---
title: "Everything technology leaders should know about… | Firevault"
description: "A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders#webpage",
      "url": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders",
      "name": "Everything technology leaders should know about…",
      "description": "A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/assets/oss-for-technology-explainer-hero-CNlr1T-9.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Everything technology leaders should know about Offline Secure Storage",
          "item": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Everything technology leaders should know about Offline Secure Storage",
      "description": "A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation differs from logical air gaps and immutability, how access and restore actually work, and how to design a recovery architecture that survives a privileged compromise.",
      "url": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders",
      "image": "/assets/oss-for-technology-explainer-hero-CNlr1T-9.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-09-08T00:00:00.000Z",
      "dateModified": "2026-09-08T00:00:00.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/knowledge/offline-secure-storage-for-technology-leaders"
      },
      "inLanguage": "en-GB",
      "articleSection": "Explainer",
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The mechanismWhy logical isolation keeps failingHow it sits alongside immutabilityWhere it sits in the architectureWhat belongs in the isolated setHow access and restore work in p…Designing the operating rhythmInstances and sizingWhere to go nextMore

[Knowledge Vault](/learn/knowledge)/ Explainer 

Explainer · 8 September 2026 

# Everything technology leaders should know about Offline Secure Storage

A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation differs from logical air gaps and immutability, how access and restore actually work, and how to design a recovery architecture that survives a privileged compromise.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Foffline-secure-storage-for-technology-leaders)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Foffline-secure-storage-for-technology-leaders&text=Everything%20technology%20leaders%20should%20know%20about%20Offline%20Secure%20Storage%0A%0AA%20CIO%2C%20CTO%20and%20IT%20director%20explainer%20on%20Offline%20Secure%20Storage%C2%AE%3A%20why%20recovery%20fails%20on%20dependencies%20rather%20than%20tooling%2C%20how%20physical%20Layer%201%20isolation%20differs%20from%20logical%20air%20gaps%20and%20immutability%2C%20how%20access%20and%20restore%20actually%20work%2C%20and%20how%20to%20design%20a%20recovery%20architecture%20that%20survives%20a%20privileged%20compromise.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Foffline-secure-storage-for-technology-leaders)[](mailto:?subject=Everything%20technology%20leaders%20should%20know%20about%20Offline%20Secure%20Storage&body=A%20CIO%2C%20CTO%20and%20IT%20director%20explainer%20on%20Offline%20Secure%20Storage%C2%AE%3A%20why%20recovery%20fails%20on%20dependencies%20rather%20than%20tooling%2C%20how%20physical%20Layer%201%20isolation%20differs%20from%20logical%20air%20gaps%20and%20immutability%2C%20how%20access%20and%20restore%20actually%20work%2C%20and%20how%20to%20design%20a%20recovery%20architecture%20that%20survives%20a%20privileged%20compromise.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fknowledge%2Foffline-secure-storage-for-technology-leaders)

![Everything technology leaders should know about Offline Secure Storage](/assets/oss-for-technology-explainer-hero-CNlr1T-9.jpg)

Explainer 

Why it matters

## What this means for organisations holding critical data

A CIO, CTO and IT director explainer on Offline Secure Storage®: why recovery fails on dependencies rather than tooling, how physical Layer 1 isolation differs from logical air gaps and immutability, how access and restore actually work, and how to design a recovery architecture that survives a privileged compromise.

**On this page**[The mechanism](#section-0)[Why logical isolation keeps failing](#section-1)[How it sits alongside immutability](#section-2)[Where it sits in the architecture](#section-3)[What belongs in the isolated set](#section-4)[How access and restore work in p…](#section-5)[Designing the operating rhythm](#section-6)[Instances and sizing](#section-7)[Where to go next](#section-8)

On this page

1.  [The mechanism](#section-0)
2.  [Why logical isolation keeps failing](#section-1)
3.  [How it sits alongside immutability](#section-2)
4.  [Where it sits in the architecture](#section-3)
5.  [What belongs in the isolated set](#section-4)
6.  [How access and restore work in practice](#section-5)
7.  [Designing the operating rhythm](#section-6)
8.  [Instances and sizing](#section-7)
9.  [Where to go next](#section-8)

Recovery rarely fails because the backup product was wrong. It fails on dependencies: identity that has to be rebuilt before anything else can start, a management plane that is itself compromised, a backup catalogue held inside the blast radius, and credentials that live in the estate being restored.

[Offline Secure Storage](/offline-secure-storage)® exists to break one dependency completely, which is the network path between the operating estate and the copy recovery depends on.

## The mechanism

Capacity sits on dedicated physical drives, paired in RAID 1, in a professionally managed facility. There is no live network path to it. The connection is physically open at Layer 1 and is closed only when an authorised out-of-band command requests it, for a defined and time-limited window, then opened again.

The control path is separate from the data path, so it cannot be reached from the estate. There is no standing IP address to resolve, no listening service to enumerate, no management API exposed to production, and no policy object that a privileged account can rewrite.

## Why logical isolation keeps failing

The word "air gap" now covers three materially different designs, and the difference decides the outcome of an incident.

**Logical.** VLANs, firewall rules, separate tenancy, virtualisation. Configuration, and therefore changeable by whoever holds the right privileges.

**Operational.** A path that exists but is scheduled closed for part of the day. Smaller window, same path.

**Physical.** No connection at Layer 1. Nothing to reconfigure, because no configured path exists.

Real incidents turn on this. Attackers who reach recovery infrastructure usually arrive with valid administrative credentials rather than malware, then use the platform as designed: delete snapshots, shorten retention, disable jobs, revoke immutability where the platform allows it. MITRE ATT&CK documents the pattern as Inhibit System Recovery, T1490, and recommends keeping recovery copies off system.

## How it sits alongside immutability

Immutable storage protects the state of an object for a retention period. It is a genuine and valuable control, and it should be used.

What it does not do is remove the environment around the object: identities, APIs, policy engines, retention configuration and a network route. Immutability protects the copy. Physical isolation controls the path to it. The strongest designs use both, and treat the isolated copy as the last-resort tier rather than the operational one.

## Where it sits in the architecture

Treat it as a tier, not a replacement.

**Tier one, operational recovery.** Local snapshots and fast restores for everyday failure. Minutes to recover, fully connected, high change rate.

**Tier two, resilient backup.** Off-site, immutable where possible, hardened credentials, separate administrative identity. This handles most incidents.

**Tier three, isolated last resort.** Offline Secure Storage®. A defined, curated set rather than the whole estate, written on a deliberate rhythm and reachable only through an out-of-band request. This is what survives the compromise of tiers one and two.

The design discipline is that tier three must not share credentials, identity provider, management plane or automation with tiers one and two. If it does, it is a copy in the blast radius with extra steps.

## What belongs in the isolated set

Curate deliberately. The last known good backup set. Identity system backups, including directory state and the recovery credentials for it. Configuration and infrastructure-as-code needed to rebuild the environment. Golden images and build artefacts. Encryption key material and escrow. The backup catalogue itself. Regulatory and audit evidence. [Intellectual property](/oss-for-intellectual-property) and design data. Financial, payroll and contractual records.

The two most commonly omitted items are the recovery credentials and the configuration required to stand the environment back up. Both are painful to discover missing during an incident.

## How access and restore work in practice

**Request.** An authorised, named user issues an out-of-band command from outside the data network.

**Verification.** The request is authenticated against the named user list on the separate control path.

**Connection.** The Layer 1 path closes and an encrypted, time-limited session is established.

**Use.** Data is written or read at disk speed using standard tooling, so there is no proprietary restore client to learn and no media to mount.

**Disconnection.** The window closes, the path opens again, and the access record is retained.

Because the media is live-capable disk rather than tape, restore begins immediately once the window opens. There is nothing to collect, transport or rehydrate, and no per-gigabyte retrieval charge applied to a recovery that is already under pressure.

## Designing the operating rhythm

Most estates settle into three rhythms: a scheduled write window for the curated set, a periodic restore test with a recorded elapsed time, and an unplanned access request handled by a named authority under change control.

Two engineering rules make this durable. Keep the write path one-directional in intent, so the isolated copy is a destination rather than a mount that production depends on. And test the restore into a clean environment, not back into the estate that produced the data, because that is the condition you will actually face.

## Instances and sizing

The range is capacity-led. LUV is 300GB fixed with a weekly 12-hour access window, suited to an archival set. Vault is 2TB, 4TB or 8TB with access on demand. Storage begins at 20TB in fixed 20TB increments. Enterprise begins at 300TB and is designed around the estate and jurisdiction. Bunkers are live across Europe, including the United Kingdom, with the United States and the Middle East next.

## Where to go next

For the whole subject in one place, read [Offline Secure Storage®: everything you need to know](/learn/knowledge/offline-secure-storage-everything-you-need-to-know). For the architecture treatment, see [Cyber Resilience, Architecture and Recovery](/learn/guides/cio-cto-guide-cyber-resilience), and for the rebuild sequence, [Ransomware Recovery, Backups and Resilience](/learn/guides/it-director-guide-ransomware-recovery). Where the same physical logic needs to apply to operating systems rather than records, see [Control by Firevault](/control).

The engineering summary is short. Every other control asks you to trust that the path is being defended. Removing the path removes the assumption.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Keep reading

## You may also find these useful

[Explainer 

### Offline Secure Storage: everything you need to know

Offline Secure Storage® is dedicated physical storage that has no network path to it until an authorised out-of-band command creates one. This explainer sets out what it is, how it differs from air gaps, tape and immutable cloud storage, what the standards and insurers expect, how access actually works and how to choose the right instance.

](/learn/knowledge/offline-secure-storage-everything-you-need-to-know)[Explainer 

### Everything leaders should know about Offline Secure Storage

A board-level explainer on Offline Secure Storage®: the accountability it answers, the difference between backup and recovery, the questions to put to management, the evidence to expect back, and how to judge whether the organisation could rebuild itself after a serious compromise.

](/learn/knowledge/offline-secure-storage-for-leaders-and-boards)[Explainer 

### Everything finance leaders should know about Offline Secure Storage

A CFO-level explainer on Offline Secure Storage®: how to build the loss model before the control decision, what cyber insurance genuinely transfers, how to treat the cost of a physically isolated copy, and the financial records that need to survive a compromised estate.

](/learn/knowledge/offline-secure-storage-for-finance-leaders)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up