Organizations managing critical infrastructure are increasingly seeking to balance the agility of cloud-native environments with the stringent security and control traditionally associated with physically isolated, or air-gapped, systems. This pursuit is further driven by escalating regulatory pressures from frameworks such as GDPR, NIS2, and DORA, which emphasize digital autonomy.
A proposed "logically air-gapped" governance model aims to address this challenge by extending principles from Data Vault scenarios, as established by AWS and IBM, across an entire application stack and its associated workflows. This model seeks to enable organizations to harness cloud-native benefits while maintaining complete, autonomous, and authoritative governance over their data and infrastructure.
The foundation of this autonomy rests on three core requirements: data residency, ensuring full control over data storage, access, and governing legal frameworks; technological autonomy, mitigating vendor lock-in through open standards and independent infrastructure; and operational autonomy, maintaining the ability to manage digital services independently without third-party interference.
Traditional physical air-gapping is often incompatible with the dynamic nature of modern containerized applications. Consequently, the logical air-gapping approach replaces physical barriers with a robust, software-defined cryptographic perimeter. At the core of this innovation is eBPF (extended Berkeley Packet Filter), a Linux-based technology that provides high-performance, low-impact security and observability at the kernel level, effectively rendering the infrastructure invisible and inaccessible to unauthorized entities.
OpenAI has adopted the Isovalent networking platform, powered by Cilium, as its standard for Kubernetes stacks, demonstrating a concrete application of this approach. This choice provides OpenAI with a unified foundation for managing CNI, IPAM, and L4/L7 filtering, ensuring operational consistency across both cloud and bare-metal environments. Isovalent was acquired by Cisco in 2024.
Cilium leverages eBPF to translate kernel capabilities into an orchestrated platform capable of managing complex data flows, transparent encryption, and network segmentation with high efficiency and scalability. This uniformity is crucial for rapidly scaling organizations, supporting security and compliance by eliminating the need to treat each environment as a siloed networking challenge and streamlining troubleshooting for platform teams. eBPF provides deep, real-time visibility into network traffic and application behavior, enabling granular, dynamic security policy enforcement directly at the kernel level.
The logically air-gapped governance model achieves its full operational potential through Live Protect, a runtime security module. Live Protect elevates protection from the configuration plane to dynamic execution, using eBPF within the kernel to monitor, detect, and mitigate threats in real-time as they attempt to bypass perimeter controls. This transforms the infrastructure into a self-defending environment.
In bare-metal scenarios, the solution extends eBPF capabilities to provide a logically isolated environment, representing the closest digital equivalent to a physical air gap. By eliminating dependency on third-party hypervisors, organizations can achieve total governance through a private control plane and superuser administration functions across the entire application stack. This drastically reduces the attack surface, ensuring that even non-containerized workloads benefit from granular segmentation, secure host networks, and end-to-end protection managed with total autonomy.
Digital autonomy is exercised by shifting network and security control into the operating system kernel. This enables deep observability without modifying source code, which is essential for demonstrating regulatory compliance. Isovalent, through Cilium Enterprise, extends these capabilities with transparent encryption (such as WireGuard or IPsec) and Egress Gateways, which force traffic toward internal checkpoints, preventing unauthorized exfiltration and ensuring sensitive information remains within defined jurisdictions.
Cisco integrates Isovalent's execution power with the governance of Cisco Secure Workload to offer a unified security model covering containerized, virtualized, and bare-metal environments. The integration between Cilium and systems like SPIRE allows the infrastructure to assign unique cryptographic identities to workloads, eliminating dependence on cloud provider proprietary IAM. Furthermore, the integration between Hubble and analytics platforms provides real-time flow mapping, enabling operators to identify bottlenecks or unauthorized connection attempts rapidly, thereby reducing resolution times.
This governance model adheres to established industry standards, including NIST SP 800-210, the Gaia-X trust framework, and ENISA’s EUCS requirements, integrating trusted execution environments as recommended by the Confidential Computing Consortium. Digital autonomy is presented not as a static state, but as a continuous process of control, trust, and resilience. By adopting a "presume breach" mentality and leveraging the combined power of eBPF and Cisco’s governance tools, enterprises can embrace innovation while maintaining the rigorous autonomy required to protect critical infrastructure transparently and scalably.






