Secure Data Sharing Over High Threat Networks

Secure Data Sharing Over High Threat Networks


U.S. military and intelligence missions and organizations are increasingly collecting and sharing information over the internet and other networks with varying (or unknown) levels of security. This information sharing is often essential for achieving operational goals, especially in joint and coalition environments. However, sharing data over the internet and other “high threat networks” presents a significant cybersecurity challenge.

In its Raise the Bar guidance, the National Cross Domain Strategy and Management Office (NCDSMO) provides updated standards for protecting secure networks against the risks lurking within high threat networks. Owl Cyber Defense provides an industry-leading line of Cross Domain Solutions that can help military and intelligence organizations meet these new requirements and protect their networks and systems from constantly evolving cyber threats.

Defining “High Threat”

A high threat network is a network in which a known or suspected threat actor is or could be operating. High threat networks may also be networks that lack sufficient cyber security measures, or where the network ownership and security posture is unknown. In a given use case, a high threat network might be the internet, a coalition partner network, or any other network with a lower security classification that is connected to a secure U.S. network.

The use of high threat networks has grown in recent years and is expected to grow further. The NCDSMO’s Raise the Bar guidelines were developed to manage the risks inherent in these connections, and are now impacting missions and organizations that need to transfer data over high threat networks without exposing sensitive information or secure networks to external threats.

Hardware-Enforced Domain Separation

One of the most significant elements in the Raise the Bar guidelines is the requirement that any traffic to or from a high-threat network needs to pass over a hardware-enforced one-way transfer mechanism, such as a data diode.

Hardware-enforced one-way transfer minimizes the risk that a threat actor on a high threat network will be able to access or control a secure network. Unlike software-only firewalls, which are vulnerable to a wide range of exploits, data diodes are deterministic and cannot be made to send data backward across a connection.

In addition, transmission protocols are terminated on the “send” side of a data diode, and only the packet payload is transferred to the “receive” side. On the “receive” side, a new protocol session is established, concealing send-side network information such as MAC addresses. This protocol break also provides protection against Ripple20-style attacks, which conceal malicious data in packet headers rather than payloads. Read our whitepaper to learn more about how to safely connect to high threat networks.

RTB-Ready Cross Domain Solutions

Owl’s Cross Domain Solutions include a data diode for hardware-enforced one-way data transfer. For use cases requiring bidirectional data flow, separate data paths—each incorporating a data diode—enable communication to and from a high threat network.

To learn more about Owl Cross Domain Solutions and how they can help your organization manage the risks of high threat networks, contact us today.

Insights to your Inbox

Stay informed with the latest cybersecurity news and resources.

Oops! We could not locate your form.

Live at DoDIIS 2026: How to Unleash iOS® & iPadOS® Behind the Air Gap

For decades, classified and otherwise air-gapped environments have run on a tradeoff. Once mission personnel step into a secure space, the iOS® and iPadOS® devices they rely on every da...
August 6, 2026
John McKeon Director, Global Partnerships

When the Only Reliable Patch Is Physics: CISA’s PLC Alert and the AI-Accelerated Threat to Water

On July 30, CISA issued an urgent alert to the Water and Wastewater Systems Sector: remove publicly exposed programmable logic controllers and other operational technology from the intern...
August 3, 2026
data center security

Data Center Security: Why “Which Firewall Is Best” Is the Wrong Question 

Search “which data center firewall is best for security” and you’ll get the usual suspects. But most conversations about data center network security still start with the wrong ques...
July 31, 2026