August 14, 2026
August 14, 2026
Cisco proposes a “logically air-gapped” architecture for critical infrastructure that combines cloud-native flexibility with the control traditionally associated with physically isolated systems. The model is built around data residency, technological autonomy and operational autonomy, helping organizations retain authority over where information is stored, reduce dependence on individual vendors and operate services without third-party interference. Because physical air gaps are often impractical for containerized and distributed applications, Cisco recommends replacing them with a software-defined cryptographic perimeter. At its foundation is eBPF, a Linux kernel technology that provides detailed visibility, efficient traffic control and dynamic security-policy enforcement with minimal performance impact.
The proposed implementation uses Cisco-owned Isovalent technologies, including Cilium for segmentation, encryption and network management, and Live Protect for real-time runtime threat detection and mitigation. On bare-metal infrastructure, this approach can reduce reliance on external hypervisors while extending protection to both containerized and conventional workloads. Transparent WireGuard or IPsec encryption, controlled egress paths, workload identities and Hubble-based traffic monitoring are intended to prevent data exfiltration and improve incident response. Combined with Cisco Secure Workload, the model covers containers, virtual machines and physical servers, while aligning with frameworks such as NIST SP 800-210, Gaia-X and ENISA’s EUCS requirements. Cisco concludes that digital autonomy is not a fixed condition but a continuous process based on visibility, cryptographic trust, resilience and a “presume breach” security posture.
Source: Cisco Blogs