Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →
Back to Whitepapers
Whitepaper

Mapping Offline Secure Storage to the NCSC Principles for Ransomware-Resistant Backups

A control-by-control mapping of Firevault Offline Secure Storage (OSS) against the NCSC.gov.uk guidance for UK government departments, critical national infrastructure operators, and regulated enterprises.

18 min read
24 pages
Share

The National Cyber Security Centre (NCSC) publishes clear, non-negotiable guidance on how UK organisations should design backups that survive a ransomware attack. The guidance emphasises that at least one backup copy must be genuinely offline and out of reach of an adversary who has taken control of the production estate. This whitepaper maps every NCSC principle for ransomware-resistant backups against Firevault Offline Secure Storage (OSS). It is written for accounting officers, senior information risk owners (SIROs), CISOs, and heads of resilience inside UK central and local government, the NHS, defence, critical national infrastructure, and regulated financial and legal services firms. Principle 1 - Backups should be resilient to destructive action. OSS holds gold-copy records inside a Firevault bunker with no persistent network path from production. An attacker who compromises Active Directory, a hypervisor, or a cloud tenant cannot reach, encrypt, or delete the offline copy. Principle 2 - At least one backup should be offline, off-site and offline-capable. Every OSS deployment satisfies this by design. Access is only possible during scheduled, identity-verified windows via the LUV (Locked User Vault) interface. Outside those windows the media is physically disconnected. Principle 3 - Backups should have a separate identity, authentication and authorisation model. OSS never reuses production identity. Access is bound to hardware-backed passkeys, sanctioned devices, and a separate authorisation flow that cannot be pivoted to from a compromised corporate SSO. Principle 4 - Backups should be regularly tested. OSS ships with structured restore rehearsals, evidence packs suitable for NIS Regulations, DORA and PRA SS1/21 audit, and CAF-aligned reporting for Objectives A to D. Principle 5 - Backups should be monitored, but monitoring must not create an attack path. OSS telemetry is one-way. Health and capacity signals leave the bunker; nothing writeable enters it from the corporate network. The paper also covers the 3-2-1-1-0 rule, the difference between immutable cloud backups and a physical air gap, procurement notes for G-Cloud and DPS frameworks, and a readiness checklist you can take to your next board or audit committee. Request access below to receive the full PDF.

NCSCransomware-resistant backupsUK governmentCNIoffline secure storageCAF3-2-1-1-0air gapresiliencecompliance

Download This Whitepaper

Free access with registration

GDPR Compliant
No spam, ever

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy