NIS2 Compliance with Offline Secure Storage
NIS2 mandates operational resilience for essential and important entities. Offline Secure Storage (OSS) provides physical disconnection as a resilience measure.
We Think This Is Hard to Ignore
M&S was paralysed for months after DragonForce ransomware encrypted systems a third party had access to. NIS2 mandates supply chain resilience and operational continuity. At Firevault, gold copies live on hardware with no network connection, because continuity starts with data that was never reachable during an attack.
£1.9B
Economic cost of JLR ransomware to UK supply chain
The Guardian, October 2025
£300M
Estimated profit loss from M&S ransomware attack
Reuters, 2025
400K+
Patient appointments disrupted by NHS Synnovis attack
NHS England, 2024
72hrs
NIS2 incident notification deadline
NIS2 Directive, Article 23
NIS2 demands operational resilience.
Supply Chain Risk
NIS2 extends requirements to supply chain and third-party providers.
Business Continuity
Entities must ensure service continuity even during cyber incidents.
Incident Response
72-hour notification requirements demand rapid, reliable recovery capabilities.
NIS2-relevant incidents are escalating.
Jaguar Land Rover: £1.9B Economic Cost from Ransomware
A ransomware attack halted production at all JLR factories, sent 30,000 employees home, and affected over 5,000 supply chain businesses. NIS2 would classify this as a critical operational failure.
The Guardian, October 2025
NHS Synnovis: Essential Service Paralysed for Months
A ransomware attack on pathology provider Synnovis disrupted blood tests and operations across major London hospitals for over six months. Under NIS2, this would trigger mandatory notification and investigation.
BBC News, June 2024
M&S: DragonForce Ransomware Shut Down Core Operations
Attackers deployed DragonForce ransomware via a compromised third party, forcing M&S to suspend online orders for months. NIS2 supply chain provisions would apply directly.
Reuters, 2025
Physical resilience for NIS2 compliance.
Offline Secure Storage (OSS) provides physically disconnected backup and recovery capabilities.
- Gold copies physically unreachable during cyber incidents
- Rapid recovery from physically intact backups
- Supply chain independence, sovereign, self-contained infrastructure
- Full audit trail for incident reporting requirements
Take Operational Data Off Connected Infrastructure
Step 1 of 3Operational data and gold copies are taken off network-connected infrastructure and written to physically disconnected RAID 1 drives inside a Firevault Bunker. Critical systems can be restored from data that was never reachable during an incident.
Win Business, Earn Trust, and Build Reputation with Butterfly
Butterfly is an operational model that helps organisations structure sensitive data to close deals faster, strengthen client relationships, and demonstrate the governance maturity that wins enterprise contracts.
Built on the VPPP framework (Vault, Policy, Permissions, Purpose), Butterfly maps your sensitive data and assigns dedicated Vaults by role, relationship, and purpose, turning data stewardship into a competitive advantage.
Deal Readiness
Governed materials ready to share with confidence
Client Trust
Demonstrate stewardship that earns loyalty
Board Confidence
Clear governance that inspires stakeholders
Enterprise Scale
Structure data governance across your organisation

Who Uses Butterfly?
-
Sales Teams
Secure client proposals, pricing, and commercial intelligence
-
Service Providers
Exchange sensitive documents with clients through governed Vaults
-
Businesses
Protect strategic plans, IP, and competitive intelligence
-
Family Offices
Structure data governance across principals, staff, and advisors
Questions