The backup is encrypted too.
Attackers target backup infrastructure first because it is connected, credentialed and discoverable.
Attack patternRansomware finds backups because backups are connected. Hold your gold copies on dedicated hardware that is physically disconnected, so the recovery path does not share the fate of the estate it is meant to restore.
Backups that are visible to the network are part of the attack surface. Physical disconnection changes that.
Attackers target backup infrastructure first because it is connected, credentialed and discoverable.
Attack patternThe most recent restore point carries the same compromise, so recovery reinfects the estate.
ReinfectionData survives but the sequence, configurations and instructions were never protected alongside it.
DowntimeThe decision is made under pressure because no independent recovery path exists.
Business riskRansomware does not need to defeat your recovery copies if it can simply follow a network path to them. Changing the connection state of the data changes what an attacker can reach at all.
If the data is physically outside the connected environment, a remote attacker cannot simply follow a network path to it.
Select → Secure → Disconnect → Access when requiredWhen the drive is disconnected there is no route, no share, no credential and no console for an intruder to abuse.
Immutability, retention locks and access policies are enforced inside the same connected platform an attacker is already inside.
Only the copies you would genuinely rebuild from need to sit outside the estate. Everyday backups keep doing their everyday job.
Your restore does not share the fate of the network being restored, so a full rebuild is possible without negotiating.
A gold copy is more than data. It is the clean data plus the configurations, instructions and evidence needed to rebuild with confidence.
Use this to establish what a genuinely independent recovery path would need.
Data → Systems → Records → Runbooks → Keys → EvidenceKeep your operational backups where they help you recover from ordinary failure. Firevault holds the copy that has to survive a deliberate, credentialed attack.
Snapshots and replicas are useful for everyday failure and quick restores.
The copy that matters most is disconnected from the estate it protects.
Access to a gold copy should require a person, an authority and a window rather than a credential that already exists on the network.
Firevault treats connection as an event that has to be requested, authorised and recorded.
A disconnected gold copy improves testing, insurance conversations and board assurance as well as recovery.
Recovery begins from data that was never reachable from the compromised network.
ResilienceProve the sequence works using a copy that is independent of production.
AssuranceDisconnection is a demonstrable measure rather than a policy commitment.
InsuranceExplain exactly which copy would be used and why it survives.
GovernanceSupport NIS2, DORA and NCSC expectations with mapped controls.
ComplianceRecovery does not depend on a platform you do not control.
Supply chainNational guidance and incident reporting both point the same way: a recovery copy that can be reached from the compromised network is a recovery copy at risk.
NCSC guidance on offline backups states that at least one backup should be kept separate from the network, offline and out of reach of an attacker who has compromised the estate.
Read the source NIST SP 1800-11NIST recovery guidance treats isolation of recovery data as a core requirement so that integrity can be restored after a destructive event.
Read the source CISA #StopRansomware GuideCISA advises maintaining offline, encrypted backups of critical data and regularly testing restoration from them.
Read the sourceConcise routes into the industry and audience pages where this need appears most often.
This page is about the exposure. Capacities, access models, specifications and pricing sit on the product pages so you can choose once the requirement is clear.
Offline Secure Storage holds selected copies on dedicated hardware that is physically disconnected until you ask for it.
Why Offline Secure StorageOn-demand access to a digital safe deposit box for recovery sets, gold copies and critical evidence.
A low use vault for runbooks, keys and small recovery essentials accessed on a nominated day.
Scalable offline capacity from 20TB upwards, designed with the solutions team around your requirement.
Defences fail occasionally. A copy that has no network path does not care.
Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.
Each Offline Secure Storage instance is allocated to a specific customer, with dedicated physical capacity and clearly defined ownership. Your data is not pooled, commingled or held within a shared storage estate.
Access begins outside the normal network path. An authorised out-of-band command, such as SMS, controls the physical Layer 1 connection to your #OSS instance. When access is not required, that network path is physically disconnected.
Your #OSS hardware is housed in carefully selected, professionally managed data centres with layered physical security, resilient power and environmental controls. Access is tightly controlled using three-factor authentication, including biometric identification, supported by 24/7 monitoring, restricted access zones and a complete audit trail. Firevault Bunkers provide jurisdictional physical resilience across our international infrastructure.
The goal is an independent recovery path, not another backup product.
Offline Secure Storage from Firevault. Online when you need it. Offline when you do not.
We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy