---
title: "NCSC On-Premises Backup Principles Mapped | Firevault"
description: "All six NCSC principles for ransomware-resistant on-premises backups, mapped to Offline Secure Storage. Physical isolation at Layer 1, key management and…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/compliance/ncsc-on-premises-backups#webpage",
      "url": "https://fire-vault.com/compliance/ncsc-on-premises-backups",
      "name": "NCSC On-Premises Backup Principles Mapped",
      "description": "All six NCSC principles for ransomware-resistant on-premises backups, mapped to Offline Secure Storage. Physical isolation at Layer 1, key management and…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/compliance/ncsc-on-premises-backups#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/compliance/ncsc-on-premises-backups#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance",
          "item": "https://fire-vault.com/compliance"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "NCSC On-Premises Backup Principles Mapped",
          "item": "https://fire-vault.com/compliance/ncsc-on-premises-backups"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The requirementThe gapsConsequencesThe architectureWhat sits offline

Compliance, NCSC, United Kingdom 

# NCSC On-Premises Backup Principles, Mapped 

How Firevault maps to the National Cyber Security Centre principles for ransomware-resistant on-premises backups. All six principles, each with the architectural answer and the evidence a UK auditor, insurer or board will ask for.

-   Offline by default
-   Identity locked access
-   Hardware encrypted

Book a mapping call[Framework matrix](/compliance/frameworks)

![Security analyst reviewing an isolated workstation with disconnected cables](/assets/hero-square-analyst-CiP17E_k.jpg)

6

NCSC principles for ransomware-resistant on-premises backups

Layer 1

Where Offline Secure Storage disconnects, below the network

0

Network interfaces on the gold copy while offline

01 The requirement 

## Attackers Go For The On-Premises Copy First

NCSC publishes its Ransomware-resistant backups collection freely at ncsc.gov.uk. It notes that in the early stages of a destructive ransomware attack, actors often target backups and infrastructure, deleting or destroying the data stored there to make recovery harder and payment more likely. The on-premises principles set out the functions a backup solution must offer before it can be described as resistant to destruction by ransomware. NCSC does not certify products, so the framing here is alignment, not certification.

This is a mapping , not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

-   6 — NCSC principles for ransomware-resistant on-premises backups. [Source: NCSC, Principles for ransomware-resistant on premises backups](https://www.ncsc.gov.uk/collection/ransomware-resistant-backups/principles-for-ransomware-resistant-on-premises-backups)

02 What is tested 

## The Six NCSC On-Premises Principles

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Make it possible to isolate your backup solution

Update your backup solution

Backups should be resilient to destructive actions

Restoration from an earlier backup is possible, even if later versions become corrupted

Have in place robust key management for data-at-rest protection

Alerts are triggered if significant changes are made, or privileged actions attempted

03 Consequences 

## Where A Typical On-Premises Estate Falls Short

What happens when the control is missing, and the record cannot be produced.

### The Backup Server Stays On The Network

A backup appliance that is always reachable is always a target. Segregation reduces the odds, it does not remove the path.

### Shared Identity And Shared Keys

When backup administration lives inside the same directory as production, one privileged compromise reaches both the data and its keys.

### Only The Latest Copy Survives

Short retention or replicated corruption removes the earlier clean state, which is exactly what a long dwell time attack relies on.

### Immutability Is Still Software Policy

Hardened repositories and object lock remain addressable over an API and depend on software enforcing the rule.

04 The architecture 

## Six Principles, Six Firevault Answers

Offline Secure Storage® is built around the same threat model NCSC describes: physical disconnection at Layer 1, a separate management plane, hardware encryption and audited restore.

### Isolation That Is Physical

While offline the gold copy holds no network interface and no address. Connection is a scheduled, identity-verified event, not a permanent state.

### Maintained By Firevault

Firmware and platform updates are applied inside controlled windows, and the exposed surface stays small because there is nothing on the network to attack while a vault is offline.

### Resilient To Destructive Actions

Production credentials, domain rights and hypervisor rights grant nothing on the offline copy, so deletion and encryption have no path to it.

### Earlier Clean States Retained

Multiple point-in-time gold copies stay offline, so a clean earlier version can be restored when the latest is suspect. Restores are checksum-verified.

### Keys Held Away From The Data

Hardware encryption at rest with customer-held identity factors, governed through a management plane separate from the systems being protected.

### Out-Of-Band Alerting And Logs

Every connection, disconnection, identity verification, privileged action and restore is logged and alerted, then packaged as evidence.

“An on-premises backup that still answers on the network is still in scope for the attack. Isolation has to be a physical fact, not a firewall rule.”

Mark Fermor, Founder, Firevault

05 What sits offline 

## What The On-Premises Gold Copy Holds

The records most often moved into Offline Secure Storage® for this framework.

Immutable gold copies of critical systems

Backup catalogues and recovery keys

Regulated records with UK retention duties

Configuration and infrastructure state

Restore verification evidence

Audit trails for insurers and regulators

### On-premises and cloud are separate principle sets

NCSC publishes two sets in the same collection, one for on-premises solutions and one for cloud-based services. This page covers the on-premises set. The cloud principles, and the guidance Offline backups in an online world, are mapped on the sibling page.

### Layer 1, not Layer 2

Hardened repositories and immutable buckets sit on the network and depend on software policy. Offline Secure Storage® sits below the network at the physical layer, so the control cannot be bypassed in software because there is no software path while offline.

### Evidence packs, not assertions

Principles only matter if you can prove them. Firevault produces per-event logs with the identity captured, packaged as the evidence UK regulators, insurers and boards now ask for.

### Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to each published principle, then hands over the evidence so your organisation can make the case itself.

[NCSC ransomware-resistant backups](/compliance/ncsc-ransomware-resistant-backups) [Layer 1 vs logical air gap](/learn/physical-vs-logical-air-gap) [Cyber insurance 3-2-1-0](/compliance/cyber-insurance-3-2-1-0) [All compliance frameworks](/compliance)

### Authoritative Sources

-   [NCSC Principles for Ransomware-Resistant On Premises Backups (NCSC) ](https://www.ncsc.gov.uk/collection/ransomware-resistant-backups/principles-for-ransomware-resistant-on-premises-backups)
-   [NCSC Ransomware-Resistant Backups Collection (NCSC) ](https://www.ncsc.gov.uk/collection/ransomware-resistant-backups)

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up 

NCSC, principles for ransomware-resistant on premises backups

## Six principles, mapped one by one 

The National Cyber Security Centre publishes [Principles for ransomware-resistant on premises backups](https://www.ncsc.gov.uk/collection/ransomware-resistant-backups/principles-for-ransomware-resistant-on-premises-backups) freely at ncsc.gov.uk, as page two of its Ransomware-resistant backups collection. The principles describe the functions an on-premises backup solution must offer before it can be considered resistant to destruction by ransomware actors. Each principle below is paired with the Firevault architectural answer, in the NCSC order.

Principle 1

### Make it possible to isolate your backup solution.

The threat NCSC describes

NCSC warns that leaving a backup solution reachable by more users and devices than necessary lets an attacker pivot from a compromised device into the backups.

How Firevault answers it

Isolation is physical, not policy. Offline Secure Storage® sits disconnected at Layer 1, so while offline it holds no interface and no address for an attacker to reach. Data ingress and the management plane are separate paths, and connection is an event inside a scheduled, identity-verified window rather than a permanent state.

Principle 2

### Update your backup solution.

The threat NCSC describes

Unpatched backup software and appliances are a known route in, because the vulnerable service usually sits on the same network as the data it protects.

How Firevault answers it

Firevault owns the patching of the storage estate and the management plane, and the exposed surface stays small by design: there is nothing to attack across the network while a vault is offline. Firmware and platform updates are applied inside controlled maintenance windows and recorded as events.

Principle 3

### Backups should be resilient to destructive actions.

The threat NCSC describes

In the early stages of a destructive attack, actors delete or wipe backup data so recovery is harder and the ransom more likely to be paid.

How Firevault answers it

A destructive action cannot reach a target with no network interface. Deletion, encryption and retention changes are not available from production credentials, domain rights or hypervisor rights, because none of those grant anything on the offline copy.

Principle 4

### Restoration from an earlier backup is possible, even if later versions become corrupted.

The threat NCSC describes

If only the most recent copy survives, silent corruption or an attacker who dwelled for weeks removes the ability to recover a clean state.

How Firevault answers it

Multiple point-in-time gold copies are retained offline, so a clean earlier state can be selected when the latest copy is suspect. Restores can be partial, and each restore is checksum-verified before the vault disconnects again.

Principle 5

### Have in place robust key management for data-at-rest protection.

The threat NCSC describes

Encryption at rest protects nothing if the keys sit alongside the data or inside the same identity system the attacker already holds.

How Firevault answers it

Encryption is performed in hardware at rest, and customer-held identity factors govern access through a management plane that is separate from the production estate. Keys are never held on the systems being protected.

Principle 6

### Alerts are triggered if significant changes are made, or privileged actions attempted.

The threat NCSC describes

Without alerting, a quiet change to retention, replication or privilege is only discovered when a restore is attempted and fails.

How Firevault answers it

Every connection, disconnection, identity verification, privileged action and restore is logged and alerted out of band. The same record set is packaged as evidence for auditors, insurers and board reporting.

### Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to each published principle and hands over the connection, verification and restore evidence, so a UK organisation can make the case to its own auditors, insurers and board.

-   [Principles for ransomware-resistant on premises backupsNCSC, ncsc.gov.uk ](https://www.ncsc.gov.uk/collection/ransomware-resistant-backups/principles-for-ransomware-resistant-on-premises-backups)
-   [Ransomware-resistant backups collectionNCSC, ncsc.gov.uk ](https://www.ncsc.gov.uk/collection/ransomware-resistant-backups)
-   [Offline backups in an online worldNCSC, ncsc.gov.uk ](https://www.ncsc.gov.uk/guidance/offline-backups-in-an-online-world)