---
title: "NCSC Ransomware-Resistant Backups: Offline Gold | Firevault"
description: "Meet NCSC ransomware-resistant backup guidance with Firevault offline gold copies, physically unreachable from your network."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Compliance",
          "item": "https://fire-vault.com/compliance"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "NCSC Ransomware-Resistant Backups: Offline Gold",
          "item": "https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups#webpage",
      "url": "https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups",
      "name": "NCSC Ransomware-Resistant Backups: Offline Gold",
      "description": "Meet NCSC ransomware-resistant backup guidance with Firevault offline gold copies, physically unreachable from your network.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/compliance/ncsc-ransomware-resistant-backups#breadcrumb"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The requirementThe gapsConsequencesThe architectureWhat sits offline

Compliance, NCSC 

# NCSC Ransomware-Resistant Backup Principles 

How Firevault maps to the National Cyber Security Centre principles for backups that survive a destructive attack. Principle by principle, with the architectural answer for each.

-   Offline by default
-   Identity locked access
-   Hardware encrypted

Book a mapping call[Framework matrix](/compliance/frameworks)

![Security analyst reviewing an isolated workstation with disconnected cables](/assets/hero-square-analyst-DI5B7V_E.jpg)

5

NCSC principles for ransomware-resistant backups

Layer 1

Where Offline Secure Storage disconnects, below the network

0

Network interfaces on the gold copy while offline

01 The requirement 

## Backups Are the Target

NCSC publishes its principles freely at ncsc.gov.uk, alongside the guidance Offline backups in an online world. Together they describe what an offline copy must do to survive an attacker who has already reached the production estate. NCSC does not certify products, so the framing here is alignment, not certification.

This is a mapping , not a certification claim. Firevault holds Cyber Essentials Plus. Everything else on this page is stated as alignment: Offline Secure Storage® produces evidence you can point at in your own submission, assessment or audit.

-   5 — NCSC principles for ransomware-resistant backups. [Source: NCSC, Principles for ransomware-resistant cloud backups](https://www.ncsc.gov.uk/blog-post/principles-for-ransomware-resistant-cloud-backups)

02 What is tested 

## The Five NCSC Principles

Each line below is something an assessor, regulator or underwriter can ask you to evidence.

Backups should be resilient to destructive actions

A backup system should be configured so that it is not possible to deny customers access to their data

The system should allow you to restore from a backup of last resort

The actions required to access backups should be sufficiently distinct from day to day actions

Backups should be regularly tested

03 Consequences 

## Where Online Backup Falls Short

What happens when the control is missing, and the record cannot be produced.

### Destructive Actions Reach Backups

An attacker inside production can reach any target that still has a network interface.

### Access Can Be Denied

Cloud backup consoles can be locked out, billing-suspended or abused through the identity layer.

### No Distinct Access Path

If restoring uses the same credentials as day to day work, an intruder inherits the path.

### Object Lock Is Not Offline

Immutable buckets remain reachable over the provider API and depend on software policy.

04 The architecture 

## Five NCSC Principles, Five Firevault Answers

Offline Secure Storage is purpose-built around the same threat model NCSC describes: physical disconnection, a separate management plane and audited restore.

### Resilient to Destructive Actions

The gold copy sits on hardware physically disconnected at Layer 1. A destructive action cannot reach a target with no network interface or IP address.

### Access Cannot Be Denied

A separate management plane and customer-held identity factors mean no single account compromise can deny access to the data.

### Backup of Last Resort

The gold copy sits offline in carefully selected colocation bunkers, brought online only inside an identity-verified connection window.

### Distinct From Day to Day

Access needs a scheduled physical connection, a separate identity and out-of-band approval, not production credentials.

### Regularly Tested

Recurring verification windows bring the copy online, checksum-verify it and restore in part, with every test event logged.

### Tamper-Evident Evidence

Every connection, disconnection, identity verification and restore is recorded for regulators, insurers and board reporting.

“A destructive action on production cannot reach a target that has no network interface. That is the whole argument, and it is a physical one.”

Mark Fermor, Founder, Firevault

05 What sits offline 

## What the Gold Copy Holds

The records most often moved into Offline Secure Storage® for this framework.

Immutable gold copies of critical systems

Backup catalogues and recovery keys

Regulated records with retention duties

Configuration and infrastructure state

Restore verification evidence

Audit trails for insurers and regulators

### Layer 1, not Layer 2

Hardened repositories and immutable buckets sit on the network and depend on software policy. Offline Secure Storage sits below the network at the physical layer, so the control cannot be bypassed in software because there is no software path while offline.

### Evidence packs, not assertions

Principles only matter if you can prove them. Firevault produces per-event logs with identity captured, packaged as evidence regulators, insurers and boards now ask for.

### Alignment, not certification

NCSC does not certify products. Firevault maps its architecture to each published principle and to the NCSC guidance Offline backups in an online world, then hands over the evidence so you can make the case yourself.

### Alongside 3-2-1-1-0

3-2-1-1-0 is the operational rule of thumb. The NCSC principles describe the properties that offline copy needs to actually resist a destructive attack. Firevault is designed to satisfy both.

[Layer 1 vs logical air gap](/learn/physical-vs-logical-air-gap) [Cyber insurance 3-2-1-0](/compliance/cyber-insurance-3-2-1-0) [All compliance frameworks](/compliance)

### Authoritative Sources

-   [NCSC Offline Backups in an Online World (NCSC) ](https://www.ncsc.gov.uk/guidance/offline-backups-in-an-online-world)
-   [NCSC Principles for Ransomware-Resistant Cloud Backups (NCSC) ](https://www.ncsc.gov.uk/blog-post/principles-for-ransomware-resistant-cloud-backups)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Tell us which framework you are being tested against.

We will map Offline Secure Storage® to the outcomes your assessor is checking, and give you the wording and evidence to submit.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up 

NCSC guidance, offline backups in an online world

## Mapped to the NCSC guidance on offline backups 

The National Cyber Security Centre publishes its guidance [Offline backups in an online world](https://www.ncsc.gov.uk/guidance/offline-backups-in-an-online-world) freely at ncsc.gov.uk. It sets out what an offline copy must do to survive an attacker who already holds the production estate. Offline Secure Storage® is built around that same threat model. Each guidance theme below is paired with the architectural answer, in the NCSC order of priority.

What NCSC advises

Keep at least one backup copy offline, so that it cannot be reached from the systems it protects.

How Offline Secure Storage answers it

The gold copy sits on hardware physically disconnected at Layer 1. While offline it holds no interface and no address, so nothing on the production estate can reach it, encrypt it or delete it.

What NCSC advises

Do not leave backup devices permanently connected to the network or to the host being backed up.

How Offline Secure Storage answers it

Connection is an event, not a state. The path opens only inside a scheduled, identity-verified window and closes again when that window ends.

What NCSC advises

Separate backup credentials and administration from day to day accounts, so one compromise cannot destroy the copy.

How Offline Secure Storage answers it

A separate management plane and customer-held identity factors govern access. Production credentials, domain rights and hypervisor rights grant nothing here.

What NCSC advises

Assume attackers will look for backups first, and design the copy of last resort accordingly.

How Offline Secure Storage answers it

The copy of last resort sits offline inside carefully selected colocation bunkers, in a jurisdiction the customer chooses, with hardware encryption at rest.

What NCSC advises

Test restores regularly, because an untested backup is an assumption rather than a control.

How Offline Secure Storage answers it

Recurring verification windows bring the copy online, checksum-verify the data, restore in part and disconnect again. Every test is a logged event.

What NCSC advises

Be able to show what is backed up, where it is held and how it is protected.

How Offline Secure Storage answers it

Every connection, disconnection, identity verification and restore is recorded and packaged as evidence for regulators, insurers and board reporting.

### Alignment, not certification

NCSC does not certify products or endorse suppliers. Firevault maps its architecture to the published guidance and hands over the connection and restore evidence, so a UK organisation can make the case to its own auditors, insurers and board.

-   [Offline backups in an online worldNCSC, ncsc.gov.uk ](https://www.ncsc.gov.uk/guidance/offline-backups-in-an-online-world)
-   [Backing up your dataNCSC, ncsc.gov.uk ](https://www.ncsc.gov.uk/guidance/backing-up-your-data)
-   [Mitigating malware and ransomware attacksNCSC, ncsc.gov.uk ](https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks)