NIST SP 800-82r3 OT Backup and Recovery
How Offline Secure Storage® maps to NIST SP 800-82 Rev. 3 for industrial control systems. An offline, 20TB+ gold copy of OT configuration, historian and engineering data for disaster recovery.
- Offline by default
- Identity locked access
- Hardware encrypted

Rev. 3
Current revision of NIST SP 800-82, published September 2023
20TB+
Firevault Storage capacity for historian and engineering archives
0
Network interfaces on the gold copy while offline
OT Recovery Depends On A Copy The Attacker Cannot Reach
NIST SP 800-82 Rev. 3 is the NIST guide to operational technology security. It adapts the SP 800-53 control baselines to OT and stresses segmentation, contingency planning and the ability to restore systems to a known-good state. When ransomware crosses from IT into the plant, recovery depends on backups of PLC logic, HMI projects, historians and engineering workstations that were never reachable from the compromised network. NIST does not certify products, so the framing here is alignment.
This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.
- Rev. 3 — Current revision of NIST SP 800-82, published September 2023. Source: NIST CSRC, SP 800-82 Rev. 3
NIST SP 800-82r3 Themes The Offline Copy Must Support
Each line below is something an assessor, regulator or underwriter can ask you to evidence.
Contingency planning and system backup (CP-9) for OT assets
Information system recovery and reconstitution (CP-10) to a known-good state
Boundary protection and segmentation between IT and OT zones (SC-7)
Protection of backup information from unauthorised modification
Separate, controlled access paths for privileged recovery actions
Audit and accountability for every recovery event (AU family)
Where Typical OT Backup Falls Short
What happens when the control is missing, and the record cannot be produced.
Backups Live On The Plant Network
A backup server reachable from Level 3 is reachable by ransomware that has crossed the IT/OT boundary.
Shared Domain Credentials
When OT backup administration shares the enterprise directory, one privileged compromise reaches both.
No Known-Good Baseline
Without retained earlier copies of PLC logic and HMI projects, rebuild means reverse engineering the plant.
USB And Laptop Workarounds
Engineers carrying backups on removable media creates its own infection and custody risk.
NIST SP 800-82r3, Answered At Layer 1
Offline Secure Storage® keeps the OT gold copy physically disconnected below the network, with Control by Firevault governing when and how the path opens.
System Backup Offline (CP-9)
OT backups land on dedicated hardware that is disconnected at Layer 1 between identity-verified windows.
Recovery To Known-Good (CP-10)
Multiple point-in-time copies of controller logic, HMI projects and historians are retained for clean rebuild.
Segmentation Preserved (SC-7)
The physical path closes after each window, so the backup never becomes a permanent bridge between zones.
Protected From Modification
With no network interface while offline, destructive or encrypting actions have no path to the copy.
20TB To 300TB+ Capacity
Firevault Storage and Enterprise hold full historian archives and engineering images, not just configuration files.
Evidence For Every Event
Each connection, identity check and restore is logged and packaged for auditors, insurers and regulators.
“In a plant, recovery is the controller logic you kept somewhere the attacker could never reach. That place has to be physically offline.”
Mark Fermor, CTO, CMO & Founder, Firevault
What The OT Gold Copy Holds
The records most often moved into Offline Secure Storage® for this framework.
PLC and controller logic
HMI and SCADA project files
Historian archives
Engineering workstation images
Network and firewall configurations
Safety system documentation
Pairs with the Purdue model
The offline copy sits outside every Purdue level while disconnected, and connects only to a defined zone during a controlled window.
Pairs with Control by Firevault
Control Blueprints govern the physical path, including Firebreak hardware that closes the connection in the event of an incident.
Alignment, not certification
NIST does not certify products. Firevault maps its architecture to the published guidance and hands over the evidence.
Also relevant to NIS and NERC CIP
The same offline copy supports UK NIS obligations and NERC CIP recovery plan requirements for operators of essential services.



Tell us which framework you are being tested against.
We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.
From £360 a month including VAT. 36-month commitment. First payment at checkout.