---
title: "NCSC Offline Backups: Control Module Mapping | Firevault"
url: https://fire-vault.com/compliance/ncsc-offline-backups-online-world
description: "Technical mapping of Control by Firevault modules to the NCSC guidance 'Offline backups in an online world'. All four rules, the architectural answers and the…"
lang: en-GB
---

Compliance, NCSC, Technical Mapping

# NCSC Offline Backups Control Module Mapping Guide

A technical mapping of Control by Firevault modules to the NCSC guidance 'Offline backups in an online world'. Each of the four published rules, the architectural answer, the modules involved and the evidence a UK auditor will ask for.

- Offline by default
- Identity locked access
- Hardware encrypted

Framework matrix: https://fire-vault.com/compliance/frameworks

Image: Security analyst reviewing an isolated workstation with disconnected cables (https://fire-vault.com/assets/hero-square-analyst-DI5B7V_E.jpg)

4

NCSC rules for offline backups, mapped in full below

9

Control by Firevault modules named in the mapping

Layer 1

Where the disconnection happens, below the network

01 The requirement

## The NCSC Threat Model Assumes The Attacker Is Already Inside

The National Cyber Security Centre publishes 'Offline backups in an online world' freely at ncsc.gov.uk. Its premise is stark: plan for an attacker who already holds the production estate, including the credentials and tooling that reach ordinary backups. The only copy that survives is one the attacker cannot reach at all. Offline Secure Storage® is built around that same threat model, and Control by Firevault governs the physical path to it. NCSC does not certify products, so this guide is a mapping, not a certification claim.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

- 4 — NCSC rules for offline backups, mapped in full below. Source: NCSC, Offline backups in an online world (https://www.ncsc.gov.uk/blog-post/offline-backups-in-an-online-world)

02 What is tested

## The Four NCSC Rules, In The Published Order

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

The offline rule: at any given time, one or more backups are offline

The recovery rule: data in backups is restorable and recoverable to a known-good state

The 3-2-1 rule: critical data is saved in multiple backup locations

The regular rule: critical data is backed up regularly and recovery is tested

03 Consequences

## Where A Typical Backup Estate Fails The Rules

What happens when the control is missing, and the record cannot be produced.

### Every Copy Stays Reachable

Backup servers, snapshots and cloud replicas all hold standing network paths. An attacker with the estate reaches all of them at once.

### One Identity System Guards Everything

When backup administration shares the production directory, a single privileged compromise opens the backup too.

### Recovery Is Assumed, Not Tested

The NCSC regular rule expects tested restoration. Most estates discover a broken backup only during the incident.

### 3-2-1 Without An Offline Copy

Three copies on two devices with one offsite still leaves every copy online. The NCSC guidance is explicit that 3-2-1 alone is not enough.

04 The architecture

## The Control Modules Behind Each Answer

Control by Firevault is the platform that governs when the physical path to Offline Secure Storage opens, who may open it and what happens while it is open. These are the modules the mapping relies on.

“The NCSC guidance describes a copy the attacker cannot reach. We build exactly that copy, and the modules below are how it stays that way.”

Mark Fermor, CTO, CMO & Founder, Firevault

05 What sits offline

## Evidence The Mapping Produces

The records most often moved into Offline Secure Storage® for this framework.

Logged connection windows with identity verification

Checksum verification records for each test

Partial restore evidence from the offline copy

Version history proving known-good states survive

Jurisdiction and custody records for the offsite copy

Audit packages for insurers, auditors and the board

### Read the full rule-by-rule mapping

The alignment section below pairs each NCSC rule with the architectural answer and the exact modules involved.

### Pairs with the on-premises principles

The same architecture maps to the six NCSC principles for ransomware-resistant on-premises backups.

### Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to the published guidance and hands over the evidence.

### Built for UK compliance queries

The mapping gives UK organisations the language to answer auditors, insurers and boards in the NCSC's own terms.

NCSC ransomware-resistant backups: https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups

NCSC on-premises backup principles: https://fire-vault.com/compliance/ncsc-on-premises-backups

Control by Firevault: https://fire-vault.com/control

All compliance frameworks: https://fire-vault.com/compliance

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-aWtKNSv7.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## The connection, physically closed

On one side, the production estate with an attacker already inside. On the other, the offline copy behind a physically closed connection. Between them, no path: no interface, no address and no route to follow.

Image: The production estate under attack on one side, the offline vault on the other, with the path between them crossed out (https://fire-vault.com/__l5e/assets-v1/7db485e7-d9b8-4755-83b5-611dbdffa864/offline-separation-concept.png)

## The nine Control by Firevault modules

The offline rule is met by Offline Secure Storage® itself. The offline copy is physically disconnected by default and stays closed between scheduled windows: no interface, no address and no route exist for an attacker inside the production estate to follow. Control by Firevault governs when a window opens, who may open it and what is logged. These are the nine modules, with their official platform icons.

- Firebreak
  FIRE layer
  Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.
- Isolate
  FIRE layer
  Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.
- Relay
  FIRE layer
  Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.
- Execute
  FIRE layer
  Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.
- Validate
  VAULT layer
  Checks whether a request, command or approval should proceed before access, action or transfer is allowed.
- Archive
  VAULT layer
  Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.
- Unlink
  VAULT layer
  Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.
- Lock
  VAULT layer
  Restricts access through identity, authority, policy, permission and operational controls.
- Transfer
  VAULT layer
  Controls how sensitive assets move into, out of or between protected environments through approved paths.

NCSC blog post, offline backups in an online world

## Mapped to the NCSC rules for offline backups

The National Cyber Security Centre publishes its guidance Offline backups in an online world (https://www.ncsc.gov.uk/blog-post/offline-backups-in-an-online-world) freely at ncsc.gov.uk. It sets out what an offline copy must do to survive an attacker who already holds the production estate. Offline Secure Storage® is built around that same threat model. The four published rules below are paraphrased and paired with the Firevault architectural answer, in the NCSC order.

NCSC rule, paraphrased

### The offline rule

At any given time, are one or more backups offline?

Only connect a backup to live systems when necessary, and never have every backup connected at the same time.

How Offline Secure Storage answers it

Offline Secure Storage® automates the offline state at Layer 1. The gold copy has no active interface or address between separately controlled, identity-verified connection windows.

Control by Firevault modules

- Unlink
- Relay
- Lock

NCSC rule, paraphrased

### The recovery rule

Is the data in cloud backups restorable and recoverable?

Keep the ability to return to a known-good state if ransomware reaches a backup.

How Offline Secure Storage answers it

Controlled restore windows allow an authorised recovery from the offline copy. Verification and restore events are logged before the physical path closes again.

Control by Firevault modules

- Validate
- Relay
- Archive

NCSC rule, paraphrased

### The 3-2-1 rule

Is critical data saved in multiple backup locations?

Keep at least three copies, on two devices, with one copy offsite, while recognising that 3-2-1 alone does not require an offline copy.

How Offline Secure Storage answers it

Firevault supplies the genuinely offline copy of last resort alongside operational and immutable backups. It is held in a carefully selected bunker in the customer's chosen jurisdiction.

Control by Firevault modules

- Archive
- Transfer
- Isolate

NCSC rule, paraphrased

### The regular rule

Is critical data backed up regularly?

Create backups regularly and test them to confirm that recovery works as expected.

How Offline Secure Storage answers it

Recurring verification windows bring the copy online, checksum-verify the data, restore in part and disconnect again. Every test is a logged event.

Control by Firevault modules

- Execute
- Validate
- Archive

### Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to the published blog post and hands over the connection and restore evidence, so a UK organisation can make the case to its own auditors, insurers and board.

- Offline backups in an online worldNCSC, ncsc.gov.uk: https://www.ncsc.gov.uk/blog-post/offline-backups-in-an-online-world
- Backing up your dataNCSC, ncsc.gov.uk: https://www.ncsc.gov.uk/collection/small-organisations-guide-to-cyber-security/backing-up-your-data
- Mitigating malware and ransomware attacksNCSC, ncsc.gov.uk: https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/compliance/ncsc-offline-backups-online-world#webpage",
    "url": "https://fire-vault.com/compliance/ncsc-offline-backups-online-world",
    "name": "NCSC Offline Backups: Control Module Mapping",
    "description": "Technical mapping of Control by Firevault modules to the NCSC guidance 'Offline backups in an online world'. All four rules, the architectural answers and the…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/compliance/ncsc-offline-backups-online-world#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/compliance/ncsc-offline-backups-online-world#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Compliance",
        "item": "https://fire-vault.com/compliance"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "NCSC Offline Backups: Control Module Mapping",
        "item": "https://fire-vault.com/compliance/ncsc-offline-backups-online-world"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```