High-Level Overview
Airgap Networks is a cybersecurity company that developed an agentless Zero Trust Firewall (ZTF) and isolation platform to prevent lateral threat movement in enterprise networks, particularly for IT/OT/IoT environments. It ring-fences every endpoint into a "network of one" using DHCP proxy and identity-based controls, solving ransomware propagation and segmentation challenges without agents, APIs, or hardware upgrades. Serving enterprises like Dropbox, Tillys, KCAS, and Skyline Enterprises, Airgap targeted critical infrastructure protection, raised $13.4M–$23M in funding, acquired NetSpyGlass in 2023 for enhanced asset visibility, and was acquired by Zscaler in April 2024 to bolster Zero Trust SASE offerings.[1][2][3][6]
The platform provided network segmentation, secure remote access, AI-driven threat detection (e.g., ThreatGPT and ransomware kill switch), and automatic device discovery, enabling fast zero-trust adoption across dynamic, hybrid networks with legacy protocols.[1][2][3][4][5]
Origin Story
Airgap Networks was founded in 2019 in Santa Clara, California, by Ritesh Agrawal (CEO) and colleagues from Juniper Networks, inspired by superior telco-grade security models that isolate subscriber communications at the network level. Agrawal's experience highlighted enterprise LAN vulnerabilities compared to telco networks, where devices cannot communicate directly, prompting the team to adapt these principles for cybersecurity.[1][2][6]
Early traction included seed and Series A funding, development of a ransomware kill switch, and customers like Dropbox and Skyline Enterprises. Key milestones: $4M+ follow-on Series A (total ~$23M), NetSpyGlass acquisition in June 2023 for better device discovery, and full microsegmentation for a major retailer's endpoints, achieving ZTNA for hybrid workforces.[1][2][4]
Core Differentiators
Airgap stood out in zero-trust microsegmentation through these key features:
- Agentless Deployment: Creates isolated "networks of one" via DHCP proxy assigning /32 IP addresses, enabling policy enforcement without software agents, hardware upgrades, or APIs—deployable in minutes across IT/OT/IoT.[2][3][4][5]
- Identity & Context-Based Controls: Uses SSO/MFA for dynamic access, agnostic to ports/protocols (including legacy SMB/RDP), preventing east-west lateral movement even post-breach.[1][3][5]
- Ransomware Kill Switch & Threat Detection: Disables non-essential communications, with AI/ML tools like ThreatGPT for early warnings and NetSpyGlass integration for asset visibility and risky device identification.[1][3]
- Scalability & Visibility: Automatic device discovery/classification baselines traffic patterns; complements existing stacks for enterprises with fluid endpoints, outperforming complex firewalls or VLANs.[3][4][5]
Competitors like Zero Networks, Authentic8, and Elisity offer similar segmentation but lack Airgap's telco-inspired simplicity and speed.[1][2]
Role in the Broader Tech Landscape
Airgap rode the zero-trust architecture wave, accelerated by rising ransomware, IoT proliferation, and hybrid work, where traditional segmentation fails due to dynamic assets and legacy systems. Its timing aligned with Gartner-noted challenges in microsegmentation projects stalling amid complex app mappings, offering a low-cost, scalable alternative modeled on telco networks for global breach rarity.[1][3][4]
Market forces favoring Airgap included OT/IoT security gaps in critical infrastructure and the shift to SASE platforms; its Zscaler acquisition extends zero-trust to east-west traffic, influencing ecosystem-wide adoption by simplifying IT/OT convergence and reducing attack surfaces without operational disruption.[2][3][6]
Quick Take & Future Outlook
Post-acquisition by Zscaler in April 2024, Airgap's tech integrates into a leading SASE leader, amplifying its ransomware kill switch and segmentation for broader enterprise use. Expect enhanced AI-driven insights and OT focus amid escalating threats; trends like AI threat mapping and agentless ZTNA will shape its path, evolving Zscaler's influence in preventing lateral propagation across hybrid ecosystems. This builds on Airgap's foundation as a nimble innovator bringing telco isolation to vulnerable LANs.[2][3]