Physical Air Gap Storage for Ransomware Protection
Cloud Object Lock is software pretending to be a wall. A physical air gap is the wall. This is the Firevault buyer's guide to Layer 1 offline storage as the gold copy of last resort.

Physical Air Gap for Ransomware Protection
Short, declarative definitions to explain why Layer 1 disconnection is the most reliable ransomware defence.
Layer 1 physical disconnect
A physical air gap means there is no electrical path between the storage hardware and any network. At Layer 1 of the OSI model, the cable is simply not connected. No IP address can be assigned, no port can be scanned, and no credential can bridge a gap that exists in copper and fibre rather than in software policy.
- No network interface when offline
- No IP, no listener, no API
- Out of band switching only
Physical separation at rest
Firevault Offline Secure Storage keeps your ransomware protection copy on hardware that is physically separated from every production system. While your estate is online and operational, the gold copy is offline. When a connection window is required, it is scheduled, identity verified and audited.
- Always offline by default
- Scheduled connection windows
- Tamper evident audit trail
Why Immutable Cloud Backup Is Not Ransomware Proof
The failure modes ransomware operators exploit on the way to your cloud backups.
Immutable does not mean unreachable
Cloud backup platforms advertise Object Lock, versioning and WORM as ransomware protection. These are logical controls on a network that remains connected. An attacker who reaches a privileged account can weaken, disable or wait out the policy. The data is still physically reachable.
- Reachable over the internet
- Defended by identity and policy
- Admin compromise defeats logic
Credential theft is the entry point
Modern ransomware operators do not brute force encryption. They phish, buy or steal credentials into cloud consoles. Once inside, backup APIs are the first target. Session tokens, service accounts and cross-account roles all provide a path to the immutable copy.
- Phished console access
- Session token theft
- Backup role escalation
Backup console targeting
Incident reports from NCSC, CISA and major cyber insurers show a consistent pattern: attackers identify backup infrastructure early, then disable or encrypt it before touching production. A reachable backup console is a single point of failure disguised as protection.
- Backup infrastructure mapped first
- Retention rewritten or poisoned
- Mass deletion before lock window
Layer 1 Disconnection Removes The Attacker's Prerequisite
Remote ransomware needs a reachable target. Firevault Offline Secure Storage removes the path before the playbook starts.
No reachable surface
Every remote ransomware playbook begins by reaching the victim. A physically disconnected Firevault disk has no NIC, no IP and no service to authenticate to. The attacker cannot scan what is not on the network, and cannot authenticate to hardware that is not listening.
- No NIC, no IP, no listener
- No credential to compromise
- Out of band switching only
Privilege cannot reattach a cable
Logical immutability collapses when an attacker gains sufficient privilege. Physical disconnection does not depend on privilege at all. No domain admin, storage admin or cloud root account can connect hardware that is physically unplugged. The boundary is physics, not policy.
- No domain admin path
- No storage admin abuse
- Insider risk reduced to physical access
Survives the rest of your estate
Most organisations keep their existing cloud or immutable backup for fast operational recovery, and add Firevault as the always offline gold copy. When ransomware reaches the hot and warm tiers, the offline copy remains untouched, unchanged and verifiable.
- Layered alongside cloud backup
- Tamper evident audit trail
- Clean restore point of last resort
Compare the approaches
Physical Air Gap vs Immutable Cloud vs Tape vs Logical Air Gap
Five approaches to a ransomware resistant backup copy, side by side on the criteria that decide whether the copy survives the incident.
| Approach | Reachable surface | Admin compromise resistance | Recovery speed | Cost model | Audit evidence |
|---|---|---|---|---|---|
| Physical air gap (Firevault OSS) | None while offline | Physics, not policy | Disk speed in scheduled window | Fixed monthly, VAT inclusive | Tamper evident connection log |
| Immutable cloud (Object Lock, WORM) | Always reachable over the internet | Retention weakened or bypassed | Egress limited by bandwidth and cost | Per GB plus egress and API fees | Cloud audit log on same plane |
| Hardened backup appliance | Reachable on management network | Repository credentials are the target | Fast local restore when intact | Capex plus support contracts | Appliance log on same plane |
| Tape rotation | None between rotations | Physical handling risk | Slow, manual, error prone | Media, drives, offsite courier | Manual chain of custody |
| Logical air gap (VLAN, firewall) | Reachable through misconfiguration | Firewall rule change reopens path | Fast when policy holds | Existing network kit | Network device logs |
Buyer checklist
Ten Questions to Ask Any Air Gap Storage Vendor
Use this checklist to separate a genuine physical air gap from a marketing term applied to a hardened network appliance.
- The storage has no network interface enabled while offline (Layer 1, not VLAN)
- Connection windows are switched out of band, not from the production network
- Every connect and disconnect event is logged on a separate management plane
- Chain of custody from ingest to sealed offline state is provable to insurers
- Fits the 3-2-1-1-0 rule as the one offline copy, not a duplicate hot tier
- Recovery time meets your RTO when a connection window is scheduled
- Deployment model matches your risk appetite (on-site, Firevault Bunker, hybrid)
- Pricing is predictable with no per-GB egress or restore fees
- Encryption keys are held separately from the storage, not on the same plane
- The vendor will attend an incident and provide the clean gold copy in person
Where Firevault sits
Mapping to the 3-2-1-1-0 Backup Rule
The modern reading of the 3-2-1 rule adds two numbers that matter after a ransomware event: one offline copy, and zero recovery errors.
Firevault is designed specifically as the fourth number, the one offline copy, so the other four numbers are free to stay online and operational.
Continue reading on the architecture, the standards and the compare set.
Physical Air Gap Ransomware Protection, Common Questions
Straight answers on how Offline Secure Storage® behaves in practice.



Add an offline gold copy to your ransomware protection
Talk to the Firevault team about layering a physically disconnected gold copy alongside your existing cloud or immutable backup.
Takes about 2 minutes. No account needed.