Sources: Google is internally piloting an opt-in program where some employees will be restricted to internet-free PCs to reduce the risk of cyberattacks
- Google is enlisting employees for a pilot program to work without internet access. — The search giant, which is undergoing …
Context & Ripple Effects
This pilot reverses a decade-old bet. In 2015, Google moved its internal apps onto the public internet and shifted security from network-level to device-level trust — connectivity was assumed, and identity was the perimeter. The Advanced Protection Program then hardened the riskiest accounts, first for high-profile users with physical keys and blocked third-party apps (launched in 2017), and later extended so G Suite admins could enroll selected users.
Internet-free PCs go further than any of those steps: instead of trusting devices more, they remove the network entirely for some workers. That lands awkwardly against Google's own distributed-work posture — its work-from-home policy covered nearly 200,000 full-time and contract employees — making this a test of how much isolation a cloud-native workforce will accept.
First-order effects
- Employees who opt in give up web access on those machines, trading day-to-day convenience for a materially smaller phishing and malware surface; Google's security teams gain an air-gapped tier of workstations without touching the rest of the fleet.
Second-order effects
- Rival cloud and search companies facing the same threat model now have a template to copy — expect peer security teams to weigh similar restricted-PC cohorts rather than inventing their own.
- Vendors selling endpoint management and secure-access tooling gain a new buyer category: enterprises carving staff into connected and disconnected tiers.
Third-order effects
- If the pattern holds, enterprise security settles into layered trust — device-level identity for most, physical isolation for the highest-risk roles — partially unwinding the 2015 assumption that everything can live safely on the open internet.
- Opt-in restriction programs like this could become a standard compliance expectation for handling sensitive source code and user data, reshaping how engineering roles are staffed and equipped.
The trend: Enterprise security is swinging back toward isolation, with big tech firms layering air-gapped workstations on top of the device-trust architectures they built for a fully connected workplace.