Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026HertzUndisclosed stolenUndisclosed records stolen2026NHS ScotlandUndisclosed stolenUndisclosed records stolen2025Marks & Spencer9.4M stolen9.4M records stolen2025PayPal35K stolen35K records stolen2025Co-operative GroupUndisclosed stolenUndisclosed records stolen2025Jaguar Land RoverUndisclosed stolenUndisclosed records stolen2024National Public Data2.9B stolen2.9B records stolen2026HertzUndisclosed stolenUndisclosed records stolen2026NHS ScotlandUndisclosed stolenUndisclosed records stolen2025Marks & Spencer9.4M stolen9.4M records stolen2025PayPal35K stolen35K records stolen2025Co-operative GroupUndisclosed stolenUndisclosed records stolen2025Jaguar Land RoverUndisclosed stolenUndisclosed records stolen2024National Public Data2.9B stolen2.9B records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Why OSS

NIST SP 1339
OT Backup Quick Start Guide

Everything you need to know about the new NIST standard for operational technology backups, what it asks you to do, and why a physically disconnected gold copy is the most direct way to meet it.

1339

In June 2026 the National Institute of Standards and Technology, through the National Cybersecurity Center of Excellence, published NIST Special Publication 1339, the Operational Technology Backup Quick Start Guide. The document is short, but it lands at a moment when industrial ransomware and destructive attacks on OT estates are a board-level risk.

The guide does not introduce new theory. It distils the backup and recovery requirements that already exist in NIST SP 800-82 Rev. 3, NIST SP 1800-11 and the NIST Cybersecurity Framework 2.0 into a single checklist that asset owners, CISOs and plant engineers can use immediately. The core message is that OT backups are not an IT afterthought; they are a safety and resilience control.

What the standard covers

Four work areas that make an OT backup programme defensible

SP 1339 breaks effective OT backup management into four practical areas. Each one needs to be documented, tested and reviewed during recovery exercises.

01
Asset inventory

Identify assets critical to operations

Map every OT device that contains important configurations or supports process operation: PLCs, switches, firewalls, transmitters, actuators, DCS, SCADA servers, VFDs and HMIs. Verify the inventory is current and assign mission criticality to prioritise backup frequency, retention policies and recovery sequence.

PLCs, DCS, SCADAAssign mission criticalityPrioritise recovery sequence
02
Gold data and spares

Identify the backups each asset needs

Capture the files, software, spare parts and documentation needed to restore the environment: program files, logic files, configuration files, I/O lists, firmware, graphics, licence keys, vendor tools, operating system or virtual machine images, and supporting software. Maintain a spare parts plan that meets recovery time objectives and is compatible with the digital backups.

Program and logic filesFirmware and licencesSpare parts plan
03
Process and controls

Manage backup and recovery procedures

Define backup frequency, media and storage locations based on how often information changes and the risk profile of each system. Document OT-specific constraints, route backup-impacting changes through change management, label media, maintain redundant on-site and off-site storage, and protect media from unauthorised access, modification or destruction.

Change management integrationMedia labellingRedundant storage
04
Validation and recovery exercises

Test integrity and restoration

Conduct recurring restore tests on non-production systems to validate backup reliability, practise restoration procedures and verify the functional integrity of the restored system. Use file hashes where feasible, and update backup and restoration processes based on lessons learned during testing.

Recurring restore testsCryptographic hashingUpdate from lessons learned

The goal is not more backups. It is recoverable, verifiable OT data.

Save engineering documents for a layered recovery

A backup of the logic or configuration is not always enough to rebuild a process. SP 1339 reminds organisations to keep supplemental engineering documents in both printed and electronic formats, and to make sure they are available during incident response. These documents can speed up verification, validation and troubleshooting during restoration.

Logic print files
I/O lists
Equipment specification sheets
Safety Requirements Specifications
Control narratives
Cause and Effect matrices
Network diagrams
Wiring diagrams
Historian configurations
How Firevault maps to SP 1339

Offline secure storage that meets the NIST guidance directly

Firevault gives you the protected, redundant, integrity-checked storage that SP 1339 describes, with a physical air gap that removes the attack surface entirely.

01
Physical disconnection

Offline gold copy

SP 1339 asks organisations to maintain the integrity and availability of backups through hashing, encryption and write-once media. Firevault adds a physical air gap: the vault has no network interface while offline, so remote ransomware cannot reach the gold copy.

No NIC while offlineNetwork path removedRansomware-proof by design
02
Evidence for recovery exercises

Tamper-evident audit trail

Every connection, disconnection and access is logged on a separate management plane with identity, timestamp and reason. This gives you the evidence insurers, regulators and board reports expect when you need to prove that a backup remained untouched.

Identity verifiedTimestampedSeparate management plane
03
Protected media

Bunker storage and encryption

Data is stored in hardened bunkers on two physical drives, protected by quantum-resistant encryption, with strict access controls and no shared tenancy. That directly addresses the SP 1339 requirement to protect backup media from unauthorised access, modification or destruction.

Bunker storageTwo physical drivesQuantum-resistant encryption
04
Recovery when you need it

Restore at disk speed

When a recovery exercise or real incident demands it, your OT gold data is available through scheduled, identity-verified connection windows. Restores run at disk speed, not tape speed, and every action is logged for your incident record.

Scheduled connection windowsDisk speed restoreNo tape rotation

Continue reading on OT security, air-gapped storage and ransomware resilience.

NIST SP 1339, common questions

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Bring your OT backups in line with NIST SP 1339

Talk to the Firevault team about a physically disconnected gold copy for your OT/ICS environment, with the audit trail and bunker storage the standard expects.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up
    Get started

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy