UK Government campaign response, 2026

Lock the door. Then take the crown jewels off the network.

Cyber Essentials reduces common routes into connected systems. Offline Secure Storage® changes what an attacker can still reach if those systems are compromised.

  • Cyber Essentials aligned
  • Physically disconnected by default
  • UK CNI-grade Bunkers
What changes when the asset is offline
Internetattack path
Connectedsystems
Physical
break
Offlineasset
No standing network path to the stored assetWhen offline, the storage is physically disconnected. Access is deliberately established only when required.
Disconnected

Firevault supports Cyber Essentials. Offline Secure Storage is an additional resilience layer, not a replacement for baseline cyber controls.

Source: UK Government, DSIT and NCSC, 17 February 2026
01
Estimated annual cost of cyber threats to UK businesses
£14.7bnEstimated annual cost of cyber threats to UK businesses
02
Small firms experienced a breach or attack in the last 12 months
1 in 2Small firms experienced a breach or attack in the last 12 months
03
Of medium and large businesses suffered a cyber incident
82%Of medium and large businesses suffered a cyber incident
04
Fewer insurance claims reported by organisations with Cyber Essentials
92%Fewer insurance claims reported by organisations with Cyber Essentials
01Defence and resilience

Cyber Essentials protects the connected estate. #OSS protects what does not need to stay connected.

The stronger idea is not one or the other. It is to make the connected environment harder to compromise, while reducing how much critical data remains continuously exposed to it.

01 · Lock the door

Cyber Essentials

Five baseline controls designed to reduce exposure to common attacks across internet-connected systems.

  • 01
    Firewalls

    Control traffic entering and leaving your networks.

  • 02
    Secure configuration

    Remove unnecessary services and insecure defaults.

  • 03
    Software updates

    Reduce exposure to known vulnerabilities.

  • 04
    User access control

    Limit accounts, permissions and privilege.

  • 05
    Malware protection

    Help prevent and contain malicious software.

02 · Reduce what is reachable

Offline Secure Storage®

For data that does not need permanent network exposure, the resilience control is architectural: physically disconnect it by default.

  • 01
    Physical disconnection

    The stored asset has no standing network path while offline.

  • 02
    Dedicated hardware

    Critical assets are held on customer-specific storage, not a shared cloud service.

  • 03
    Controlled access

    Connectivity is deliberately established for approved access, then removed again.

  • 04
    Recovery independence

    Keep clean copies outside the same connected attack path as production.

  • 05
    Evidence of control

    Make offline an operational state you can prove, not just a backup policy.

02The structural question

What can the attacker still reach after the first control fails?

Security programmes often focus on stopping entry. The resilience question starts one step later: if identity, endpoint or network controls are bypassed, what remains inside the same reachable environment?

Typical connected attack pathExample, not a threat model for every organisation
01Identity or endpoint compromised
02Privileges and sessions abused
03Connected storage discovered
04Backups, data or admin planes targeted
05Business impact expands
#OSS changes step 03.

If selected assets are physically offline, compromise of the connected estate does not automatically provide a live path to those copies.

Path removed while offline
03Do not take everything offline

Take the right things offline.

Offline storage works best when it is applied deliberately to the small proportion of data whose loss, theft or corruption would create disproportionate harm.

IP

Intellectual property

Source code, designs, patents, research, engineering files and proprietary methods.

GC

Gold copies

Known-clean recovery data kept outside the connected production and backup estate.

PII

Sensitive personal data

Identity, customer, employee, medical or other high-impact personal records.

BRD

Board and executive records

Strategic documents, confidential decisions, transaction material and governance evidence.

LEG

Privileged and legal material

Client files, litigation evidence, matter archives and other information where confidentiality matters.

OPS

Operational recovery assets

Configuration, runbooks, credentials and documentation needed to recover without the primary environment.

04A layered strategy

Lock the door. Limit the path. Protect the asset. Prove recovery.

A practical sequence, rather than a long comparison between two technologies.

01 / Defend

Implement Cyber Essentials

Start with the five controls the UK Government and NCSC are asking organisations to put in place.

Connected defence
02 / Reduce

Reduce standing access

Remove unnecessary pathways, privileges and always-on access to systems that do not require them.

Attack-surface control
03 / Disconnect

Move crown jewels offline

Physically disconnect selected data and digital assets when they are not being used.

Offline Secure Storage®
04 / Recover

Test independent recovery

Know what you can restore, from where, under whose authority and without relying on the compromised environment.

Business resilience
0560-second check

How exposed are your crown jewels?

Select the statements that are true today. This is a simple discussion aid, not a security assessment.

06Side by side

Defence and resilience solve different parts of the same problem.

The distinction should be simple enough to understand in seconds, without diminishing the value of Cyber Essentials.

Question
Cyber Essentials
Cyber Essentials + #OSS
How do we reduce common attack routes?Five baseline security controls across the connected estate.The same baseline controls remain essential.
What happens if an attacker still gets in?Incident response and recovery controls take over.Selected data can already sit outside the live network path.
Can ransomware reach every recovery copy?Depends on the organisation's backup and access architecture.A physically offline copy has no live network path while disconnected.
Is critical data continuously reachable?May be, depending on the service and configuration.Not when the selected OSS asset is in its offline state.
Important: Offline Secure Storage® is not a substitute for Cyber Essentials.

Cyber Essentials helps protect connected systems from common attacks. Offline Secure Storage is an additional architectural control for selected data that does not need to remain continuously connected.

Campaign source. UK Government, Department for Science, Innovation and Technology and the National Cyber Security Centre, "Businesses urged to lock the door on cyber criminals as new government campaign launches", published 17 February 2026.

Read the GOV.UK source
07The next question

Which data should still be reachable if your connected estate is compromised?

Map your crown jewels, decide what genuinely needs permanent connectivity, and build an offline layer around the assets that do not.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy