Breaking NewsUpdated as information becomes available
Industry Insight·18 August 2026·Breaking

When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
9 min read
Share
A reinforced secure vault door inside a resilient concrete facility, representing physical data protection during natural disasters and infrastructure failure.
Industry Insight

Article record

Industry InsightCategory
18 August 2026Published
9 min readReading time
Mark FermorWritten by
A reinforced secure vault door inside a resilient concrete facility, representing physical data protection during natural disasters and infrastructure failure.

Why it matters

What this means for organisations holding critical data

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

Wildfire, flood, heat and grid stress are the disruptions that make the news, so continuity planning tends to be written around them. That framing is too narrow. The organisations we work with lose access to their own records for reasons that have nothing to do with weather: a cloud region fails, a subsea cable is cut, a software supplier is breached, an identity provider locks out every user, an administrator deletes the wrong container, a building becomes a crime scene. The cause changes. The consequence does not. Authorised people cannot reach authoritative records at the exact moment those records decide how fast, and how expensively, the organisation recovers.

This is not an argument against cloud computing. It is an argument against single points of failure, and an argument for holding a curated portion of what matters most somewhere that neither nature, accident, negligence nor an attacker can reach across a network.

It Is Not Just the Grid

Continuity is a question of failure domains rather than weather. A plan is only as good as the number of independent domains it can survive. In practice, six categories account for almost every loss of access we review.

  • Environmental. Fire, flood, storm, extreme heat, cooling failure and the power events that follow them. Physical, local, and usually the only category the plan names.
  • Infrastructure and connectivity. Fibre cuts during emergency works, subsea cable damage, carrier outages, routing failures. The data is intact and unreachable at the same time.
  • Platform and provider. A cloud region degraded, a SaaS platform breached, a supplier entering administration, a contract terminated, a tenant suspended for billing or compliance reasons. Concentration risk that no amount of internal engineering removes.
  • Identity and access. A compromised or misconfigured identity provider, an expired certificate, a conditional access rule applied too widely. Every system is running and nobody can log in.
  • Malicious action. Ransomware, extortion without encryption, and destructive attacks that specifically target the backup estate before touching production.
  • Human and legal. Accidental deletion, misapplied retention policies, departing administrators, seizure of equipment, or a site that cannot be entered while an investigation proceeds.

Uptime Institute's annual outage analyses have consistently found power-related failure to be the largest single cause of significant data centre incidents, ahead of networking and cooling (Uptime Institute). The UK National Cyber Security Centre makes the parallel point on the security side, recommending that at least one backup copy be kept offline and separated from the live network, so that an attacker who reaches the network cannot reach the copy (NCSC backup guidance). Two disciplines, environmental resilience and cyber resilience, arrive at the same control: separation.

The Failure Mode Is Always Access, Not Storage

In almost every disruption we review, the data still exists. What fails is the path to it. That distinction matters because most continuity investment goes into making copies, and comparatively little goes into guaranteeing that at least one copy can be reached when the usual route is gone.

A copy that shares a network, an identity system, a provider or a building with the thing it protects is not an independent copy. It is the same risk written twice.

Why Continuity Plans Still Run on Paper

Walk into a serious incident management room and you will find paper. Paper continuity plans, paper call trees, printed recovery runbooks. The reason has nothing to do with nostalgia. Paper does not need electricity. It does not need single sign-on. It cannot be encrypted by ransomware, deleted by a script or suspended by a supplier.

Paper is also a poor long-term control. It burns and floods. It is difficult to keep current, so the version in the folder is rarely the version in force. It cannot be reached by a distributed team. It offers no record of who read what, and when, which matters when a regulator later asks how decisions were made. For decades organisations accepted those weaknesses because the alternative, keeping the same records on connected systems, felt riskier still.

That trade-off is no longer necessary. Offline Secure Storage® delivers what paper delivers, independence from the network, without giving up encryption, version control or an audit trail.

What Belongs Offline

Offline is a tier, not a replacement. Live operations stay on connected systems. Routine backup continues to encrypted cloud storage. A small, deliberately chosen set of records is held on physically disconnected media, refreshed on a schedule and released only through identity verification.

In practice that set is usually short:

  • Recovery material. System recovery keys, configuration baselines, network diagrams, certificate and key escrow material. The items that make rebuilding possible, and which are frequently held only inside the environment being rebuilt.
  • Legal and contractual records. Deeds, leases, executed contracts, share registers, intellectual property filings, matter files where a copy of record is required.
  • Insurance and claims evidence. Policy schedules, asset registers, valuations, condition photographs. Claims move faster when evidence survives the event.
  • Regulatory and audit evidence. Attestations, board minutes, decision logs, retention records that must remain provable after an incident.
  • Identity and continuity data. Emergency contact information, delegated authority records, supplier escalation routes, and the exit material you would need if a provider disappeared.

If a record would change the speed or the cost of your recovery, it is a candidate. If it merely supports daily work, it is not.

The Retrieval Process Is the Product

Storage is the easy half. An offline copy that nobody can retrieve under pressure is a dark archive, and dark archives fail audits as reliably as they fail incidents. The control that makes offline storage credible is the release process: verified identity, dual authorisation where the record justifies it, defined turnaround, and an immutable log of every request and release.

That is the distinction between a disconnected copy and a governed one. It also gives continuity leaders something they can rehearse. A continuity plan that has never tested retrieval has not been tested.

Sector Reality

Different sectors feel the same failure differently.

  • Legal. Matter files, undertakings and deeds carry obligations that survive any outage. Solicitors, partners and paralegals need a copy of record that does not depend on the firm's practice management system, or its hosting provider, being reachable. See Offline Secure Storage® for legal.
  • Accountancy and professional services. Client records, working papers and filing deadlines do not move because a platform failed. Deadlines are statutory; connectivity is not.
  • Energy, water and industrial operations. Where operational technology is involved, recovery depends on engineering material held away from the affected network. This is the same reasoning behind Firevault Control blueprints.
  • Healthcare and education. Continuity of care and continuity of records both depend on documents that remain readable when the estate does not.
  • Boards and directors. Personal liability does not pause during a disruption, whatever caused it. Demonstrable technical measures are part of the defence. See Offline Secure Storage® for directors and boards.

Where This Sits in Recognised Frameworks

None of this is novel. ISO 22301 asks organisations to identify their minimum viable operating requirements and the resources needed to meet them, without limiting the scenarios considered. The 3-2-1-1-0 backup convention, now common in cyber insurance underwriting, asks explicitly for one offline or immutable copy and zero errors on verification, which we cover in the 3-2-1-1-0 rule. The NCSC and FEMA both frame resilience as redundancy across independent failure domains (FEMA continuity guidance).

Physically disconnected storage is simply redundancy applied to the data layer, using a failure domain that a network event cannot cross.

A Question of Responsibility

There is always a temptation, after a disaster, to present a product as the answer to the catastrophe that has just unfolded. That is not the intention here. Firevault was built on the belief that data protection should be physical as well as logical, and that the right moment to prepare for disruption is before it arrives.

Fires and heatwaves are warnings rather than sales opportunities, and they are only one warning among several. They remind us that infrastructure we treat as invisible is physical, contractual and fragile. The organisations that recover fastest will not be the ones with the most subscriptions. They will be the ones that kept a governed copy of what matters in a place that a fire, a fibre cut, a failed provider or a stolen credential cannot reach.

How Do I Know Which Records Belong Offline?

Start from recovery rather than from storage. List the decisions and actions required in the first 72 hours of a serious disruption, then identify the records each one depends on. Anything on that list which exists only inside the environment you would be recovering, or only inside a single provider, belongs offline. Most organisations find the genuine set is far smaller than expected, which makes the control affordable.

Is Immutable Cloud Storage Not the Same Thing?

Immutability protects a copy from being altered or deleted. It does not remove the copy from the network, and it does not survive the loss of the platform, the region, the contract or the credentials that reach it. Immutable cloud storage and offline storage answer different questions, and mature continuity plans use both. The comparison is set out in air gap versus immutable backup.

How Quickly Can Offline Records Be Retrieved?

Retrieval is a governed process rather than an instant read, and that is deliberate. Access requires verified identity and, where appropriate, dual authorisation, with the release logged. The practical point for continuity planning is that retrieval time is known, documented and rehearsable, rather than dependent on whether a network happens to be available.

Does This Only Matter for Large Organisations?

No. Smaller organisations are usually more exposed, because a single site, a single provider or a single administrator often represents the whole estate. A modest offline tier holding recovery keys, contracts and insurance evidence changes the recovery profile of a small firm more than it changes that of a large one.

What to Do Next

The question is not whether your organisation can afford offline storage. It is whether you can afford to discover, during a fire, a flood, an outage, a supplier failure or an attack, that the records you need are on the wrong side of a broken connection.

Two practical steps. First, run the 72-hour exercise above and write down the records list. Second, test retrieval of one of those records this quarter. If either step is difficult, the plan is not yet a plan.

If you would like a second opinion on the records list, talk to a member of the team or create your vault and start with the material you would not want to rebuild.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breaking News
Industry Insight18 August 20269 min read

When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

When Access Fails: Continuity Needs Offline Secure Storage
Mark Fermor
Published by Mark Fermor, Director & Co-Founder