Use cases
OSS Use Cases

Gold Copy Backups Beyond Ransomware Reach

Ransomware operators delete every backup they can reach before they encrypt. A gold copy held behind a physical air gap is the one backup they cannot touch.

Why OSS

93%

Of ransomware attacks specifically target backup infrastructure before encrypting production systems.

Source: Sophos State of Ransomware 2024

Threats addressed

Encryption of primary and backupAttacker deletion of snapshotsImmutable-store bypassFailed restore under pressure
01The problem

Why the current setup leaves this data exposed.

Ransomware operators know that backups are the last line of defence. That is why 93% of attacks specifically target backup infrastructure before encrypting production systems. Cloud-connected backups are reachable, and therefore encryptable. Network-attached storage sits on the same network as the threat. Once backups are gone, the organisation has no choice but to pay.

02How it plays out

The scenario, and what physical disconnection changes.

One realistic sequence of events, then the controls that break it.

Scenario

A mid-size firm's entire network is encrypted overnight. The attackers had already compromised the cloud backup account and deleted all snapshots before triggering the ransomware. The NAS device on the local network was encrypted alongside production servers. With no clean backup available, the firm faced a £1.5M ransom demand and 34 days of downtime.

Protection

  • Gold copies stored on physically air-gapped media, no network path exists for ransomware to reach them
  • Tamper-evident storage with 24/7 physical monitoring ensures backup integrity
  • Rapid recovery, gold copies are always intact, verified, and ready for restoration
  • Scalable from terabytes to hundreds of terabytes of critical data
03The outcome

Ransom paid. Hours, not weeks, to restore.

Zero

With gold copies stored offline in Firevault OSS, the firm restored operations within hours instead of weeks. No ransom was paid, no data was lost, and the board could demonstrate to regulators that proper technical measures were in place.

The only backup an attacker cannot encrypt is the one they cannot reach.

Hardware

The data sits on Firevault hardware, not a shared cloud tenancy.

Disconnect

Offline by default. No standing network path in or out.

Command

Access opens on your instruction, identity checked and logged.

Location

Held in a Firevault Bunker. Firevault provisions the location unless you request one in writing.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy