Removable media is the threat that network controls do not see. A USB drive carried into a plant bypasses firewalls, segmentation and even an air gap, because it crosses the boundary physically rather than over the wire.

Despite years of awareness, USB and removable media remain a leading infection vector in OT, precisely because they are the workaround people reach for when systems are isolated. Reducing the risk means controlling the media and offering safer alternatives for the transfers it is used for.

01Key takeaways

  1. 01

    Removable media bypasses network controls because it crosses the boundary physically, not over the network.

  2. 02

    An air gap does not protect against a USB drive carried across it; isolation can even increase reliance on media.

  3. 03

    Sanitization and scanning kiosks check media at the boundary before it is allowed onto sensitive systems.

  4. 04

    Policy and physical controls limit which media and devices are permitted at all.

  5. 05

    One-way network transfer can replace much of the manual media movement that creates the risk in the first place.

02Why USB is still a top OT vector

Removable media works for attackers because it sidesteps the controls organizations invest in most. A drive does not need a firewall rule or a network path; it needs a person and a port. That makes it effective even against well-segmented environments.

It is also durable as a threat because it is genuinely useful. Updates, configuration files, vendor tools and data exports all move on media when networks are restricted, which keeps ports in use and the vector alive.

Removable media is the boundary crossing your network controls never observe.

03Air-gapped does not mean safe from media

It is tempting to assume an air-gapped system is safe, but the air gap only removes the network path. Every legitimate need to get data in or out of an isolated system tends to be met with removable media, which means isolation can increase media use rather than reduce it.

Notable industrial incidents have shown malware reaching isolated systems through media. The lesson is not that air gaps are useless, but that they must be paired with control over the physical transfers that inevitably cross them.

04Sanitization and scanning kiosks

A common control is to require all media to pass through a scanning and sanitization station before it touches a sensitive system. The kiosk checks the media for known threats and can extract only the intended files into a clean form.

  • Scan incoming media at the boundary before it is allowed inward.
  • Extract and reconstruct only the needed files rather than trusting the original.
  • Block or quarantine media that fails checks.
  • Keep a record of what media was introduced, by whom and when.

Kiosks reduce risk but depend on discipline: they only help if every piece of media actually goes through them.

05Policy and physical controls

Technical scanning works best alongside rules about what is permitted in the first place. Limiting which devices and media are allowed shrinks the problem before it reaches a kiosk.

  • Permit only approved, controlled media and disallow personal devices.
  • Disable or physically restrict unused ports on sensitive systems.
  • Define clear procedures for how data may be brought in or taken out.
  • Train staff and vendors so the safe path is also the easy path.

06One-way transfer as the network alternative

Much removable-media use exists only because there is no safe network path. People reach for a USB drive because the alternative is no transfer at all. Providing a controlled network path removes that reason.

A one-way or scheduled connection can carry the routine transfers that media is used for, safely. An AIRGAPNET controlled connectivity pattern can open a path for an approved data or update window and close it again, so a clean, auditable transfer replaces the sneakernet that introduced the risk.

When the safe network path is genuinely available, reliance on removable media falls, and with it the vector that bypasses every other control.

07Removable media control checklist

  • Is all media required to pass through scanning and sanitization before use?
  • Are only approved devices and media permitted, with personal devices disallowed?
  • Are unused ports on sensitive systems disabled or physically restricted?
  • Is there a record of what media was introduced, by whom and when?
  • Have the routine transfers that drive media use been replaced with a controlled network path?
  • Do staff and vendors have a safe path that is also convenient?

08Closing thought

Removable media endures as a threat because it is both dangerous and useful. It crosses boundaries that nothing else can, and people rely on it precisely where networks are most restricted.

Control the media with scanning, policy and physical limits, but also remove the reason it is used by providing a safe, controlled network path for routine transfers. The most effective way to reduce USB risk is to make the safe path the easy one.

FAQFrequently asked questions

Why is removable media still a major OT risk?

Removable media bypasses network controls because it crosses the boundary physically rather than over the wire. It is also genuinely useful for updates, tools and data exports, especially where networks are restricted, which keeps the vector alive.

Does an air gap protect against USB threats?

No. An air gap removes the network path but not the physical one. Because every legitimate transfer to an isolated system tends to use media, isolation can actually increase media use, and malware has reached air-gapped systems this way.

What is a media sanitization kiosk?

It is a station that all removable media must pass through before touching a sensitive system. The kiosk scans the media for threats and can extract only the intended files in a clean form, blocking or quarantining anything that fails checks.

How do policy and physical controls help?

They reduce the problem before it reaches a kiosk by permitting only approved media, disallowing personal devices, disabling or restricting unused ports, and defining clear procedures for bringing data in or out.

How does one-way transfer reduce removable media use?

Much media use exists only because there is no safe network path. Providing a one-way or scheduled connection for routine transfers gives people a clean, auditable alternative, so reliance on USB drives falls along with the risk they carry.

SRCSources of record

Make the safe path the easy path

Replace the USB workaround with a controlled transfer.

Provide a one-way or scheduled network path for the routine transfers that drive removable-media use, so a clean, auditable transfer replaces the sneakernet.

Related article

Continue the thread Protecting Backup Repositories from Ransomware with One-Way Replication and Disconnection