Offline Secure Storage® (#OSS) for ransomware resilience

Offline Secure Storage for clean recovery copies. Beyond the reach of the attack.

Ransomware finds backups because backups are connected. Hold your gold copies on dedicated hardware that is physically disconnected, so the recovery path does not share the fate of the estate it is meant to restore.

Physically disconnectedGold copy protectionImmutable by stateTested recovery
Offline Secure Storage for clean recovery copies.
Offline by default
What stays out of reach

The copy ransomware cannot touch.

Gold copyLast known good
SystemsConfiguration and images
RecordsRegulated data
RunbooksRecovery instructions
KeysCredential material
EvidenceIncident evidence
StorageDedicated hardware
AccessControlled by you
When closedNo standing network path
A simple recovery question

If the estate were encrypted tonight, is there a copy the attacker could not reach?

Backups that are visible to the network are part of the attack surface. Physical disconnection changes that.

01

The backup is encrypted too.

Attackers target backup infrastructure first because it is connected, credentialed and discoverable.

Attack pattern
02

The snapshot is already infected.

The most recent restore point carries the same compromise, so recovery reinfects the estate.

Reinfection
03

Recovery takes weeks.

Data survives but the sequence, configurations and instructions were never protected alongside it.

Downtime
04

You pay to get moving.

The decision is made under pressure because no independent recovery path exists.

Business risk
The Firevault principle

The problem is not just ransomware. It is what ransomware can reach.

Ransomware does not need to defeat your recovery copies if it can simply follow a network path to them. Changing the connection state of the data changes what an attacker can reach at all.

If the data is physically outside the connected environment, a remote attacker cannot simply follow a network path to it.

Select → Secure → Disconnect → Access when required

A path that does not exist cannot be used

When the drive is disconnected there is no route, no share, no credential and no console for an intruder to abuse.

Software controls still run on software

Immutability, retention locks and access policies are enforced inside the same connected platform an attacker is already inside.

Selection matters more than volume

Only the copies you would genuinely rebuild from need to sit outside the estate. Everyday backups keep doing their everyday job.

Recovery becomes independent

Your restore does not share the fate of the network being restored, so a full rebuild is possible without negotiating.

The recovery checklist

Protect the things recovery actually depends on.

A gold copy is more than data. It is the clean data plus the configurations, instructions and evidence needed to rebuild with confidence.

Your recovery inventory

Six areas most estates overlook.

Use this to establish what a genuinely independent recovery path would need.

Data → Systems → Records → Runbooks → Keys → Evidence
The data

Gold copies

  • Last known good data
  • Critical databases
  • Regulated records
  • Historic archives
  • Verified integrity checks
The systems

Build material

  • Golden images
  • Configuration files
  • Infrastructure definitions
  • Licence evidence
  • Dependency maps
The plan

Runbooks

  • Recovery sequence
  • Contact trees
  • Supplier details
  • Decision authority
  • Tested procedures
The access

Credential material

  • Break-glass information
  • Recovery instructions
  • Escrow references
  • Administrative authority
  • Out-of-band contacts
The obligations

Regulated evidence

  • Retention-bound records
  • Reporting evidence
  • Audit trails
  • Contractual commitments
  • Insurance requirements
The aftermath

Incident evidence

  • Forensic images
  • Log exports
  • Timeline records
  • Communications
  • Lessons and remediation
The Firevault difference

Online backup is not the same as offline protection.

Keep your operational backups where they help you recover from ordinary failure. Firevault holds the copy that has to survive a deliberate, credentialed attack.

Everyday and connected

Keep operational backup where it helps.

Snapshots and replicas are useful for everyday failure and quick restores.

  • Daily snapshots
  • Replication between sites
  • Short-term retention
  • Live failover copies
  • Everyday restore points
Important and offline

Give the gold copy a different state.

The copy that matters most is disconnected from the estate it protects.

  • Clean gold copies
  • Golden images and configurations
  • Recovery runbooks
  • Regulated retained records
  • Incident and forensic evidence
Immutability policies live inside systems an attacker may control. Physical disconnection does not.Online when you need it. Offline when you do not.
Controlled recovery, not open access

The recovery path should be deliberate.

Access to a gold copy should require a person, an authority and a window rather than a credential that already exists on the network.

VERIFIED OWNER
RECOVERY LEAD
AUDITOR OR INSURER
SUCCESSION ROUTE
Connection happens inside an authorised window. Selected data can be released without exposing the whole vault. Every retrieval is recorded.
No standing credential

Disconnection is the control. Access is the exception.

Firevault treats connection as an event that has to be requested, authorised and recorded.

Windowed connectionData is reachable during the access window you nominate rather than continuously.
Authority before accessRetrieval is tied to a verified individual rather than an infrastructure account.
Evidence of restorationAccess records support insurer, regulator and board reporting after an incident.
This is not only about the worst day

Useful long before an incident.

A disconnected gold copy improves testing, insurance conversations and board assurance as well as recovery.

Live incident

Rebuild from a copy nobody touched.

Recovery begins from data that was never reachable from the compromised network.

Resilience
Recovery testing

Test restoration properly.

Prove the sequence works using a copy that is independent of production.

Assurance
Insurance renewal

Show a control that is physical.

Disconnection is a demonstrable measure rather than a policy commitment.

Insurance
Board reporting

Answer the recovery question.

Explain exactly which copy would be used and why it survives.

Governance
Regulatory review

Evidence operational resilience.

Support NIS2, DORA and NCSC expectations with mapped controls.

Compliance
Supplier failure

Survive somebody else's incident.

Recovery does not depend on a platform you do not control.

Supply chain
Who this applies to

Sectors where the recovery copy is the last line.

Concise routes into the industry and audience pages where this need appears most often.

The Firevault response

Offline Secure Storage®, then the product that fits the volume.

This page is about the exposure. Capacities, access models, specifications and pricing sit on the product pages so you can choose once the requirement is clear.

Offline Secure Storage®

Offline Secure Storage holds selected copies on dedicated hardware that is physically disconnected until you ask for it.

Why Offline Secure Storage

Vault

On-demand access to a digital safe deposit box for recovery sets, gold copies and critical evidence.

Explore Vault

LUV

A low use vault for runbooks, keys and small recovery essentials accessed on a nominated day.

Explore LUV

Storage

Scalable offline capacity from 20TB upwards, designed with the solutions team around your requirement.

Explore Storage
Why Firevault

Detection on top. Physical separation underneath.

Defences fail occasionally. A copy that has no network path does not care.

01

Physical storage

Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.

02

Physical ownership

Each Offline Secure Storage instance is allocated to a specific customer, with dedicated physical capacity and clearly defined ownership. Your data is not pooled, commingled or held within a shared storage estate.

03

Physical control

Access begins outside the normal network path. An authorised out-of-band command, such as SMS, controls the physical Layer 1 connection to your #OSS instance. When access is not required, that network path is physically disconnected.

04

Physical security

Your #OSS hardware is housed in carefully selected, professionally managed data centres with layered physical security, resilient power and environmental controls. Access is tightly controlled using three-factor authentication, including biometric identification, supported by 24/7 monitoring, restricted access zones and a complete audit trail. Firevault Bunkers provide jurisdictional physical resilience across our international infrastructure.

Questions security teams ask

Before you rebuild your recovery plan.

The goal is an independent recovery path, not another backup product.

Immutability is enforced by software inside a connected platform. Firevault removes the network path entirely when the vault is offline.
Recovery that does not depend on the network under attack

Start with the copy you would actually rebuild from.

Offline Secure Storage from Firevault. Online when you need it. Offline when you do not.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy