NCSC Ransomware-Resistant Backup Principles
How Firevault maps to the National Cyber Security Centre principles for backups that survive a destructive attack. Principle by principle, with the architectural answer for each.
- Offline by default
- Identity locked access
- Hardware encrypted

5
NCSC principles for ransomware-resistant backups
Layer 1
Where Offline Secure Storage disconnects, below the network
0
Network interfaces on the gold copy while offline
Backups Are the Target
NCSC publishes its principles freely at ncsc.gov.uk, alongside the guidance Offline backups in an online world. Together they describe what an offline copy must do to survive an attacker who has already reached the production estate. NCSC does not certify products, so the framing here is alignment, not certification.
This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.
- 5 — NCSC principles for ransomware-resistant backups. Source: NCSC, Principles for ransomware-resistant cloud backups
The Five NCSC Principles
Each line below is something an assessor, regulator or underwriter can ask you to evidence.
Backups should be resilient to destructive actions
A backup system should be configured so that it is not possible to deny customers access to their data
The system should allow you to restore from a backup of last resort
The actions required to access backups should be sufficiently distinct from day to day actions
Backups should be regularly tested
Where Online Backup Falls Short
What happens when the control is missing, and the record cannot be produced.
Destructive Actions Reach Backups
An attacker inside production can reach any target that still has a network interface.
Access Can Be Denied
Cloud backup consoles can be locked out, billing-suspended or abused through the identity layer.
No Distinct Access Path
If restoring uses the same credentials as day to day work, an intruder inherits the path.
Object Lock Is Not Offline
Immutable buckets remain reachable over the provider API and depend on software policy.
Five NCSC Principles, Five Firevault Answers
Offline Secure Storage is purpose-built around the same threat model NCSC describes: physical disconnection, a separate management plane and audited restore.
Resilient to Destructive Actions
The gold copy sits on hardware physically disconnected at Layer 1. A destructive action cannot reach a target with no network interface or IP address.
Access Cannot Be Denied
A separate management plane and customer-held identity factors mean no single account compromise can deny access to the data.
Backup of Last Resort
The gold copy sits offline in carefully selected colocation bunkers, brought online only inside an identity-verified connection window.
Distinct From Day to Day
Access needs a scheduled physical connection, a separate identity and out-of-band approval, not production credentials.
Regularly Tested
Recurring verification windows bring the copy online, checksum-verify it and restore in part, with every test event logged.
Tamper-Evident Evidence
Every connection, disconnection, identity verification and restore is recorded for regulators, insurers and board reporting.
“A destructive action on production cannot reach a target that has no network interface. That is the whole argument, and it is a physical one.”
Mark Fermor, Founder, Firevault
What the Gold Copy Holds
The records most often moved into Offline Secure Storage® for this framework.
Immutable gold copies of critical systems
Backup catalogues and recovery keys
Regulated records with retention duties
Configuration and infrastructure state
Restore verification evidence
Audit trails for insurers and regulators
Layer 1, not Layer 2
Hardened repositories and immutable buckets sit on the network and depend on software policy. Offline Secure Storage sits below the network at the physical layer, so the control cannot be bypassed in software because there is no software path while offline.
Evidence packs, not assertions
Principles only matter if you can prove them. Firevault produces per-event logs with identity captured, packaged as evidence regulators, insurers and boards now ask for.
Alignment, not certification
NCSC does not certify products. Firevault maps its architecture to each published principle and to the NCSC guidance Offline backups in an online world, then hands over the evidence so you can make the case yourself.
Alongside 3-2-1-1-0
3-2-1-1-0 is the operational rule of thumb. The NCSC principles describe the properties that offline copy needs to actually resist a destructive attack. Firevault is designed to satisfy both.



Tell us which framework you are being tested against.
We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.
From £360 a month including VAT. 36-month commitment. First payment at checkout.
NCSC blog post, offline backups in an online world
Mapped to the NCSC rules for offline backups
The National Cyber Security Centre publishes its guidance Offline backups in an online world freely at ncsc.gov.uk. It sets out what an offline copy must do to survive an attacker who already holds the production estate. Offline Secure Storage® is built around that same threat model. The four published rules below are paraphrased and paired with the Firevault architectural answer, in the NCSC order.
NCSC rule, paraphrased
The offline rule
At any given time, are one or more backups offline?
Only connect a backup to live systems when necessary, and never have every backup connected at the same time.
How Offline Secure Storage answers it
Offline Secure Storage® automates the offline state at Layer 1. The gold copy has no active interface or address between separately controlled, identity-verified connection windows.
Control by Firevault modules
- Unlink
- Relay
- Lock
NCSC rule, paraphrased
The recovery rule
Is the data in cloud backups restorable and recoverable?
Keep the ability to return to a known-good state if ransomware reaches a backup.
How Offline Secure Storage answers it
Controlled restore windows allow an authorised recovery from the offline copy. Verification and restore events are logged before the physical path closes again.
Control by Firevault modules
- Validate
- Relay
- Archive
NCSC rule, paraphrased
The 3-2-1 rule
Is critical data saved in multiple backup locations?
Keep at least three copies, on two devices, with one copy offsite, while recognising that 3-2-1 alone does not require an offline copy.
How Offline Secure Storage answers it
Firevault supplies the genuinely offline copy of last resort alongside operational and immutable backups. It is held in a carefully selected bunker in the customer's chosen jurisdiction.
Control by Firevault modules
- Archive
- Transfer
- Isolate
NCSC rule, paraphrased
The regular rule
Is critical data backed up regularly?
Create backups regularly and test them to confirm that recovery works as expected.
How Offline Secure Storage answers it
Recurring verification windows bring the copy online, checksum-verify the data, restore in part and disconnect again. Every test is a logged event.
Control by Firevault modules
- Execute
- Validate
- Archive
Alignment, not certification
NCSC does not certify products or endorse suppliers. Firevault maps its architecture to the published blog post and hands over the connection and restore evidence, so a UK organisation can make the case to its own auditors, insurers and board.