---
title: "NCSC exposes Iranian spyware targeting dissiden… | Firevault"
description: "The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026#webpage",
      "url": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026",
      "name": "NCSC exposes Iranian spyware targeting dissiden…",
      "description": "The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NCSC exposes Iranian spyware targeting dissidents, activists and journalists",
          "item": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "NCSC exposes Iranian spyware targeting dissidents, activists and journalists",
      "description": "The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages from dissidents, activists and journalists.",
      "url": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-20T06:52:00+00:00",
      "dateModified": "2026-09-20T06:54:46.765939+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/iranian-chosen-brick-targeting-journalists-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Threat Intelligence",
      "wordCount": 1044,
      "keywords": "NCSC, Threat Intelligence, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The UK National Cyber Security Centre has joined the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service in exposing malware used by Iranian state cyber actors against dissidents, activists and journalists. The joint advisory, published on 15 September 2026, names the malware family **CHOSEN BRICK**. The agencies say it has targeted people around the w",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is CHOSEN BRICK?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "CHOSEN BRICK is a Windows malware family that the NCSC, FBI and AIVD say Iranian state cyber actors have used against dissidents, activists and journalists since at least 2025."
          }
        },
        {
          "@type": "Question",
          "name": "What information can CHOSEN BRICK collect?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The joint advisory says it can collect contacts, emails and social media messages, capture screens, exfiltrate data and download additional malware. The related NCSC release says it can reportedly access a device microphone."
          }
        },
        {
          "@type": "Question",
          "name": "Why does this cyber campaign create a physical safety risk?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The NCSC says stolen information could enable the tracking of victims’ movements and that details of some previous victims appeared on pro-Iranian leak sites. It also notes previous plots by Iranian intelligence services against perceived enemies abroad."
          }
        },
        {
          "@type": "Question",
          "name": "Does Offline Secure Storage stop the malware?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Endpoint protection and the NCSC mitigations remain essential. Offline Secure Storage limits what malware on a connected device can reach by keeping retained archives on dedicated hardware with no standing network path."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

Trust is the first attack surfaceWhat CHOSEN BRICK can doThe cyber incident and the safet…The Firevault view: reduce what …Practical actions for at-risk pe…SourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Threat Intelligence · 20 September 2026 · Breaking 

# NCSC exposes Iranian spyware targeting dissidents, activists and journalists

The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages from dissidents, activists and journalists.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

6 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Firanian-chosen-brick-targeting-journalists-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Firanian-chosen-brick-targeting-journalists-2026&text=NCSC%20exposes%20Iranian%20spyware%20targeting%20dissidents%2C%20activists%20and%20journalists%0A%0AThe%20NCSC%2C%20FBI%20and%20Dutch%20intelligence%20service%20have%20exposed%20CHOSEN%20BRICK%2C%20malware%20used%20by%20Iranian%20state%20cyber%20actors%20to%20collect%20contacts%2C%20emails%20and%20messages%20from%20dissidents%2C%20activists%20and%20journalists.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Firanian-chosen-brick-targeting-journalists-2026)[](mailto:?subject=NCSC%20exposes%20Iranian%20spyware%20targeting%20dissidents%2C%20activists%20and%20journalists&body=The%20NCSC%2C%20FBI%20and%20Dutch%20intelligence%20service%20have%20exposed%20CHOSEN%20BRICK%2C%20malware%20used%20by%20Iranian%20state%20cyber%20actors%20to%20collect%20contacts%2C%20emails%20and%20messages%20from%20dissidents%2C%20activists%20and%20journalists.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Firanian-chosen-brick-targeting-journalists-2026)

![A journalist at a Windows laptop facing a targeted surveillance threat, with physically disconnected secure storage in the foreground](/news/iranian-chosen-brick-targeting-journalists-2026.jpg)

A journalist at a Windows laptop facing a targeted surveillance threat, with physically disconnected secure storage in the foreground

Why it matters

## What this means for organisations holding critical data

The NCSC, FBI and Dutch intelligence service have exposed CHOSEN BRICK, malware used by Iranian state cyber actors to collect contacts, emails and messages from dissidents, activists and journalists.

In this analysis

1.  01 [Trust is the first attack surface](#section-0)
2.  02 [What CHOSEN BRICK can do](#section-1)
3.  03 [The cyber incident and the safet…](#section-2)
4.  04 [The Firevault view: reduce what …](#section-3)
5.  05 [Practical actions for at-risk pe…](#section-4)

**On this page**[Trust is the first attack surface](#section-0)[What CHOSEN BRICK can do](#section-1)[The cyber incident and the safet…](#section-2)[The Firevault view: reduce what …](#section-3)[Practical actions for at-risk pe…](#section-4)

The UK National Cyber Security Centre has joined the US Federal Bureau of Investigation and the Netherlands' General Intelligence and Security Service in exposing malware used by Iranian state cyber actors against dissidents, activists and journalists.

The joint advisory, published on 15 September 2026, names the malware family **CHOSEN BRICK**. The agencies say it has targeted people around the world, including in the United Kingdom, United States and Netherlands, since at least 2025.

This is not simply another information-stealing campaign. The NCSC says the malware can collect a target's contacts, emails and social media messages, information that could be used to track their movements. It assesses that Iran almost certainly uses cyber activity to support the repression of people viewed as threats to the regime.

The advisory adds a stark physical dimension. The NCSC says Iranian intelligence services have, in some cases, plotted kidnappings or lethal operations against people abroad whom they perceive as enemies. Personal details belonging to some previous CHOSEN BRICK victims have appeared on pro-Iranian leak sites, potentially increasing risks to their safety.

## Trust is the first attack surface

The campaign begins with careful social engineering rather than a noisy technical exploit. According to the advisory, operators research their intended target and tailor the approach. They may contact a person through WhatsApp or Telegram while impersonating someone the victim knows, or pose as technical support for a trusted platform.

The files are designed to fit the conversation. The agencies observed fake versions of applications including Telegram, Norton Antivirus, KeePass, Pictory and RunwayML. One lure was presented as the result of an MRI scan. The objective is to make opening the file feel reasonable in the moment.

The malware has exclusively targeted Windows devices in the cases the agencies observed. Attackers may first approach a work or corporate machine, then try to move the conversation to a personal device if they believe workplace monitoring makes detection more likely. That shift matters because a personal computer may sit beyond an organisation's managed security controls while still holding access to the same people, sources and conversations.

## What CHOSEN BRICK can do

Once installed, CHOSEN BRICK can establish persistence, weaken Microsoft Defender by adding antivirus exclusions and connect to Telegram for command and control. The NCSC says every victim device uses a unique Telegram Bot ID, an operational-security measure that helps separate one compromise from another.

The malware can capture the screen, exfiltrate data and download further payloads. The related NCSC release says it can reportedly access a device microphone. Information can be sent through Telegram or cloud object-storage services, while newer variants use proxy infrastructure to disguise Telegram traffic.

The agencies have not observed automated lateral movement across a network. That does not make the threat minor. Its focus is the person and the device that holds their relationships. A single carefully selected laptop may contain a journalist's sources, an activist's organising network, travel plans, private correspondence and the identities of people whose exposure carries a real-world consequence.

One sample also contained data-wiping capability. The potential outcome therefore spans surveillance, theft, further compromise and destruction.

## The cyber incident and the safety incident are the same event

Most breach reporting treats names, emails and messages as units in a database. Here, the value of the information lies in what it reveals about people: whom they trust, where they may be, what they intend to publish and who else is connected to them.

For journalists, campaigners, researchers and organisations supporting dissidents, the security question is not only whether a file is encrypted. It is whether there is any standing route from an internet-connected account or endpoint to the retained archive.

Strong authentication, current software, endpoint monitoring and social-engineering awareness remain essential. The NCSC describes awareness training as the best defence against the initial approach and provides technical indicators and mitigations for individuals and network administrators in its full advisory.

Those controls reduce the likelihood of compromise. They cannot make every person infallible, and they cannot turn an always-connected archive into an offline one.

## The Firevault view: reduce what a compromised device can reach

A targeted individual may need email, messaging and research tools online. Historical source material, contact archives, evidence, identity records and completed work do not all need to remain continuously reachable from the same device.

[Offline Secure Storage](/offline-secure-storage)® provides a separate control: dedicated hardware with no standing network path. Access is opened only after an authorised out-of-band request, for a defined period, and then closed again. When the storage is offline, malware on a laptop cannot browse it, copy it, encrypt it or silently use it to map a person's network.

This does not claim to stop CHOSEN BRICK reaching a connected Windows device. Nor does it replace the NCSC's mitigations. It limits the body of sensitive retained information available after an endpoint or account is compromised.

For people facing state-backed surveillance, that distinction is not theoretical. If connected data can reveal a source, contact or movement, keeping the definitive archive physically disconnected can help place a hard boundary between a cyber intrusion and its wider human consequences.

## Practical actions for at-risk people and organisations

-   Read the joint NCSC, FBI and AIVD advisory and use its indicators when investigating a suspected compromise.
-   Treat unexpected support messages and tailored file-sharing approaches with suspicion, even when the sender appears familiar.
-   Verify unusual requests through a separate, known communication channel before opening a file or installing software.
-   Keep Windows, security tools and applications current, and investigate unexpected antivirus exclusions.
-   Separate high-risk browsing and messaging from the systems used to retain source archives and identity material.
-   Keep an offline copy of sensitive records and recovery data that no compromised endpoint can reach.
-   Seek specialist help if you believe the activity may form part of transnational repression or pose a risk to physical safety.

## Sources

-   [NCSC, FBI and AIVD joint advisory: Iranian cyber targeting of dissidents, activists and journalists](https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists), 15 September 2026.
-   [NCSC release: UK and allies expose spyware used by Iranian state actors](https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists), 15 September 2026.

Firevault is not affiliated with or endorsed by the NCSC, FBI or AIVD. Attribution and intelligence assessments in this article are reported as stated by those agencies.

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later](/news/hcrg-care-group-children-records-cyber-attack-2026.jpg)

Breach Analysis 

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min 







](/news/hcrg-care-group-children-records-cyber-attack-2026)[

![Google Gemini AI autonomously hacked three companies during security test](/news/google-gemini-ai-hacked-companies-test-2026.jpg)

AI Security 

### Google Gemini AI autonomously hacked three companies during security test

Google has confirmed that its Gemini AI model autonomously hacked into three companies during a security evaluation, guessing credentials to access systems it believed were part of the test, in what is thought to be the first known case of its kind.

20 Sept 2026 4 min 







](/news/google-gemini-ai-hacked-three-companies-security-test-2026)[

![Sensitive UK police data on Microsoft's cloud judged vulnerable to compromise by the US government and foreign actors](/news/uk-police-data-microsoft-cloud-sovereignty-2026.jpg)

Data Sovereignty 

### Sensitive UK police data on Microsoft's cloud judged vulnerable to compromise by the US government and foreign actors

A Guardian investigation reports that criminal records, victim statements and intelligence files from more than 40 UK police forces sit on Microsoft Azure, on a platform an official police risk assessment judged vulnerable to compromise by foreign actors and to access by United States government insiders.

18 Sept 2026 6 min 







](/news/uk-police-data-microsoft-cloud-sovereignty-risk-2026)[

![FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

Breach Analysis 

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min 







](/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![CenterPoint Energy confirms hackers stole customer data through an exposed API](/news/centerpoint-energy-cyberattack-2026.jpg)

Breach Analysis 

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min 







](/news/centerpoint-energy-confirms-cyberattack-data-theft-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)