whitepaper·27 July 2026

Mapping Offline Secure Storage to the NCSC Principles for Ransomware-Resistant Backups

A control-by-control mapping of Firevault Offline Secure Storage against the NCSC guidance on ransomware-resistant backups, written for UK government, CNI operators and regulated enterprises.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
2 min read
Share
whitepaper#OSSOffline Secure Storage®

Article record

whitepaperCategory
27 July 2026Published
2 min readReading time
Mark FermorWritten by
24Pages
18 min readReading time
The National Cyber Security Centre (NCSC) publishes clear, non-negotiable guidance on how UK organisations should design backups that survive a ransomware attack. The guidance emphasises that at least one backup copy must be genuinely offline and out of reach of an adversary who has taken control of the production estate. This whitepaper maps every NCSC principle for ransomware-resistant backups against Firevault Offline Secure Storage (OSS). It is written for accounting officers, senior information risk owners (SIROs), CISOs, and heads of resilience inside UK central and local government, the NHS, defence, critical national infrastructure, and regulated financial and legal services firms. Principle 1 - Backups should be resilient to destructive action. OSS holds gold-copy records inside a Firevault bunker with no persistent network path from production. An attacker who compromises Active Directory, a hypervisor, or a cloud tenant cannot reach, encrypt, or delete the offline copy. Principle 2 - At least one backup should be offline, off-site and offline-capable. Every OSS deployment satisfies this by design. Access is only possible during scheduled, identity-verified windows via the LUV (Locked User Vault) interface. Outside those windows the media is physically disconnected. Principle 3 - Backups should have a separate identity, authentication and authorisation model. OSS never reuses production identity. Access is bound to hardware-backed passkeys, sanctioned devices, and a separate authorisation flow that cannot be pivoted to from a compromised corporate SSO. Principle 4 - Backups should be regularly tested. OSS ships with structured restore rehearsals, evidence packs suitable for NIS Regulations, DORA and PRA SS1/21 audit, and CAF-aligned reporting for Objectives A to D. Principle 5 - Backups should be monitored, but monitoring must not create an attack path. OSS telemetry is one-way. Health and capacity signals leave the bunker; nothing writeable enters it from the corporate network. The paper also covers the 3-2-1-1-0 rule, the difference between immutable cloud backups and a physical air gap, procurement notes for G-Cloud and DPS frameworks, and a readiness checklist you can take to your next board or audit committee. Request access below to receive the full PDF.

Download this whitepaper

Free access with registration

GDPR compliantNo spam

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy