Software Defined Air Gapped Networks
The battle to keep IT and OT (Operational Technology) systems secure from cybercriminals, and to prevent accidental data leakage, is an ongoing task. Malicious adversaries are just as smart as those who seek to protect systems from attack. As protections are put in place then, as night follows day, ways to circumvent them are discovered and used. Increasingly the protection measures and attack methods are changing at a rate and scale, via AI and machine learning, that makes it difficult for humans to keep up.
For the reasons above and many others, providers of security solutions must always be involved in security R&D, so that new protections can be developed and deployed. For us in Renaissance, as a leading supplier of the best security solutions available, this means that we are always surveying the security landscape and market. We do this to identify the best new and emerging solutions so we can add them to our portfolio to deliver the best solutions for our customers.
One such emerging solution is to micro-segment the internal network behind the border firewalls and other traditional security measures. Doing this delivers a software-defined airgap between IT systems and data repositories. Any attacker that breaches the perimeter defences then does not have free run of the internal network. Each micro-segment has separate security requirements for access and is in effect a different security domain. Unisys's Stealth suite of products and services make it easy to implement and deploy micro-segmented network infrastructure. All without increasing the administration and management overhead for IT staff. Renaissance and Unisys can help you design and deploy a Stealth based security solution today. Contact us to find out more, or read on for an overview of microsegmentation and the Stealth product suite.
Network Microsegmentation
Organisations IT, OT, and data networks are not monolithic in nature. They all have many different systems that are providing various services to diverse staff and clients. These systems are also deployed across multiple locations in private data centres, the cloud, and increasingly out on edge networks for IoT and 5G connectivity.
Not everyone within an organisation needs to access all the systems. Most only need access to the IT systems and data that are relevant to their job. The same applies to clients and customers who only need to access the applications and data they need for their interactions with the organisation. This means that networks are already split up from a user point of view into lots of small groups of users and clients that access particular systems. Microsegmentation takes this idea and makes it concrete in software. Each system or datastore is logically isolated within its own micro-network with communication occurring only through authorised channels that are limited to authorised and authenticated users. These micro-networks are invisible to anyone who doesn't need to access them. Unless given explicit access then they logically don't exist on the network.
The same applies to any cybercriminals who breach the perimeter security protections on a network. The breach is sandboxed within the particular micro-segmented portion of the overall network that was compromised. This is especially useful when dealing with ransomware-type attacks that have become so numerous and sophisticated over the last few years. If a user is tricked into following a phishing link and gets their device infected with ransomware, the malware can only spread within the micro-segment that user is on. The rest of the network that the user never uses is invisible to them, and any malware they introduce can't infect it.
Unisys Stealth Products and Services
The Unisys Stealth suite comprises five products that are backed by a Services offering to assist organisations in deploying and operating the solutions. They are:
- Stealth(core)™️ - provides foundational capabilities - identity-based microsegmentation, cryptographic cloaking and encryption of data in motion - for transforming your existing networks into Zero Trust Networks without added implementation and management complexity.
- Stealth(aware)™️ - provides powerful live discovery, modelling, and visualisation to see network relationships to use microsegmentation to isolate trusted entities.
- Stealth(cloud)™️ - easily extends protection across public and private networks. Identity-driven microsegmentation isolates critical assets, and data encryption protects data in motion to reduce attack surfaces on virtual machines.
- Stealth(identity)™️ - establishes trusted identities with multi-modal biometrics - such as fingerprint, iris, facial, and voice recognition - to enhance security with good user experience.
- Stealth(mobile)™️ - extends Stealth(core)™ protection to mobile environments, closing security gaps outside the scope of enterprise mobility management solutions.
- Stealth™️ Services - a range of implementation services to deliver the software-defined security solution that enables you to improve your organisation's security posture while reducing network complexity and cost. The deployment begins with network visibility, policy design & enforcement, and continues with operational control.
Conclusion
Microsegmentation, via Unisys Stealth products, provides an excellent core pillar within an overall network and data security strategy. By limiting access to, and hiding the presence of separate systems within a network, it prevents a perimeter breach from infecting or exposing the whole network. Contact us to see how deploying Stealth can enhance your security posture.

