Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026Lidl GBCustomer contact data (subset via supplier) records stolen2026Asahi GroupProduction systems disrupted records stolen2026Kido InternationalPhotos and personal data of ~8,000 children records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Lidl GBCustomer contact data (subset via supplier) records stolen2026Asahi GroupProduction systems disrupted records stolen2026Kido InternationalPhotos and personal data of ~8,000 children records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Adidas UKCustomer contact details (subset) records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →
Why OSS

Hot Storage vs
Cold Storage

Hot tiers are fast and expensive. Cold tiers are cheap and slow. Both stay on the network. Here is how they compare, and where a physical air gap belongs in the mix.

S1
Definitions

Two Different Access Tiers

Hot and cold storage exist to serve different access patterns. Start with clean definitions before comparing cost and risk.

01
Online, low latency, always reachable

Hot storage

Hot storage keeps data on media that is permanently online and optimised for fast read and write. Think production SSD, primary NAS or a standard cloud object tier. Access is measured in milliseconds and the storage is always addressable over the network.

Millisecond access, high IOPSAlways network reachableHighest cost per terabyte per month
02
Rarely accessed, cost optimised

Cold storage

Cold storage is designed for data that is retained but seldom read. Cloud tiers like AWS Glacier, Azure Archive and Google Coldline lower the price per terabyte in exchange for slower retrieval, minimum retention periods and per gigabyte egress fees. The media itself is still online.

Minutes to hours to retrieveRetention minimums and egress feesMuch lower cost per terabyte
Where they diverge

Performance, Cost and Security Trade-offs

Three trade-offs decide where each tier belongs in your architecture, and where cloud cold storage quietly leaves risk on the table.

01
Latency, throughput and retrieval time

Performance trade-off

Hot tiers return objects in milliseconds and handle heavy concurrent workloads. Cold tiers deprioritise retrieval to save money, so first byte latency can stretch to minutes or hours and rehydration is billed. The right tier depends on how often the data is actually read.

Hot: ms latency, unlimited readsCold: minutes to hours, rehydration feesMatch tier to real access pattern
02
Storage price versus access price

Cost trade-off

Cold storage looks cheap on the storage line but adds early deletion charges, minimum commitment windows and per gigabyte egress when you need the data back. A restore under pressure can cost more than a year of hot storage. Model the full recovery bill, not just the monthly resting price.

Cheap at rest, expensive to recoverMinimum retention windows applyEgress fees dominate incident cost
03
Both tiers stay reachable to the network

Security trade-off

Hot and cold cloud tiers live behind the same identity plane. A compromised admin account, expired MFA or exposed access key can reach either. Object Lock and versioning help, but the storage itself never leaves the network, so remote ransomware and insider actions still have a path.

Same identity plane as productionObject Lock is a logical, not physical, controlRemote path never fully closes
Firevault vs cloud cold storage

The High Security Alternative

Where cloud cold tiers stay online, Firevault keeps the media physically disconnected. It sits alongside hot and immutable storage as the offline gold copy of last resort.

01
No IP, no listener, no reachable target

Physical air gap by default

Firevault Offline Secure Storage keeps the media physically disconnected between scheduled, identity verified access windows. There is no network path for remote attackers to reach, so the class of ransomware that walks through cold cloud tiers has nothing to attack.

Offline between access windowsOut of band management planeImmune to remote credential abuse
02
No egress fees on your gold copy

Predictable retrieval cost

Cold cloud tiers punish the day you actually need the data. Firevault retrieval happens on your own site through your own network on a fixed subscription. There are no per gigabyte egress charges, no rehydration windows and no billing surprises during an incident.

Flat subscription, no egressRetrieve at local network speedRecovery cost known in advance
03
The offline gold copy in 3-2-1-1-0

Fits alongside hot and cold

Firevault is not a replacement for hot production storage or immutable cloud backup. It sits alongside them as the offline copy the 3-2-1-1-0 rule requires, so operational recovery stays fast and the gold copy of last resort stays untouchable.

Keep hot for operationsKeep immutable for fast recoveryAdd offline for the worst day

Read the related guides that put hot, cold and offline storage in context.

Hot vs Cold Storage, Common Questions

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Add an offline gold copy alongside your hot and cold tiers

Talk to the Firevault team about layering a physical air gap under your existing cloud storage strategy.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy