---
title: "Air Gap vs Immutable Backup: How They Differ and Combine"
description: "Air-gapped storage versus immutable storage explained: what object lock and WORM actually protect, what they do not, and how to combine both for ransomware…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/air-gap-vs-immutable-backup#webpage",
      "url": "https://fire-vault.com/learn/air-gap-vs-immutable-backup",
      "name": "Air Gap vs Immutable Backup: How They Differ and Combine",
      "description": "Air-gapped storage versus immutable storage explained: what object lock and WORM actually protect, what they do not, and how to combine both for ransomware…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/air-gap-vs-immutable-backup#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/air-gap-vs-immutable-backup#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "https://fire-vault.com/"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Air Gap vs Immutable Backup: How They Differ and Combine",
          "item": "https://fire-vault.com/learn/air-gap-vs-immutable-backup"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Air Gap vs Immutable Backup: How They Differ and Combine",
      "description": "Air-gapped storage versus immutable storage explained: what object lock and WORM actually protect, what they do not, and how to combine both for ransomware…",
      "image": "https://fire-vault.com/images/og/og-base-learn.jpg",
      "author": {
        "@type": "Organization",
        "name": "Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png"
        }
      },
      "datePublished": "2025-09-22",
      "dateModified": "2026-08-27",
      "mainEntityOfPage": "https://fire-vault.com/learn/air-gap-vs-immutable-backup"
    },
    {
      "@context": "https://schema.org",
      "@type": "TechArticle",
      "@id": "https://fire-vault.com/learn/air-gap-vs-immutable-backup#article",
      "headline": "Air Gap vs Immutable Backup: How They Differ and Combine",
      "description": "Air-gapped storage versus immutable storage explained: what object lock and WORM actually protect, what they do not, and how to combine both for ransomware resilience.",
      "about": [
        {
          "@type": "Thing",
          "name": "Immutable backup"
        },
        {
          "@type": "Thing",
          "name": "Object lock"
        },
        {
          "@type": "Thing",
          "name": "WORM storage"
        },
        {
          "@type": "Thing",
          "name": "Air gap"
        },
        {
          "@type": "Thing",
          "name": "Retention lock"
        },
        {
          "@type": "Thing",
          "name": "3-2-1-1-0 backup rule"
        }
      ],
      "keywords": "air gap vs immutable backup, immutable backup, object lock, WORM storage, retention lock, air gapped storage, immutable storage ransomware, 3-2-1-1-0 backup rule, backup immutability limitations, physical air gap backup",
      "articleSection": "Data protection architecture",
      "inLanguage": "en-GB",
      "isAccessibleForFree": true,
      "wordCount": 2300,
      "image": [
        "https://fire-vault.com/assets/explainer-air-gap-vs-immutable-backup-CNe0GHaE.jpg"
      ],
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "url": "https://fire-vault.com/about",
        "jobTitle": "Director and Co-Founder, Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "url": "https://fire-vault.com"
      },
      "datePublished": "2025-09-22",
      "dateModified": "2026-08-27",
      "url": "https://fire-vault.com/learn/air-gap-vs-immutable-backup",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/air-gap-vs-immutable-backup"
      },
      "citation": [
        {
          "@type": "CreativeWork",
          "name": "NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events",
          "url": "https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events"
        },
        {
          "@type": "CreativeWork",
          "name": "NIST SP 800-209, Security Guidelines for Storage Infrastructure",
          "url": "https://csrc.nist.gov/pubs/sp/800/209/final"
        },
        {
          "@type": "CreativeWork",
          "name": "ISO/IEC 27040:2024, Storage Security",
          "url": "https://www.iso.org/standard/79280.html"
        },
        {
          "@type": "CreativeWork",
          "name": "NCSC UK, Offline Backups Guidance",
          "url": "https://www.ncsc.gov.uk/blog-post/protecting-backups-from-ransomware"
        },
        {
          "@type": "CreativeWork",
          "name": "CISA, StopRansomware Guide",
          "url": "https://www.cisa.gov/stopransomware/ransomware-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is immutable backup the same as an air gap?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Immutable backup prevents data being altered or deleted for a set retention period, but the storage remains connected to the network throughout. An air gap removes the network path itself. They are complementary controls, not interchangeable terms."
          }
        },
        {
          "@type": "Question",
          "name": "What is object lock?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Object lock is a feature, most commonly associated with S3-compatible cloud storage, that prevents an object from being deleted or overwritten until a specified retention date. It is enforced by the storage platform's software and configuration, not by physical disconnection."
          }
        },
        {
          "@type": "Question",
          "name": "What is WORM storage?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "WORM stands for write once, read many. It describes storage where data can be written once and then only read, not modified or deleted, for a defined period. WORM is the underlying mechanism behind most immutable backup and retention lock features."
          }
        },
        {
          "@type": "Question",
          "name": "Can immutable backup be deleted by an attacker?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The individual protected objects cannot be deleted within their retention window through normal means. However, an attacker with sufficient administrative privilege over the storage account can, in some configurations, disable versioning, alter bucket-level settings, delete the entire account or bucket, or wait out the retention period before acting."
          }
        },
        {
          "@type": "Question",
          "name": "Does immutability protect against credential compromise?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Not fully. Immutability protects the data object itself from modification, but it does not prevent an attacker who has compromised administrative credentials from changing account-level configuration, disabling protection features going forward, or removing access for legitimate users. The retention lock protects the object, not the account holding it."
          }
        },
        {
          "@type": "Question",
          "name": "Can retention locks be shortened or bypassed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Some retention lock implementations distinguish between governance mode, which can be altered by users with special permissions, and compliance mode, which cannot be shortened even by the account owner during the lock period. The protection offered depends entirely on which mode is configured and enforced correctly."
          }
        },
        {
          "@type": "Question",
          "name": "What does immutable storage not protect against?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Immutability does not protect against compromise of the credentials or identity system controlling the account, misconfiguration that leaves protection disabled from the outset, deletion of the entire account or bucket by a sufficiently privileged actor, or attacks that target the cloud provider's control plane rather than the individual object."
          }
        },
        {
          "@type": "Question",
          "name": "Is a hardened backup repository the same as an air gap?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. A hardened repository reduces attack surface and often includes immutability, but it remains reachable on the network and trusts an identity layer to authorise access. It is a strong logical control, not a physical air gap."
          }
        },
        {
          "@type": "Question",
          "name": "When is immutable backup enough on its own?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Immutable backup, correctly configured with compliance-mode retention and separated credentials, is often sufficient for recovering from accidental deletion, ransomware limited to endpoint or file-share encryption, and most day-to-day operational incidents where the backup platform's own account is not compromised."
          }
        },
        {
          "@type": "Question",
          "name": "When do I need a physical air gap as well as immutable backup?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A physical air gap becomes necessary when the threat model includes an attacker who may obtain administrative access across the connected estate, including identity systems and the backup platform's own account. In that scenario, a copy with no network path at all is the only copy the attacker cannot reach."
          }
        },
        {
          "@type": "Question",
          "name": "How do air gap and immutable backup fit into the 3-2-1-1-0 rule?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The 3-2-1-1-0 rule calls for three copies of data, on two different media, one offsite, one offline, and zero errors after a recovery test. Immutable cloud storage typically satisfies the offsite copy. A physical air gap is what satisfies the offline copy, since an online immutable bucket, however well protected, is not an offline copy."
          }
        },
        {
          "@type": "Question",
          "name": "Should I choose one or the other?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Most well-designed backup architectures use both. Immutable, network connected storage supports fast, everyday recovery. A physical air gap provides the last, trusted copy for the scenario where the connected estate itself has been compromised. Treating them as alternatives rather than layers leaves a gap in the architecture."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Knowledge Vault](/learn/knowledge)

Explainer Data protection architecture 

# Air Gap vs Immutable Backup: How They Differ and Combine

Object lock and WORM retention are powerful, but they are not the same control as a physical air gap. This explainer sets out what immutability actually protects, what it does not, and how the two belong together in a resilient backup architecture.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

22 September 2025 15 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup&text=Air%20Gap%20vs%20Immutable%20Backup%3A%20How%20They%20Differ%20and%20Combine%0A%0AObject%20lock%20and%20WORM%20retention%20are%20powerful%2C%20but%20they%20are%20not%20the%20same%20control%20as%20a%20physical%20air%20gap.%20This%20explainer%20sets%20out%20what%20immutability%20actually%20protects%2C%20what%20it%20does%20not%2C%20and%20how%20the%20two%20belong%20together%20in%20a%20resilient%20backup%20architecture.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup)[](mailto:?subject=Air%20Gap%20vs%20Immutable%20Backup%3A%20How%20They%20Differ%20and%20Combine&body=Object%20lock%20and%20WORM%20retention%20are%20powerful%2C%20but%20they%20are%20not%20the%20same%20control%20as%20a%20physical%20air%20gap.%20This%20explainer%20sets%20out%20what%20immutability%20actually%20protects%2C%20what%20it%20does%20not%2C%20and%20how%20the%20two%20belong%20together%20in%20a%20resilient%20backup%20architecture.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup)

![A locked storage vault beside a networked backup server, illustrating the difference between an air gap and immutable storage](/assets/explainer-air-gap-vs-immutable-backup-CNe0GHaE.jpg)

Immutable storage stops data being altered while it remains reachable. A physical air gap removes the network path to the data entirely.

Written by

Mark Fermor, Co-Founder, Firevault

Technical review

Firevault architecture team

First published

22 September 2025

Last reviewed

27 August 2026

Review cycle

At least annually, or following material changes to NIST, NCSC or ISO guidance.

How we built this explainer:  This explainer draws on published guidance from NIST, NCSC UK and CISA on ransomware resilience and backup architecture, together with documented incidents involving immutable and cloud backup platforms. No vendor performance claim, percentage or statistic appears unless it can be traced to a named, checkable source.

**On this page**[What is immutable storage?](#what-is-immutable)[WORM, object lock and retention locks explained](#worm-object-lock)[What is a physical air gap?](#what-is-air-gap)[Air gap versus immutable, side by side](#comparison)[What immutability actually protects](#what-immutability-protects)[What immutability does not protect against](#what-immutability-does-not)[How standards and guidance frame the two](#standards)[When each control is appropriate](#when-each-appropriate)[How to combine air gap and immutable backup](#combining)[Where each fits in the 3-2-1-1-0 rule](#3-2-1-1-0)[How Firevault applies these principles](#firevault)[The key takeaway](#takeaway)

On this page

1.  [What is immutable storage?](#what-is-immutable)
2.  [WORM, object lock and retention locks explained](#worm-object-lock)
3.  [What is a physical air gap?](#what-is-air-gap)
4.  [Air gap versus immutable, side by side](#comparison)
5.  [What immutability actually protects](#what-immutability-protects)
6.  [What immutability does not protect against](#what-immutability-does-not)
7.  [How standards and guidance frame the two](#standards)
8.  [When each control is appropriate](#when-each-appropriate)
9.  [How to combine air gap and immutable backup](#combining)
10.  [Where each fits in the 3-2-1-1-0 rule](#3-2-1-1-0)
11.  [How Firevault applies these principles](#firevault)
12.  [The key takeaway](#takeaway)

Immutable storage and air-gapped storage are frequently discussed as though they solve the same problem. They do not. Immutability is a promise about what can happen to data that remains reachable. An air gap is a statement about whether the data is reachable at all. Confusing the two leads organisations to believe they have covered a risk that, in fact, remains open.

This explainer sets out what immutable storage mechanisms such as object lock and WORM actually do, where their protection stops, and how to combine immutability with a genuine physical air gap so that neither gap in coverage is left unaddressed.

## What is immutable storage?

Immutable storage is storage configured so that, once written, an object cannot be modified or deleted until a defined retention period has elapsed. The guarantee is enforced by the storage platform's software, typically at the object or volume level, and is intended to stop both accidental and malicious alteration of backup data during the protected window.

The storage remains connected to the network throughout. Backup jobs need to reach it to write new data, and administrators need to reach it to manage retention settings, which means the protection depends on the software enforcing it and the identity system authorising access to it, both of which remain part of the attack surface.

## WORM, object lock and retention locks explained

WORM

Write once, read many. Data can be written once and subsequently only read, not altered, for a defined period. The underlying mechanism behind most immutable storage.

Object lock

A cloud storage feature, common in S3-compatible platforms, that applies a WORM-style retention date to individual objects.

Governance mode retention

A retention lock that certain privileged accounts or roles can override, shorten or remove before expiry.

Compliance mode retention

A stricter retention lock that cannot be shortened or removed by any account, including the owner, before the retention period expires.

The distinction between governance mode and compliance mode matters considerably. A retention lock that can be overridden by a sufficiently privileged account offers weaker protection against an attacker who has obtained that privilege than a lock that genuinely cannot be altered by anyone until it expires.

## What is a physical air gap?

A physical air gap means the storage has no active network interface while it is meant to be isolated. There is no address to reach it at, no listening service to authenticate to, and no software process on the connected estate that can bring it back online by itself. Reconnection is a distinct, separately controlled and auditable event.

Where immutability is a policy statement enforced by software that remains reachable, a physical air gap removes the reachability itself. The two controls answer different questions: immutability asks "can this data be changed while I can still reach it", and a physical air gap asks "can this data be reached at all".

## Air gap versus immutable, side by side

Immutable storage

Cannot be altered, remains reachable

-   Protects the object from modification during retention
-   Enforced by platform software and configuration
-   Depends on the account and identity system holding
-   Governance mode can be overridden by privileged roles

Physical air gap

Has no network path to reach

-   Protects the copy by removing reachability
-   Enforced by the absence of an active interface
-   Unaffected by compromise of the connected account
-   Reconnection is a separate, audited event

Immutable storage and a physical air gap protect against different classes of compromise.

## What immutability actually protects

Immutability is a genuinely effective control against a specific, common set of failure modes, and should not be dismissed because it has limits.

-   Accidental deletion by an authorised user during normal operations
-   Malware or ransomware that only encrypts or deletes files, without reaching the backup account itself
-   A rogue or careless script that attempts to overwrite backup data within the retention window
-   Basic insider actions from an account that does not hold elevated administrative privilege

## What immutability does not protect against

The limits of immutability are not a flaw in the technology. They are the natural consequence of the storage remaining reachable, which it must be for backups to be written to it in the first place.

Object layer

Protected by immutability

Individual backup objects cannot be modified or deleted within the retention window, provided the lock is correctly configured.

Account layer

Credential and identity compromise

An attacker with administrative credentials to the storage account can, in some configurations, disable protection features, alter settings or remove legitimate access.

Policy layer

Retention policy manipulation

Governance-mode retention locks can be shortened or removed by privileged roles. Misconfigured or absent locks provide no protection at all.

Provider layer

Provider-plane and account-level attacks

Deletion of the entire account, bucket or subscription, or an attack on the cloud provider's own control plane, can remove data regardless of object-level immutability.

Immutability protects one layer of the stack. The layers below and around it remain exposed.

### Four failure modes immutability alone does not close

1.  Credential compromise.  An attacker who obtains sufficiently privileged credentials to the backup or cloud storage account can alter configuration that sits outside the immutability lock itself, including access permissions and future retention settings.
2.  Retention policy manipulation.  Where retention is configured in governance mode rather than compliance mode, a privileged account, legitimate or compromised, can shorten or remove the lock before it expires.
3.  Provider-plane attacks.  Attacks that target the cloud provider's control plane, billing account or organisation-level settings, rather than the individual storage object, can affect data that the object-level lock was never designed to defend against.
4.  Deletion of the whole account.  Object Lock protects individual objects. It does not, on its own, prevent deletion of the entire bucket, account or subscription by an actor with sufficient privilege at that higher level, depending on the specific platform and configuration.

## How standards and guidance frame the two

[NIST SP 800-209](https://csrc.nist.gov/pubs/sp/800/209/final) treats immutability, access control and isolation as separate storage security layers, each closing a different gap rather than one substituting for another. [NIST SP 1800-11](https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events) discusses the need for an isolated, trusted recovery source specifically because software controls on the production or backup network cannot be assumed to hold under a determined attack.

[ISO/IEC 27040](https://www.iso.org/standard/79280.html) addresses WORM and retention mechanisms alongside isolation as complementary storage security controls, rather than presenting either as a complete answer on its own. [NCSC UK guidance](https://www.ncsc.gov.uk/blog-post/protecting-backups-from-ransomware) and the [CISA StopRansomware guide](https://www.cisa.gov/stopransomware/ransomware-guide) both recommend maintaining at least one offline backup copy in addition to immutable, network connected copies, precisely because the two address different parts of the threat model.

## When each control is appropriate

The right choice depends on the specific failure scenario a given backup copy is meant to survive, not on which control sounds more modern.

Scenario

Immutable storage alone

Physical air gap

Accidental deletion by a normal user

Sufficient

Not required for this scenario

Ransomware limited to endpoints and file shares

Usually sufficient, if correctly configured

Provides additional assurance

Attacker with domain administrator access

Not sufficient on its own

Required for a trusted last copy

Compromise of the backup platform's own account

Not sufficient on its own

Required for a trusted last copy

Cloud provider control-plane incident

Not sufficient on its own

Required for a trusted last copy

Matching the control to the scenario it needs to survive.

## How to combine air gap and immutable backup

Combining the two is not complicated in principle, though it requires treating them as distinct layers in the recovery architecture rather than as alternative products competing for the same budget line.

Layer 1

Immutable, network connected backup for daily operational recovery

Configure compliance-mode retention where the platform supports it, and keep backup account credentials separate from general administrative accounts.

Layer 2

Separate identity domain for backup infrastructure

Ensure the credentials controlling backup and retention settings are not the same credentials an attacker would obtain through general domain compromise.

Layer 3

A physical air gap for the gold copy of last resort

Maintain at least one copy with no active network path, reconnected only through a separately controlled, audited process.

Layer 4

Test recovery from the offline copy on a defined schedule

A copy that has never been restored from is a hypothesis, not a control. Regular recovery testing closes the loop.

A layered approach that uses immutability for speed and a physical air gap for assurance.

## Where each fits in the 3-2-1-1-0 rule

The 3-2-1-1-0 rule extends the classic 3-2-1 backup rule with one additional offline copy and a requirement of zero errors on recovery testing. Immutable, network connected storage can satisfy the offsite copy requirement, but it does not satisfy the offline requirement, because it remains reachable throughout. A physical air gap is what the offline requirement in the rule is describing.

Immutable, offsite copy

Network Data 

-   Reachable over the network throughout
-   Protected from deletion within the retention window
-   Still exposed to account and identity compromise

Offline, air-gapped copy

Network Data 

-   No network path while in its isolated state
-   Unaffected by compromise of the connected estate
-   Satisfies the offline element of 3-2-1-1-0

An immutable bucket satisfies the offsite copy. It does not satisfy the offline copy, because the network path never closes.

## How Firevault applies these principles

Firevault's Offline Secure Storage® is designed to provide the physical air gap layer described in this explainer, alongside, rather than instead of, whatever immutable backup platform an organisation already runs. Storage hardware has no active network interface while offline, and scheduled, identity verified connection windows are controlled from a management plane separate from the customer's own estate, so compromise of that estate, including its identity systems and backup consoles, has no path to the offline copy.

Firevault does not position Offline Secure Storage® as a replacement for immutable, network connected backup. Immutable storage continues to do the job it does well: fast, everyday recovery. Offline Secure Storage® exists for the copy that needs to survive the day the rest of the estate, including the account controlling that immutable storage, has been compromised.

Key takeaway 

## Immutability protects the object. A physical air gap protects the copy from the account holding it

Immutable storage is a genuine, valuable control that stops data being silently altered or deleted while it remains reachable on the network. It does not, on its own, protect against compromise of the account, identity system or provider control plane that governs it. A physical air gap addresses exactly that gap by removing the network path entirely. The resilient answer is not to choose between them but to use immutable storage for fast recovery and a physical air gap for the copy that must survive everything else failing at once.

Questions 

## Frequently Asked Questions

Straight answers on how Offline Secure Storage® behaves in practice.

### Is immutable backup the same as an air gap?

### What is object lock?

### What is WORM storage?

### Can immutable backup be deleted by an attacker?

### Does immutability protect against credential compromise?

### Can retention locks be shortened or bypassed?

### What does immutable storage not protect against?

### Is a hardened backup repository the same as an air gap?

### When is immutable backup enough on its own?

### When do I need a physical air gap as well as immutable backup?

### How do air gap and immutable backup fit into the 3-2-1-1-0 rule?

### Should I choose one or the other?

## Sources and further reading

-   [NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events](https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events)
    
    Practice guide covering isolated, trusted recovery sources and the limits of protections that remain on a reachable network.
    
-   [NIST SP 800-209, Security Guidelines for Storage Infrastructure](https://csrc.nist.gov/pubs/sp/800/209/final)
    
    Guidance on storage security controls including immutability, access control and isolation as distinct layers.
    
-   [ISO/IEC 27040:2024, Storage Security](https://www.iso.org/standard/79280.html)
    
    International standard addressing WORM, retention and isolation controls within a storage security programme.
    
-   [NCSC UK, Offline Backups Guidance](https://www.ncsc.gov.uk/blog-post/protecting-backups-from-ransomware)
    
    Recommends at least one backup copy that is genuinely offline, distinct from immutable copies that remain network reachable.
    
-   [CISA, StopRansomware Guide](https://www.cisa.gov/stopransomware/ransomware-guide)
    
    Federal guidance recommending both immutable and offline backup copies as part of a layered ransomware defence.
    

Related Firevault guides

[Physical vs logical air gap](/learn/physical-vs-logical-air-gap) [The 3-2-1-1-0 backup rule](/learn/3-2-1-1-0-backup-rule) [What is Offline Secure Storage](/how-it-works/offline-secure-storage)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this explainer 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup&text=Air%20Gap%20vs%20Immutable%20Backup%3A%20How%20They%20Differ%20and%20Combine%0A%0AObject%20lock%20and%20WORM%20retention%20are%20powerful%2C%20but%20they%20are%20not%20the%20same%20control%20as%20a%20physical%20air%20gap.%20This%20explainer%20sets%20out%20what%20immutability%20actually%20protects%2C%20what%20it%20does%20not%2C%20and%20how%20the%20two%20belong%20together%20in%20a%20resilient%20backup%20architecture.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup)[](mailto:?subject=Air%20Gap%20vs%20Immutable%20Backup%3A%20How%20They%20Differ%20and%20Combine&body=Object%20lock%20and%20WORM%20retention%20are%20powerful%2C%20but%20they%20are%20not%20the%20same%20control%20as%20a%20physical%20air%20gap.%20This%20explainer%20sets%20out%20what%20immutability%20actually%20protects%2C%20what%20it%20does%20not%2C%20and%20how%20the%20two%20belong%20together%20in%20a%20resilient%20backup%20architecture.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fair-gap-vs-immutable-backup)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)