NCSC On-Premises Backup Principles, Mapped
How Firevault maps to the National Cyber Security Centre principles for ransomware-resistant on-premises backups. All six principles, each with the architectural answer and the evidence a UK auditor, insurer or board will ask for.
- Offline by default
- Identity locked access
- Hardware encrypted

6
NCSC principles for ransomware-resistant on-premises backups
Layer 1
Where Offline Secure Storage disconnects, below the network
0
Network interfaces on the gold copy while offline
Attackers Go For The On-Premises Copy First
NCSC publishes its Ransomware-resistant backups collection freely at ncsc.gov.uk. It notes that in the early stages of a destructive ransomware attack, actors often target backups and infrastructure, deleting or destroying the data stored there to make recovery harder and payment more likely. The on-premises principles set out the functions a backup solution must offer before it can be described as resistant to destruction by ransomware. NCSC does not certify products, so the framing here is alignment, not certification.
This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.
- 6 — NCSC principles for ransomware-resistant on-premises backups. Source: NCSC, Principles for ransomware-resistant on premises backups
The Six NCSC On-Premises Principles
Each line below is something an assessor, regulator or underwriter can ask you to evidence.
Make it possible to isolate your backup solution
Update your backup solution
Backups should be resilient to destructive actions
Restoration from an earlier backup is possible, even if later versions become corrupted
Have in place robust key management for data-at-rest protection
Alerts are triggered if significant changes are made, or privileged actions attempted
Where A Typical On-Premises Estate Falls Short
What happens when the control is missing, and the record cannot be produced.
The Backup Server Stays On The Network
A backup appliance that is always reachable is always a target. Segregation reduces the odds, it does not remove the path.
Shared Identity And Shared Keys
When backup administration lives inside the same directory as production, one privileged compromise reaches both the data and its keys.
Only The Latest Copy Survives
Short retention or replicated corruption removes the earlier clean state, which is exactly what a long dwell time attack relies on.
Immutability Is Still Software Policy
Hardened repositories and object lock remain addressable over an API and depend on software enforcing the rule.
Six Principles, Six Firevault Answers
Offline Secure Storage® is built around the same threat model NCSC describes: physical disconnection at Layer 1, a separate management plane, hardware encryption and audited restore.
Isolation That Is Physical
While offline the gold copy holds no network interface and no address. Connection is a scheduled, identity-verified event, not a permanent state.
Maintained By Firevault
Firmware and platform updates are applied inside controlled windows, and the exposed surface stays small because there is nothing on the network to attack while a vault is offline.
Resilient To Destructive Actions
Production credentials, domain rights and hypervisor rights grant nothing on the offline copy, so deletion and encryption have no path to it.
Earlier Clean States Retained
Multiple point-in-time gold copies stay offline, so a clean earlier version can be restored when the latest is suspect. Restores are checksum-verified.
Keys Held Away From The Data
Hardware encryption at rest with customer-held identity factors, governed through a management plane separate from the systems being protected.
Out-Of-Band Alerting And Logs
Every connection, disconnection, identity verification, privileged action and restore is logged and alerted, then packaged as evidence.
“An on-premises backup that still answers on the network is still in scope for the attack. Isolation has to be a physical fact, not a firewall rule.”
Mark Fermor, Founder, Firevault
What The On-Premises Gold Copy Holds
The records most often moved into Offline Secure Storage® for this framework.
Immutable gold copies of critical systems
Backup catalogues and recovery keys
Regulated records with UK retention duties
Configuration and infrastructure state
Restore verification evidence
Audit trails for insurers and regulators
On-premises and cloud are separate principle sets
NCSC publishes two sets in the same collection, one for on-premises solutions and one for cloud-based services. This page covers the on-premises set. The cloud principles, and the guidance Offline backups in an online world, are mapped on the sibling page.
Layer 1, not Layer 2
Hardened repositories and immutable buckets sit on the network and depend on software policy. Offline Secure Storage® sits below the network at the physical layer, so the control cannot be bypassed in software because there is no software path while offline.
Evidence packs, not assertions
Principles only matter if you can prove them. Firevault produces per-event logs with the identity captured, packaged as the evidence UK regulators, insurers and boards now ask for.
Alignment, not certification
NCSC does not certify products or endorse suppliers. Firevault maps its architecture to each published principle, then hands over the evidence so your organisation can make the case itself.



Tell us which framework you are being tested against.
We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.
Takes about 2 minutes. No account needed.
NCSC, principles for ransomware-resistant on premises backups
Six principles, mapped one by one
The National Cyber Security Centre publishes Principles for ransomware-resistant on premises backups freely at ncsc.gov.uk, as page two of its Ransomware-resistant backups collection. The principles describe the functions an on-premises backup solution must offer before it can be considered resistant to destruction by ransomware actors. Each principle below is paired with the Firevault architectural answer, in the NCSC order.
Principle 1
Make it possible to isolate your backup solution.
The threat NCSC describes
NCSC warns that leaving a backup solution reachable by more users and devices than necessary lets an attacker pivot from a compromised device into the backups.
How Firevault answers it
Isolation is physical, not policy. Offline Secure Storage® sits disconnected at Layer 1, so while offline it holds no interface and no address for an attacker to reach. Data ingress and the management plane are separate paths, and connection is an event inside a scheduled, identity-verified window rather than a permanent state.
Principle 2
Update your backup solution.
The threat NCSC describes
Unpatched backup software and appliances are a known route in, because the vulnerable service usually sits on the same network as the data it protects.
How Firevault answers it
Firevault owns the patching of the storage estate and the management plane, and the exposed surface stays small by design: there is nothing to attack across the network while a vault is offline. Firmware and platform updates are applied inside controlled maintenance windows and recorded as events.
Principle 3
Backups should be resilient to destructive actions.
The threat NCSC describes
In the early stages of a destructive attack, actors delete or wipe backup data so recovery is harder and the ransom more likely to be paid.
How Firevault answers it
A destructive action cannot reach a target with no network interface. Deletion, encryption and retention changes are not available from production credentials, domain rights or hypervisor rights, because none of those grant anything on the offline copy.
Principle 4
Restoration from an earlier backup is possible, even if later versions become corrupted.
The threat NCSC describes
If only the most recent copy survives, silent corruption or an attacker who dwelled for weeks removes the ability to recover a clean state.
How Firevault answers it
Multiple point-in-time gold copies are retained offline, so a clean earlier state can be selected when the latest copy is suspect. Restores can be partial, and each restore is checksum-verified before the vault disconnects again.
Principle 5
Have in place robust key management for data-at-rest protection.
The threat NCSC describes
Encryption at rest protects nothing if the keys sit alongside the data or inside the same identity system the attacker already holds.
How Firevault answers it
Encryption is performed in hardware at rest, and customer-held identity factors govern access through a management plane that is separate from the production estate. Keys are never held on the systems being protected.
Principle 6
Alerts are triggered if significant changes are made, or privileged actions attempted.
The threat NCSC describes
Without alerting, a quiet change to retention, replication or privilege is only discovered when a restore is attempted and fails.
How Firevault answers it
Every connection, disconnection, identity verification, privileged action and restore is logged and alerted out of band. The same record set is packaged as evidence for auditors, insurers and board reporting.
Alignment, not certification
NCSC does not certify products or endorse suppliers. Firevault maps its architecture to each published principle and hands over the connection, verification and restore evidence, so a UK organisation can make the case to its own auditors, insurers and board.