
Alan Stewart-Brown at Opengear explains the role of independent management planes in enhancing network resilience
In the rapidly-advancing realm of digital technology, cyber-security has transitioned from a peripheral concern to a central element of organisational strategy. The emergence of sophisticated cyber-threats, coupled with their growing prevalence, has compelled entities to rethink and reinforce their defensive mechanisms.
More than half of companies (53%) across eight countries that were surveyed for the Hiscox Cyber Readiness Report 2023 said they had experienced a cyber-attack over the previous 12 months, up from 48% in the year prior. The figures show that overall cyber-attacks have risen for the fourth year in a row.
Organisations pay the price for this in terms of increased downtime, which impacts business continuity; in costs from lost business and regulatory fines; and with adversely impacted reputation. In a recent global study by Opengear polling CIOs, only 9% stated that they don’t experience any network outages at all, with 81% saying that they experience between 1-4 outages in an average quarter and a further 10% stating that 5-10 outages occur in a quarter.
As businesses continue to suffer from frequent network outages, the research also found that as many as 94% of CIOs identify cyber-security as a major threat to their organisation.
Ransomware remains one of the most serious and difficult-to-counter cyber-threats facing organisations today. It was ranked by 37% of CIOs among the biggest cyber-security threats to their organisation in the Opengear survey, second only to malware, identified by 38%.
In Sophos’s The State of Ransomware 2023 report, 53% of organisations impacted by an attack took more than a week to recover from it. Typically, once a ransomware breach occurs, it rapidly proliferates throughout the system, swiftly identifying and exploiting any vulnerabilities present. One of the biggest system weaknesses that have the potential to exacerbate the impact of ransomware attacks is in-band management.
Numerous organisations operate a management network which is dependent on their production network. In the event of an attack, this interdependence hinders the ability to rapidly disconnect or segregate systems for cleansing, reconstruction, and restoration. Moreover, if attackers have maintained a presence in the network, there’s a high probability of backup compromise, which can, in turn, significantly impede swift recovery.
So how can the threat of ransomware and other associated cyber-crime best be addressed? And how can organisations achieve network resilience in the face of these threats? Cyber-security products play a crucial role in thwarting attacks, but equally vital is an organisation’s recovery capability.
Recent ransomware incidents have led entities like Cyber-security and Infrastructure Security Agency (CISA), the FBI, and assorted NetSecOps experts globally to pinpoint isolation as a fundamental strategy against such threats.
Addressing what has been identified as the pervasive issue of open management ports, CISA has issued a binding operational directive, which requires US Federal Government organisations to create an Isolated Management Infrastructure (IMI), underscoring its importance in bolstering defenses against ransomware.
In countering these threats, extensive, high-quality staff training is key in empowering employees to identify and avoid threats caused by phishing and malicious emails. Regular system patching is also crucial in tackling the security vulnerabilities highlighted here, ensuring that organisations are better protected against new kinds of ransomware, or other malware injected into the network.
Further to this, the use of an independent management plane or IMI offers a way forward. In this scenario, serial console servers are used to open up an alternate path via the independent management plane for remediation of both physical and virtually-connected network devices. In the case of cyber-attack, engineers are empowered to lock down specific elements of the network and restrict access from any location before bringing them back online again when the threat has receded.
During an incident caused by ransomware or other malware, for example, engineers are able to disable access to impacted network equipment via the console port, thereby isolating the incident.
Servers can be shut down to protect private data until the breach has been remediated. WAN connections can also be disconnected to isolate a breach, and if it’s not possible to regain control of network assets, they can power off via remote PDU control capabilities. Devices can additionally be reconfigured to factory defaults and the configuration can be rebuilt via the console port or independent network management connection.
Cyber-security: from remediation and recovery to the everyday
The increasing sophistication and frequency of cyber-attacks, particularly ransomware, necessitate a multifaceted approach to cyber-security. Organisations must blend robust cyber-security products with effective recovery capabilities to establish a resilient network.
The adoption of an independent network management plane or Isolated Management Infrastructure (IMI) emerges as a critical component in this strategy. By enabling network engineers to remotely manage and restore network operations through a secure, separate path, IMIs offer a robust defence mechanism against pervasive cyber-threats.
However, the useful applications of an IMI extend far beyond recovery and remediation to also encompass everyday cyber-security measures and best practice. By segregating the management network from the production network, IMIs inherently limit access and connectivity to critical infrastructure, thereby significantly reducing attack surfaces.
This independent management network can enforce more stringent access controls, apply tailored network policies, and facilitate enhanced logging and scanning of traffic.
Leveraging a separate management network allows for precise configuration, auditing, security scanning, and timely updating of critical infrastructure components. Access to essential devices is meticulously controlled through the isolated management network, with critical connections often limited to point-to-point serial connections.
This air-gapped connectivity method further minimises IP access vulnerabilities, fortifying the network’s defences against unauthorised access.
Moreover, the management network infrastructure plays a vital role in the regular backup and storage of device configurations and logged events. This includes comprehensive records of access attempts, ensuring swift remediation and restoration of an uncompromised configuration state in the aftermath of an incident.
Such meticulous logging is instrumental for thorough after-action analysis, providing invaluable insights into the events leading up to, during, and following a cyber-incident.
This IMI-focused approach is designed to ensure resilient access to network resources, aiding in the prevention, mitigation, and efficient recovery from cyber-attacks, even when standard access methods are compromised. It not only significantly enhances the organisation’s ability to respond swiftly and effectively to incidents but also establishes a safeguard against potential system-wide compromises.
As the digital threat landscape continues to evolve, the role of independent network management planes in bolstering network resilience cannot be overstated.
Alan Stewart-Brown is VP EMEA, Opengear
Main image courtesy of iStockPhoto and ivanastar
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543