---
title: "Credential Governance Guide: storing keys | Firevault"
description: "Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/credential-governance#webpage",
      "url": "https://fire-vault.com/learn/guides/credential-governance",
      "name": "Credential Governance Guide: storing keys",
      "description": "Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcredential-governance.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/credential-governance#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/credential-governance#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Credential Governance: Managing Your Keys",
          "item": "https://fire-vault.com/learn/guides/credential-governance"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Credential Governance: Managing Your Keys",
      "description": "Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.",
      "url": "https://fire-vault.com/learn/guides/credential-governance",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcredential-governance.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:13:51.962911+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/credential-governance"
      },
      "inLanguage": "en-GB",
      "articleSection": "Security",
      "wordCount": 519,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Credentials Are the Real TargetThe Credential Dependency MapThe Three Tiers of Credential Go…Why Tier 3 Demands Physical Disc…Credential Governance LifecycleConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Security 

Security · 19 February 2026 

# Credential Governance: Managing Your Keys

Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcredential-governance)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcredential-governance&text=Credential%20Governance%3A%20Managing%20Your%20Keys%0A%0AEvery%20system%2C%20every%20backup%2C%20every%20recovery%20procedure%20depends%20on%20credentials.%20When%20those%20credentials%20are%20compromised%20or%20inaccessible%2C%20technical%20capability%20becomes%20irrelevant.%20Credential%20governance%20through%20OSS%20ensures%20the%20keys%20to%20your%20kingdom%20survive%20any%20incident.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcredential-governance)[](mailto:?subject=Credential%20Governance%3A%20Managing%20Your%20Keys&body=Every%20system%2C%20every%20backup%2C%20every%20recovery%20procedure%20depends%20on%20credentials.%20When%20those%20credentials%20are%20compromised%20or%20inaccessible%2C%20technical%20capability%20becomes%20irrelevant.%20Credential%20governance%20through%20OSS%20ensures%20the%20keys%20to%20your%20kingdom%20survive%20any%20incident.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcredential-governance)

![Credential Governance: Managing Your Keys](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcredential-governance.jpg)

Security 

Why it matters

## What this means for organisations holding critical data

Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.

**On this page**[Credentials Are the Real Target](#section-0)[The Credential Dependency Map](#section-1)[The Three Tiers of Credential Go…](#section-2)[Why Tier 3 Demands Physical Disc…](#section-3)[Credential Governance Lifecycle](#section-4)[Conclusion](#section-5)

On this page

1.  [Credentials Are the Real Target](#section-0)
2.  [The Credential Dependency Map](#section-1)
3.  [The Three Tiers of Credential Governance](#section-2)
4.  [Why Tier 3 Demands Physical Disconnection](#section-3)
5.  [Credential Governance Lifecycle](#section-4)
6.  [Conclusion](#section-5)

## Credentials Are the Real Target

In 86% of breaches involving ransomware, the attacker had valid credentials before deploying encryption. They did not break through a firewall or exploit a zero-day. They logged in. With legitimate usernames and passwords, obtained through phishing, credential stuffing, or purchasing them on the dark web.

This means the most valuable asset in your organisation is not your data. It is the credentials that control access to your data, your backups, your cloud consoles, and your recovery systems. Govern the credentials, and you govern everything.

## The Credential Dependency Map

Most organisations have no single view of which credentials their critical operations depend on. To build one, trace backwards from your most important business processes:

-   **Email recovery:** What credentials are needed to restore Exchange or Microsoft 365?
-   **Backup restoration:** What login is required for the backup console? Where is the encryption passphrase?
-   **Domain recovery:** What is the domain admin password? The DSRM password?
-   **Cloud console access:** What are the root account credentials for AWS, Azure, or GCP?
-   **DNS management:** Who controls your domain registrar account?
-   **Certificate authority:** Where is the root CA private key? Who can issue certificates?

Each of these represents a single point of failure. If the credential is compromised, the attacker controls the system. If the credential is inaccessible, recovery is impossible.

## The Three Tiers of Credential Governance

### Tier 1: Operational Credentials

Day-to-day login credentials managed through your identity provider, password manager, and multi-factor authentication. These are well-understood and widely governed.

### Tier 2: Administrative Credentials

Privileged access credentials for system administration, cloud console management, and security tool configuration. These should be managed through privileged access management (PAM) solutions with session recording and just-in-time access.

### Tier 3: Recovery Credentials

Break-glass access codes, backup encryption passphrases, root CA private keys, and emergency access tokens. These are the credentials of last resort, used only when Tier 1 and Tier 2 systems have failed. They require physical governance because they must survive the failure of every connected system.

## Why Tier 3 Demands Physical Disconnection

Tier 3 credentials have a unique requirement: they must be available when every connected system has failed. Storing them in a password manager, a cloud vault, or an encrypted file defeats their purpose, because these systems may be exactly what you are trying to recover.

Physical disconnection through OSS resolves this paradox. Recovery credentials stored in hardware with no network interface remain accessible regardless of what happens to your connected infrastructure. They cannot be encrypted, exfiltrated, or deleted by any network-based attack.

## Credential Governance Lifecycle

1.  **Identify:** Map every Tier 3 credential your recovery depends on
2.  **Capture:** Record current values through controlled, verified procedures
3.  **Store:** Place in [physically disconnected storage](/storage) with identity-verified access
4.  **Rotate:** When credentials change, update offline copies through governed transfer procedures
5.  **Verify:** Quarterly verification that offline credentials remain current and valid
6.  **Test:** Annual recovery exercises that include accessing offline credentials under simulated incident conditions

## Conclusion

Credentials are the most valuable and most vulnerable assets in any organisation. Governing Tier 3 recovery credentials through [Offline Secure Storage](/offline-secure-storage)® ensures that when everything else has failed, the keys to recovery remain in your hands.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Backup and Recovery Architecture Guide: 3-2-1, 3-2-1-1-0, Immutability and Offline Copies
    
    The consolidated technical guide to backup and recovery architecture: what 3-2-1 and 3-2-1-1-0 mean, how immutability actually works, where offline copies differ, and how to design and test a recovery path.
    
    Read guide ](/learn/guides/backup-and-recovery-architecture-guide)
-   [
    
    ### NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
    
    A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.
    
    Read guide ](/learn/guides/ncsc-caf-guide)
-   [
    
    ### NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
    
    A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.
    
    Read guide ](/learn/guides/nist-csf-2-0-guide)
-   [
    
    ### Cost of Paying Ransoms: Why Payers Still Lose
    
    Paying a ransom does not end a ransomware incident. It begins a longer, more expensive, and more damaging process that organisations without recovery independence are forced into. Understanding the true cost changes the calculation entirely.
    
    Read guide ](/learn/guides/cost-of-paying-ransoms)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up