Compliance, NCSC, Technical Mapping

NCSC Offline Backups Control Module Mapping Guide

A technical mapping of Control by Firevault modules to the NCSC guidance 'Offline backups in an online world'. Each of the four published rules, the architectural answer, the modules involved and the evidence a UK auditor will ask for.

  • Offline by default
  • Identity locked access
  • Hardware encrypted
Framework matrix
Security analyst reviewing an isolated workstation with disconnected cables

4

NCSC rules for offline backups, mapped in full below

9

Control by Firevault modules named in the mapping

Layer 1

Where the disconnection happens, below the network

01The requirement

The NCSC Threat Model Assumes The Attacker Is Already Inside

The National Cyber Security Centre publishes 'Offline backups in an online world' freely at ncsc.gov.uk. Its premise is stark: plan for an attacker who already holds the production estate, including the credentials and tooling that reach ordinary backups. The only copy that survives is one the attacker cannot reach at all. Offline Secure Storage® is built around that same threat model, and Control by Firevault governs the physical path to it. NCSC does not certify products, so this guide is a mapping, not a certification claim.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

02What is tested

The Four NCSC Rules, In The Published Order

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

The offline rule: at any given time, one or more backups are offline

The recovery rule: data in backups is restorable and recoverable to a known-good state

The 3-2-1 rule: critical data is saved in multiple backup locations

The regular rule: critical data is backed up regularly and recovery is tested

03Consequences

Where A Typical Backup Estate Fails The Rules

What happens when the control is missing, and the record cannot be produced.

Every Copy Stays Reachable

Backup servers, snapshots and cloud replicas all hold standing network paths. An attacker with the estate reaches all of them at once.

One Identity System Guards Everything

When backup administration shares the production directory, a single privileged compromise opens the backup too.

Recovery Is Assumed, Not Tested

The NCSC regular rule expects tested restoration. Most estates discover a broken backup only during the incident.

3-2-1 Without An Offline Copy

Three copies on two devices with one offsite still leaves every copy online. The NCSC guidance is explicit that 3-2-1 alone is not enough.

04The architecture

The Control Modules Behind Each Answer

Control by Firevault is the platform that governs when the physical path to Offline Secure Storage opens, who may open it and what happens while it is open. These are the modules the mapping relies on.

“The NCSC guidance describes a copy the attacker cannot reach. We build exactly that copy, and the modules below are how it stays that way.”

Mark Fermor, CTO, CMO & Founder, Firevault

05What sits offline

Evidence The Mapping Produces

The records most often moved into Offline Secure Storage® for this framework.

Logged connection windows with identity verification

Checksum verification records for each test

Partial restore evidence from the offline copy

Version history proving known-good states survive

Jurisdiction and custody records for the offsite copy

Audit packages for insurers, auditors and the board

Read the full rule-by-rule mapping

The alignment section below pairs each NCSC rule with the architectural answer and the exact modules involved.

Pairs with the on-premises principles

The same architecture maps to the six NCSC principles for ransomware-resistant on-premises backups.

Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to the published guidance and hands over the evidence.

Built for UK compliance queries

The mapping gives UK organisations the language to answer auditors, insurers and boards in the NCSC's own terms.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Get started

Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/moVAT included36-month plan

The connection, physically closed

On one side, the production estate with an attacker already inside. On the other, the offline copy behind a physically closed connection. Between them, no path: no interface, no address and no route to follow.

The production estate under attack on one side, the offline vault on the other, with the path between them crossed out

The nine Control by Firevault modules

The offline rule is met by Offline Secure Storage® itself. The offline copy is physically disconnected by default and stays closed between scheduled windows: no interface, no address and no route exist for an attacker inside the production estate to follow. Control by Firevault governs when a window opens, who may open it and what is logged. These are the nine modules, with their official platform icons.

  • Firebreak

    FIRE layer

    Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.

  • Isolate

    FIRE layer

    Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.

  • Relay

    FIRE layer

    Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.

  • Execute

    FIRE layer

    Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.

  • Validate

    VAULT layer

    Checks whether a request, command or approval should proceed before access, action or transfer is allowed.

  • Archive

    VAULT layer

    Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.

  • Unlink

    VAULT layer

    Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.

  • Lock

    VAULT layer

    Restricts access through identity, authority, policy, permission and operational controls.

  • Transfer

    VAULT layer

    Controls how sensitive assets move into, out of or between protected environments through approved paths.

NCSC blog post, offline backups in an online world

Mapped to the NCSC rules for offline backups

The National Cyber Security Centre publishes its guidance Offline backups in an online world freely at ncsc.gov.uk. It sets out what an offline copy must do to survive an attacker who already holds the production estate. Offline Secure Storage® is built around that same threat model. The four published rules below are paraphrased and paired with the Firevault architectural answer, in the NCSC order.

NCSC rule, paraphrased

The offline rule

At any given time, are one or more backups offline?

Only connect a backup to live systems when necessary, and never have every backup connected at the same time.

How Offline Secure Storage answers it

Offline Secure Storage® automates the offline state at Layer 1. The gold copy has no active interface or address between separately controlled, identity-verified connection windows.

Control by Firevault modules

  • Unlink
  • Relay
  • Lock

NCSC rule, paraphrased

The recovery rule

Is the data in cloud backups restorable and recoverable?

Keep the ability to return to a known-good state if ransomware reaches a backup.

How Offline Secure Storage answers it

Controlled restore windows allow an authorised recovery from the offline copy. Verification and restore events are logged before the physical path closes again.

Control by Firevault modules

  • Validate
  • Relay
  • Archive

NCSC rule, paraphrased

The 3-2-1 rule

Is critical data saved in multiple backup locations?

Keep at least three copies, on two devices, with one copy offsite, while recognising that 3-2-1 alone does not require an offline copy.

How Offline Secure Storage answers it

Firevault supplies the genuinely offline copy of last resort alongside operational and immutable backups. It is held in a carefully selected bunker in the customer's chosen jurisdiction.

Control by Firevault modules

  • Archive
  • Transfer
  • Isolate

NCSC rule, paraphrased

The regular rule

Is critical data backed up regularly?

Create backups regularly and test them to confirm that recovery works as expected.

How Offline Secure Storage answers it

Recurring verification windows bring the copy online, checksum-verify the data, restore in part and disconnect again. Every test is a logged event.

Control by Firevault modules

  • Execute
  • Validate
  • Archive

Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to the published blog post and hands over the connection and restore evidence, so a UK organisation can make the case to its own auditors, insurers and board.