---
title: "OT/ICS Security Vault | Air-Gapped Recovery"
description: "Firevault is the OT and ICS security vault: a Layer 1 air-gapped, immutable gold copy at Purdue Level 3.5 for ICS ransomware recovery, IEC 62443 and NIS2."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/solutions/ot-ics-security-vault#webpage",
      "url": "https://fire-vault.com/solutions/ot-ics-security-vault",
      "name": "OT/ICS Security Vault",
      "description": "Firevault is the OT and ICS security vault: a Layer 1 air-gapped, immutable gold copy at Purdue Level 3.5 for ICS ransomware recovery, IEC 62443 and NIS2.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-solutions.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/solutions/ot-ics-security-vault#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/solutions/ot-ics-security-vault#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Solutions",
          "item": "https://fire-vault.com/solutions"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "OT/ICS Security Vault",
          "item": "https://fire-vault.com/solutions/ot-ics-security-vault"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Product",
      "name": "Firevault OT/ICS Security Vault",
      "brand": {
        "@type": "Brand",
        "name": "Firevault"
      },
      "category": "OT and ICS air-gapped backup vault",
      "description": "Air-gapped, immutable vault for OT and ICS gold copies, deployed at Purdue Level 3.5 or in a dedicated bunker adjacent to the plant.",
      "manufacturer": {
        "@type": "Organization",
        "name": "Firevault"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is an OT/ICS security vault?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "An OT/ICS security vault is a dedicated store for the gold copy of operational technology and industrial control system data, deployed at the industrial DMZ (Purdue Level 3.5) or in a bunker adjacent to the plant. It combines a physical air gap with immutable WORM storage so that the copy remains recoverable even when the corporate identity domain, the site business systems and the primary backup platform have all been destroyed."
          }
        },
        {
          "@type": "Question",
          "name": "How is an air-gapped backup for OT different from cloud immutable backup?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cloud immutable backup keeps a policy-locked copy on infrastructure that is always network reachable and always inside a cloud identity plane. An air-gapped OT backup keeps a copy on media with no live network interface at all, isolated from that identity plane. Both are valuable layers, but only the air gap is  disconnected to an attacker who has already compromised your cloud IAM."
          }
        },
        {
          "@type": "Question",
          "name": "Where should the vault sit in the Purdue Model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The recommended placement is Purdue Level 3.5, the industrial DMZ, or a dedicated bunker adjacent to the OT estate. That keeps the gold copy out of the Level 4 and Level 5 identity domain where the vast majority of destructive OT ransomware incidents originate, while still allowing scheduled, out-of-band synchronisation with the plant."
          }
        },
        {
          "@type": "Question",
          "name": "Does Firevault replace our existing ICS backup platform?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Firevault layers over existing tools such as Veeam, Rubrik, Commvault and the native backup features of ICS vendors. Those platforms handle fast operational recovery for the ordinary failure modes. Firevault provides the one offline copy the 3-2-1-1-0 rule requires and the tamper evident evidence the insurer requires."
          }
        },
        {
          "@type": "Question",
          "name": "Which standards and frameworks does the vault map to?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Firevault maps to IEC 62443 zones and conduits, NIS2 recovery and reporting obligations, NERC CIP for the North American energy sector, and the NCSC ransomware-resistant backup guidance for UK essential services. Every connection window, write and restore rehearsal produces a signed record aligned to those frameworks."
          }
        },
        {
          "@type": "Question",
          "name": "How is the vault protected from a compromised administrator?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The vault runs on a separate management plane, outside the corporate identity domain. Retention is enforced in hardware, not by a policy that a domain admin can change. Connection windows are switched out of band and logged. A compromised administrator on the corporate side cannot rewrite, expire or delete a copy inside the retention window."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Why OSS 

# The OT/ICS Security Vault for Air-Gapped Recovery 

Firevault is a Layer 1 air-gapped, immutable vault for the gold copy of your OT and ICS data. It sits at Purdue Level 3.5, isolated from the corporate identity domain ransomware targets first, with the signed evidence IEC 62443, NIS2 and NCSC reviewers expect.

Book a demo

![Rows of locked server cabinets inside a secure Firevault data hall](/__l5e/assets-v1/a4d3902c-28a5-42f4-bbfb-c12ddaacce1b/hero-square-drive.png)

S1 

Mapped to IEC 62443 · NIS2 · NERC CIP · NCSC ransomware-resistant backups

What the vault does 

## Six Capabilities That Define An OT/ICS Security Vault 

Air gap, immutability, Purdue Level 3.5 placement, ransomware recovery, segmentation-friendly deployment and audit-ready evidence, in one appliance line.

01 

Layer 1 physical isolation 

### Air-gapped OT backup

Firevault holds the gold copy of your OT and ICS data on media with no live network interface. Connection windows are switched out of band, logged on a separate management plane, and closed the moment the sync ends. Ransomware cannot reach what is not on the wire.

-   No live network interface offline
-   Out-of-band switching
-   Tamper evident connection log

02 

Write once, retain for the policy window 

### Immutable WORM storage

Every copy is written under WORM controls with hardware-enforced retention. Neither an operator nor an attacker with stolen credentials can rewrite, expire or delete a copy inside the retention window. Immutability rides on top of the physical air gap, not in place of it.

-   Hardware-enforced retention
-   No admin override
-   Verified restore evidence

03 

Where the gold copy belongs 

### Purdue Level 3 and 3.5 deployment

Firevault deploys at Purdue Level 3.5, the industrial DMZ, or in a dedicated bunker adjacent to the OT estate. That placement keeps the copy out of the Level 4 and Level 5 identity domain that ransomware targets first, without adding another VLAN rule to an already busy firewall.

-   Sits at the industrial DMZ
-   Isolated from corporate identity
-   Firebreak hardware option

04 

A copy the attacker cannot reach 

### ICS ransomware recovery

Every published post-incident report on a large OT ransomware event follows the same pattern: entry at Level 5, lateral to Level 4, pivot through Level 3.5, then plant shutdown. Firevault gives you the one recovery copy that pattern cannot touch, and the audit trail your insurer requires.

-   Breaks the L5 to plant chain
-   Restore rehearsals on schedule
-   Insurer-ready evidence pack

05 

Layers over existing OT security 

### Segmentation-friendly deployment

Firevault does not replace Veeam, Rubrik, Commvault or native ICS backup platforms. Those handle fast operational recovery. Firevault sits alongside them as the one offline copy the 3-2-1-1-0 rule requires, honouring your existing zone and conduit design.

-   Works with existing backup tools
-   Respects IEC 62443 zones
-   One offline copy done properly

06 

IEC 62443, NIS2, NERC CIP, NCSC 

### Audit-ready evidence

Every connection window, every write, every restore rehearsal produces a signed record. That evidence pack answers the questions IEC 62443 assessors, NIS2 reporters, NERC CIP auditors and NCSC-aligned reviewers actually ask, without a scramble the week before the audit.

-   IEC 62443 mapped
-   NIS2 and NCSC aligned
-   NERC CIP evidence trail

Why most OT backups still fail 

## The Three Failure Modes Firevault Is Built Against 

A backup on the corporate domain, an immutable appliance mislabelled as an air gap, and a restore that has never been rehearsed across Level 3.5. Firevault removes all three.

01 

The single most common failure 

### Backup on the corporate domain

When the OT backup platform runs on a VM in the corporate hypervisor, joined to the corporate identity domain, a single compromised admin account destroys production data and every recovery copy in the same afternoon. Firevault sits outside that domain by design.

-   No corporate domain trust
-   No shared admin plane
-   Physical, not logical, boundary

02 

Immutability is not isolation 

### Immutable appliance called an air gap

An immutable appliance still lives on the network, still exposes a management interface, and still trusts an identity plane an attacker can compromise. It is a valuable layer, but describing it as an air gap in insurer paperwork is how claims get disputed. Firevault provides both.

-   Immutability plus air gap
-   No management plane exposure
-   Truthful insurer paperwork

03 

A copy you have not restored is a hope 

### No tested restore across L3.5

The failure mode auditors flag most often is a backup platform that has never been rehearsed across the Level 3.5 boundary. Firevault schedules and logs those rehearsals, so the evidence is already on file when the assessor arrives.

-   Scheduled restore rehearsals
-   Signed evidence per run
-   Ready before the audit

Firevault vs. the alternatives

## How the Vault Compares to Cloud Immutable and Tape

Cloud immutable storage and tape both belong in a well-designed OT recovery plan. Neither alone provides the physical isolation, the Purdue Level 3.5 placement and the signed evidence pack a vault does.

Capability

Firevault OT/ICS Vault

Cloud immutable

Tape

Physical air gap between copies

Yes, Layer 1, no live interface 

No, always network reachable

Partial, only when ejected and stored offsite

Immutable WORM storage

Yes, hardware enforced 

Yes, policy enforced

Yes, by media type

Sits at Purdue Level 3.5 by design

Yes 

No, lives beyond Level 5

Depends on library placement

Isolated from corporate identity

Yes, separate management plane 

No, cloud IAM in scope

Partial, depends on library operator

Restore rehearsal evidence pack

Yes, signed per run 

Manual, tenant responsibility

Manual, operator responsibility

Recovery when corporate domain is destroyed

Yes, unaffected 

Blocked, IAM often affected

Yes, if media is offsite

Outcomes

## What Operators Get from a Firevault Deployment

### Plant restart from a clean copy

A recovery source that is unaffected when the corporate identity domain and the primary backup platform are both destroyed.

### Evidence pack the insurer accepts

Signed connection windows, WORM writes and restore rehearsals mapped to IEC 62443 and NIS2 obligations.

### One offline copy, done properly

The 3-2-1-1-0 rule satisfied by a physical air gap, not a marketing claim on an immutable appliance.

Continue with the reference architecture, the segmentation guide and the air gap comparison.

[Purdue Model for OT/ICS](/learn/purdue-model-ot-ics-security) [Air gap vs. immutable backup](/learn/air-gap-vs-immutable-backup) [OT network segmentation](/learn/ot-network-segmentation) [OT/ICS security pillar](/learn/ot-ics-security-air-gap-storage)

Questions 

## OT/ICS Security Vault, Common Questions

Straight answers on how Offline Secure Storage® behaves in practice.

### What is an OT/ICS security vault?

### How is an air-gapped backup for OT different from cloud immutable backup?

### Where should the vault sit in the Purdue Model?

### Does Firevault replace our existing ICS backup platform?

### Which standards and frameworks does the vault map to?

### How is the vault protected from a compromised administrator?

![Mark Fermor](/assets/mark-fermor-C-vy1NeN.jpg)

![David Bailey](/assets/david-bailey-CnLw95Ao.jpg)

![Kenny Phipps](/assets/kenny-phipps-DxIqwaIL.jpg)

Online Now 

Concierge 

## Put the OT gold copy in a vault the corporate domain cannot reach

Talk to the Firevault team about a Layer 1 air-gapped, immutable vault at Purdue Level 3.5, with the signed evidence pack IEC 62443, NIS2 and NCSC reviewers expect.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up