that the vendor is ISO 27001 certified and hosts in a UK region. That misses the point. The problem is not the vendor’s security posture, it is the data flow. Uploading a network diagram of a classified system, a list of unpatched OT assets, or a risk register naming specific vulnerabilities creates an aggregation of exactly the information an adversary wants, on a system outside your accreditation boundary. Most security aspects letters and OT security policies forbid it outright.

So the programme has to run on what is inside the gap, whether file shares, self-hosted tools on the isolated network, or in plenty of real cases, spreadsheets and paper. That is workable if you design for it.

Network zone diagram showing the prohibited data flow from an air-gapped environment to cloud SaaS GRC

Network zone diagram showing the prohibited data flow from an air-gapped environment to cloud SaaS GRC

The flow the accreditation boundary exists to stop. The target map stays inside the gap.

Practical patterns that work

Sneakernet evidence transfer, done properly

Evidence will move across the gap, with audit reports going out and policy updates coming in. Treat this as a controlled process, not an ad hoc favour. That means a small set of authorised removable media, serial-numbered and logged, a scanning kiosk with ideally two engines that every item passes through in both directions, a transfer log recording who, what, when and approval, and a one-way preference where possible, such as data diodes for exporting monitoring data from OT to the corporate side.

Process flow of a controlled media transfer with five steps from authorised media pool to import station, plus a one-way data diode arrow

Process flow of a controlled media transfer with five steps from authorised media pool to import station, plus a one-way data diode arrow

The sanctioned route, with five controlled steps for moving media across the gap and a one-way diode for outbound monitoring data.

Offline documentation as the source of truth

Pick one authoritative store inside the environment and be disciplined about it. A structured file share with a naming convention beats a sophisticated tool nobody keeps current. Version documents explicitly, so v1.3, dated, with a change table, because you cannot rely on cloud version history. Print matters more than people expect, because during an ICS incident the network you would read the runbook on may be the network that is down.

Update and patch strategy without internet

Unpatched air-gapped systems are common and indefensible. A workable pattern is a monthly cycle. Download vendor patches and signature updates on a connected staging system, verify hashes and signatures, burn to write-once media or transfer via the controlled process, test on a representative offline rig, then deploy in a maintenance window. Document the cadence and the risk acceptance for anything the vendor no longer supports. Auditors accept a slower cycle, but they do not accept the absence of one.

Circular six-stage monthly patch cycle for air-gapped systems with the offline test rig stage highlighted in amber

Circular six-stage monthly patch cycle for air-gapped systems with the offline test rig stage highlighted in amber

A documented monthly patch cycle, where the amber testing stage is the step teams most often skip.

Audit logistics

External auditors can rarely bring laptops into the environment, and remote evidence sharing is out. Plan for it. Agree the evidence list six weeks ahead, prepare sanitised exports where classification allows, book cleared escorts, and set up a review room with a standalone screen for walking through logs and configurations. A three-day audit becomes five. Budget for that.

Activity

Connected environment

Air-gapped equivalent

Evidence collection

Automated API pulls

Scheduled manual exports via controlled media

Policy distribution

Intranet portal

Signed documents imported monthly

Patch intake

Direct from vendor

Staged, verified, transferred, tested

Audit fieldwork

Screen share

On-site, escorted, sanitised exports

Common mistakes

Undocumented USB exceptions

This is the classic. The official position is “no removable media”, and the reality is a drawer of unmanaged sticks used whenever someone needs to move a file. Every audit finds them. An honest, controlled media process with logging is far stronger than a pristine policy plus a shadow practice. If people need to move data, give them a sanctioned way or they will invent one.

Assuming the gap holds

Vendors arrive with laptops, engineers tether phones to “quickly check something”, and maintenance connections get left in place. Verify isolation periodically rather than asserting it. Stuxnet crossed an air gap on removable media, so the gap is a control, not a guarantee.

Evidence that ages silently

Without automation, last quarter’s asset list quietly becomes last year’s. Put evidence refresh on a named person’s calendar with dates, not intentions.

One heroic individual

Offline programmes often depend on the single person who knows where everything lives. When they leave, the programme resets to zero. Insist on the shared store and written procedures.

Copying corporate policy wholesale

A patching policy demanding 14-day remediation is fiction in an OT environment with annual outage windows. Write policies the environment can actually meet, then enforce them.

Making it sustainable

An air-gapped compliance programme costs more per control than a connected one, and pretending otherwise is how they fail. Budget explicit time for the manual work, meaning evidence refresh, media handling, and import and export cycles. Keep the control set proportionate, because 40 well-evidenced controls beat 200 aspirational ones. Rehearse the audit logistics before the auditor is standing at the gate. And revisit the boundary once a year, because the strongest finding you can present is proof that the gap you claim is the gap you have. Teams that treat the constraint as a design input, rather than an excuse, run some of the most disciplined programmes I have seen.

Run your GRC programme in your own network.

RaptorGRC Community Edition is free: every module, offline licence activation, nothing phones home.

Register / Download Contact us
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.