Compliance, Cyber Insurance

3-2-1-0 Backup, The Insurer Standard

Cyber insurers now expect a real offline copy. Firevault Bunkers deliver the 0 in 3-2-1-0 with the audit trail underwriters want to see.

  • Offline by default
  • Identity locked access
  • Hardware encrypted
Framework matrix
Security analyst reviewing an isolated workstation with disconnected cables

3

Copies: production plus two protective copies

2

Different media, to avoid correlated failure

1

Offsite copy, physically separated from production

0

Errors on restore, and zero online copies

01The requirement

What 3-2-1-0 Actually Means

A plain English breakdown of the rule insurers, regulators and boards keep referencing. Wording from underwriters such as Lloyd's syndicates, Beazley and AXA now references offline, immutable or air gapped backup as a control.

This is a mapping, not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

02What is tested

The Rule, Line by Line

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Three copies: one copy alone is not resilience, it is hope

Two media: a single firmware bug should not take both backups

One offsite copy with documented chain of custody

Zero verified errors, evidenced by regular test restores

Zero copies reachable from production at the time of an attack

03Consequences

Where Strategies Fall Short

What happens when the control is missing, and the record cannot be produced.

Same Media Twice

Both backups on one storage technology means one vendor incident can take both.

Cold Cloud Is Still Online

Glacier and similar tiers stay addressable through the cloud control plane and IAM.

Untested Restores

Insurers increasingly ask for documented test dates, scope and outcome.

Egress and Handling Cost

Per gigabyte retrieval fees and tape handling overhead both bite at the worst moment.

04The architecture

Tape, Cold Cloud, or Bunker

The three credible ways to satisfy the offline copy requirement, and where each one wins or loses.

Iron Mountain Tape

A genuine physical air gap. The tradeoff is operational: recoveries can take days, handling errors are common and verifying restores at scale is painful.

AWS Glacier and Cold Cloud

Still reachable through the public cloud control plane. Retrieval is slower and cheaper than hot storage, but the data remains addressable and IAM dependent.

Firevault Bunkers

A tape style physical air gap with scheduled, identity verified online windows for restores. CNI-grade bunkers and no per gigabyte egress to budget around.

Layer 1 Disconnection

Between sessions the drives have no network connection, so the offline copy survives a complete production or cloud account compromise.

Underwriter Evidence Pack

A control attestation pack covering Layer 1 disconnection, identity verified access, audit trails and bunker physical security, written to hand to brokers.

Documented Custody

Geographic separation with a recorded chain of custody and verified retrieval for every session.

“The 0 in 3-2-1-0 is the only part of the rule an attacker cannot argue with. A copy with no network connection is not a policy, it is a fact.”

Mark Fermor, Founder, Firevault

05What sits offline

What the Offline Copy Holds

The records most often moved into Offline Secure Storage® for this framework.

Gold copies of production systems

Backup catalogues and recovery keys

Regulated records under retention duties

Finance and payroll archives

Restore test evidence for underwriters

Board and audit reporting packs

Do insurers really require an offline copy?

An increasing share do, particularly in mid market and enterprise lines. Premiums and coverage scope are routinely linked to evidence of these controls.

Where the 0 comes from

The 0 has two readings and Firevault recommends covering both: zero errors during restore testing, and zero copies reachable from the production network during an attack.

Is cloud immutability enough?

It is a strong layer, not a complete one. Cloud immutability still depends on identity, billing and policy controls remaining intact. A genuinely offline copy survives a full account compromise.

How often to test restores

At minimum quarterly for critical systems and annually for the full estate. Scheduled access windows make recurring test restores straightforward to evidence.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up