Why OSS

Physical Air Gap Storage for Ransomware Protection

Cloud Object Lock is software pretending to be a wall. A physical air gap is the wall. This is the Firevault buyer's guide to Layer 1 offline storage as the gold copy of last resort.

Corridor of offline storage racks inside a Firevault bunker
R2
What it is

Physical Air Gap for Ransomware Protection

Short, declarative definitions to explain why Layer 1 disconnection is the most reliable ransomware defence.

01
Removing the cable, not just the permission

Layer 1 physical disconnect

A physical air gap means there is no electrical path between the storage hardware and any network. At Layer 1 of the OSI model, the cable is simply not connected. No IP address can be assigned, no port can be scanned, and no credential can bridge a gap that exists in copper and fibre rather than in software policy.

  • No network interface when offline
  • No IP, no listener, no API
  • Out of band switching only
02
Gold copy that survives the incident

Physical separation at rest

Firevault Offline Secure Storage keeps your ransomware protection copy on hardware that is physically separated from every production system. While your estate is online and operational, the gold copy is offline. When a connection window is required, it is scheduled, identity verified and audited.

  • Always offline by default
  • Scheduled connection windows
  • Tamper evident audit trail
Where cloud backup falls short

Why Immutable Cloud Backup Is Not Ransomware Proof

The failure modes ransomware operators exploit on the way to your cloud backups.

01
Object Lock and WORM are logical controls

Immutable does not mean unreachable

Cloud backup platforms advertise Object Lock, versioning and WORM as ransomware protection. These are logical controls on a network that remains connected. An attacker who reaches a privileged account can weaken, disable or wait out the policy. The data is still physically reachable.

  • Reachable over the internet
  • Defended by identity and policy
  • Admin compromise defeats logic
02
Identity is the attack surface

Credential theft is the entry point

Modern ransomware operators do not brute force encryption. They phish, buy or steal credentials into cloud consoles. Once inside, backup APIs are the first target. Session tokens, service accounts and cross-account roles all provide a path to the immutable copy.

  • Phished console access
  • Session token theft
  • Backup role escalation
03
Ransomware crews hunt backups first

Backup console targeting

Incident reports from NCSC, CISA and major cyber insurers show a consistent pattern: attackers identify backup infrastructure early, then disable or encrypt it before touching production. A reachable backup console is a single point of failure disguised as protection.

  • Backup infrastructure mapped first
  • Retention rewritten or poisoned
  • Mass deletion before lock window
Why physical air gap wins

Layer 1 Disconnection Removes The Attacker's Prerequisite

Remote ransomware needs a reachable target. Firevault Offline Secure Storage removes the path before the playbook starts.

01
Remote ransomware needs a target

No reachable surface

Every remote ransomware playbook begins by reaching the victim. A physically disconnected Firevault disk has no NIC, no IP and no service to authenticate to. The attacker cannot scan what is not on the network, and cannot authenticate to hardware that is not listening.

  • No NIC, no IP, no listener
  • No credential to compromise
  • Out of band switching only
02
Independent of identity systems

Privilege cannot reattach a cable

Logical immutability collapses when an attacker gains sufficient privilege. Physical disconnection does not depend on privilege at all. No domain admin, storage admin or cloud root account can connect hardware that is physically unplugged. The boundary is physics, not policy.

  • No domain admin path
  • No storage admin abuse
  • Insider risk reduced to physical access
03
The gold copy that outlasts the attack

Survives the rest of your estate

Most organisations keep their existing cloud or immutable backup for fast operational recovery, and add Firevault as the always offline gold copy. When ransomware reaches the hot and warm tiers, the offline copy remains untouched, unchanged and verifiable.

  • Layered alongside cloud backup
  • Tamper evident audit trail
  • Clean restore point of last resort

Compare the approaches

Physical Air Gap vs Immutable Cloud vs Tape vs Logical Air Gap

Five approaches to a ransomware resistant backup copy, side by side on the criteria that decide whether the copy survives the incident.

Approach Reachable surface Admin compromise resistance Recovery speed Cost model Audit evidence
Physical air gap (Firevault OSS) None while offline Physics, not policy Disk speed in scheduled window Fixed monthly, VAT inclusive Tamper evident connection log
Immutable cloud (Object Lock, WORM) Always reachable over the internet Retention weakened or bypassed Egress limited by bandwidth and cost Per GB plus egress and API fees Cloud audit log on same plane
Hardened backup appliance Reachable on management network Repository credentials are the target Fast local restore when intact Capex plus support contracts Appliance log on same plane
Tape rotation None between rotations Physical handling risk Slow, manual, error prone Media, drives, offsite courier Manual chain of custody
Logical air gap (VLAN, firewall) Reachable through misconfiguration Firewall rule change reopens path Fast when policy holds Existing network kit Network device logs

Buyer checklist

Ten Questions to Ask Any Air Gap Storage Vendor

Use this checklist to separate a genuine physical air gap from a marketing term applied to a hardened network appliance.

  • The storage has no network interface enabled while offline (Layer 1, not VLAN)
  • Connection windows are switched out of band, not from the production network
  • Every connect and disconnect event is logged on a separate management plane
  • Chain of custody from ingest to sealed offline state is provable to insurers
  • Fits the 3-2-1-1-0 rule as the one offline copy, not a duplicate hot tier
  • Recovery time meets your RTO when a connection window is scheduled
  • Deployment model matches your risk appetite (on-site, Firevault Bunker, hybrid)
  • Pricing is predictable with no per-GB egress or restore fees
  • Encryption keys are held separately from the storage, not on the same plane
  • The vendor will attend an incident and provide the clean gold copy in person

Where Firevault sits

Mapping to the 3-2-1-1-0 Backup Rule

The modern reading of the 3-2-1 rule adds two numbers that matter after a ransomware event: one offline copy, and zero recovery errors.

3
Copies of your data
2
Different media
1
Copy offsite
1
Copy offline (Firevault)
0
Errors on recovery

Firevault is designed specifically as the fourth number, the one offline copy, so the other four numbers are free to stay online and operational.

Questions

Physical Air Gap Ransomware Protection, Common Questions

Straight answers on how Offline Secure Storage® behaves in practice.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Add an offline gold copy to your ransomware protection

Talk to the Firevault team about layering a physically disconnected gold copy alongside your existing cloud or immutable backup.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy