Explainer·8 September 2026

Everything finance leaders should know about Offline Secure Storage

A CFO-level explainer on Offline Secure Storage®: how to build the loss model before the control decision, what cyber insurance genuinely transfers, how to treat the cost of a physically isolated copy, and the financial records that need to survive a compromised estate.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
6 min read
Share
Everything finance leaders should know about Offline Secure Storage
Explainer

Why it matters

What this means for organisations holding critical data

A CFO-level explainer on Offline Secure Storage®: how to build the loss model before the control decision, what cyber insurance genuinely transfers, how to treat the cost of a physically isolated copy, and the financial records that need to survive a compromised estate.

Finance leaders are asked to fund security without a reliable way to price the risk it removes. Security proposals arrive as capability, not as loss avoided, and the comparison between one control and another becomes a matter of confidence rather than arithmetic.

Offline Secure Storage® is easier to appraise than most security spending, because it addresses a single, quantifiable exposure: the cost of not being able to trade while the estate is rebuilt.

What it is, briefly

Dedicated physical storage on real drives in a secured facility, with no live network path to it. The connection is physically open at Layer 1 and closes only on an authorised out-of-band command, for a defined window. Nothing inside the operating estate can reach it, whatever credentials are compromised.

Build the loss model first

The control decision follows the loss model, not the other way round. Four components are enough to make a defensible case.

Interruption cost per day. Gross margin foregone, plus fixed cost that continues regardless, plus contractual penalties and service credits, plus the cost of manual workaround. Calculate this per business day, by function, because loss is rarely uniform across the organisation.

Duration. How long the rebuild takes from the copy that is actually trustworthy. Not the recovery time objective on paper: the tested figure, or the honest estimate where no test exists. Serious ransomware recoveries are commonly measured in weeks, not hours, and the long tail is data validation rather than restoration.

Remediation and response. Incident response, forensics, legal counsel, regulatory notification, customer communication, credit monitoring where personal data is involved, overtime and contractor cover, and the accelerated replacement of infrastructure that can no longer be trusted.

Second-order cost. Lost pipeline, contractual renegotiation, tender disqualification, insurance repricing at renewal, audit and covenant consequences, and management time diverted for a full quarter.

Multiply exposure by a considered likelihood rather than a vendor statistic, and the number is usually large enough that the control decision is straightforward. The point of the exercise is not precision. It is to hold the loss in the same currency as the spend.

What insurance transfers, and what it does not

Cyber insurance is a valuable instrument that is frequently mistaken for a substitute control.

It typically indemnifies defined first-party and third-party costs after the fact, subject to retention, sub-limits, waiting periods and conditions. It does not restore data, shorten downtime, preserve customer relationships or discharge the director duties that attach to resilience.

Three practical points for finance.

Underwriting now asks about isolation directly. Questionnaires ask whether an offline or immutable copy exists, whether it is segregated from production credentials and whether restores are tested. The answers move premium and retention.

Conditions become claim arguments. Where a policy warrants a control that was not in place, or restore testing that did not happen, the loss is contested at the worst possible moment.

Retention is the real number. The retained layer plus the uninsurable second-order cost is what the balance sheet actually absorbs. Isolation reduces the size of that layer by shortening duration.

How to treat the cost

Offline Secure Storage® is an operating subscription rather than a capital purchase, which keeps the appraisal simple.

Pricing is VAT inclusive, with the first payment taken at checkout and a 36-month commitment. Capacities are fixed by design, so growth means moving up the range on a new commitment rather than incremental sprawl. That fixed shape is useful for budgeting: the cost does not drift with consumption the way metered cloud storage does, and there are no egress charges applied to a recovery that happens under duress.

Compare it against the interruption cost of a single additional day of downtime. In most organisations the annual subscription is smaller than that one day, which is the whole appraisal.

The financial records that need to survive

Finance owns more of the recovery-critical data set than it usually realises. In practice the protected set should include the general ledger and trial balance, statutory and management accounts, payroll and pension records, banking mandates and payment instructions, tax filings and supporting workings, purchase and sales ledgers with supporting documentation, contracts and lease agreements, insurance policies and claims history, board minutes and delegated authorities, and the audit evidence that supports all of it.

The test is not sentimental value. It is whether the organisation could pay its people, collect its debts, satisfy its auditors and prove its position without the record in question.

Retention, deletion and residual liability

Data held is data exposed, and finance carries the consequence when it is exposed. Two disciplines matter.

Retention with intent. Keep what regulation, contract or genuine business need requires, for as long as that requires, and no longer. Every additional year of retained personal data on a reachable system is a liability with no matching asset.

Verifiable deletion. Third parties routinely retain data long after assurances that it was destroyed. Where a record must be retained but not reachable, an isolated copy plus deletion from connected systems reduces exposure without losing the evidence.

The questions to ask internally

What does one day of downtime cost us, by function? What is our tested recovery time from a copy that a compromised administrator could not have touched? What did we tell our insurer about offline copies, and can we evidence it? Which financial records would we be unable to reproduce, and where is the isolated copy? What are we retaining that we no longer need?

Where Firevault fits

Firevault provides Offline Secure Storage® as the isolated copy behind existing backup arrangements, on dedicated drives in Firevault Bunkers, with access controlled from outside the data network and a full audit record of every window. Instances run from LUV at 300GB through Vault at 2TB, 4TB and 8TB, Storage from 20TB and Enterprise from 300TB, with jurisdiction chosen by the customer.

Where to go next

For the whole subject in one place, read Offline Secure Storage®: everything you need to know. For the full financial treatment, see Cyber Risk, Financial Resilience and Recovery. To size an instance and see the cost, use the OSS Concierge.

The finance case does not rest on fear. It rests on the fact that duration drives loss, and an unreachable copy is the only thing that reliably shortens duration.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker

Keep reading

You may also find these useful

Explainer

Offline Secure Storage: everything you need to know

Offline Secure Storage® is dedicated physical storage that has no network path to it until an authorised out-of-band command creates one. This explainer sets out what it is, how it differs from air gaps, tape and immutable cloud storage, what the standards and insurers expect, how access actually works and how to choose the right instance.

Explainer

Everything leaders should know about Offline Secure Storage

A board-level explainer on Offline Secure Storage®: the accountability it answers, the difference between backup and recovery, the questions to put to management, the evidence to expect back, and how to judge whether the organisation could rebuild itself after a serious compromise.

Explainer

Everything technology leaders should know about Offline Secure Storage

A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation differs from logical air gaps and immutability, how access and restore actually work, and how to design a recovery architecture that survives a privileged compromise.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Get started

Protect what matters. Control what moves.

Choose your Vault and check out in minutes. Dedicated hardware, identity-locked to you, physically disconnected when closed.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/moVAT included36-month plan