---
title: "Crown Jewels Audit Guide: what data deserves | Firevault"
description: "Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/crown-jewels-audit#webpage",
      "url": "https://fire-vault.com/learn/guides/crown-jewels-audit",
      "name": "Crown Jewels Audit Guide: what data deserves",
      "description": "Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcrown-jewels-audit.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/crown-jewels-audit#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/crown-jewels-audit#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Crown Jewels Audit: What Deserves Disconnection",
          "item": "https://fire-vault.com/learn/guides/crown-jewels-audit"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Crown Jewels Audit: What Deserves Disconnection",
      "description": "Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.",
      "url": "https://fire-vault.com/learn/guides/crown-jewels-audit",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcrown-jewels-audit.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:13:51.962911+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/crown-jewels-audit"
      },
      "inLanguage": "en-GB",
      "articleSection": "Strategic Planning",
      "wordCount": 587,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Not Everything Is a Crown JewelThe Three QuestionsThe Five Categories of Crown JewelsConducting the AuditCommon MistakesConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Strategic Planning 

Strategic Planning · 19 February 2026 

# Crown Jewels Audit: What Deserves Disconnection

Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcrown-jewels-audit)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcrown-jewels-audit&text=Crown%20Jewels%20Audit%3A%20What%20Deserves%20Disconnection%0A%0ANot%20everything%20needs%20to%20go%20offline.%20The%20Crown%20Jewels%20Audit%20is%20a%20structured%20framework%20for%20identifying%20exactly%20which%20assets%20deserve%20the%20protection%20that%20only%20physical%20disconnection%20can%20provide.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcrown-jewels-audit)[](mailto:?subject=Crown%20Jewels%20Audit%3A%20What%20Deserves%20Disconnection&body=Not%20everything%20needs%20to%20go%20offline.%20The%20Crown%20Jewels%20Audit%20is%20a%20structured%20framework%20for%20identifying%20exactly%20which%20assets%20deserve%20the%20protection%20that%20only%20physical%20disconnection%20can%20provide.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcrown-jewels-audit)

![Crown Jewels Audit: What Deserves Disconnection](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcrown-jewels-audit.jpg)

Strategic Planning 

Why it matters

## What this means for organisations holding critical data

Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.

**On this page**[Not Everything Is a Crown Jewel](#section-0)[The Three Questions](#section-1)[The Five Categories of Crown Jewels](#section-2)[Conducting the Audit](#section-3)[Common Mistakes](#section-4)[Conclusion](#section-5)

On this page

1.  [Not Everything Is a Crown Jewel](#section-0)
2.  [The Three Questions](#section-1)
3.  [The Five Categories of Crown Jewels](#section-2)
4.  [Conducting the Audit](#section-3)
5.  [Common Mistakes](#section-4)
6.  [Conclusion](#section-5)

## Not Everything Is a Crown Jewel

The instinct to protect everything equally is the enemy of effective protection. When organisations treat all data with the same level of security, they dilute their defences and overspend on assets that do not warrant it, while under-protecting the handful of assets whose compromise would be genuinely existential.

The Crown Jewels Audit is a structured process for identifying exactly which assets require the strongest possible protection: physical disconnection through [Offline Secure Storage](/offline-secure-storage)®.

## The Three Questions

For every digital asset your organisation holds, ask three questions:

1.  **If this asset were encrypted tomorrow, could we still recover our business?** If the answer is no, it is a crown jewel.
2.  **If this asset were exfiltrated and published, would the damage be existential?** If the answer is yes, it is a crown jewel.
3.  **If this asset were silently modified without detection, could it undermine our entire security posture?** If the answer is yes, it is a crown jewel.

Most organisations discover they have between 15 and 40 crown jewels. Not thousands. Not hundreds. A focused set of assets that, if compromised, would fundamentally alter the organisation's ability to operate, recover, or survive.

## The Five Categories of Crown Jewels

### 1\. Recovery Credentials

Domain administrator passwords, break-glass access codes, service account credentials, and emergency access tokens. These are the keys that unlock recovery. If they are encrypted alongside production data, recovery becomes a negotiation, not a procedure.

### 2\. Cryptographic Material

Root CA private keys, intermediate certificates, code signing keys, and encryption master keys. Certificate infrastructure compromise enables attackers to impersonate trusted systems, issue fraudulent certificates, and maintain persistent access even after remediation.

### 3\. Privileged Communications

Legal privilege files, board minutes covering sensitive strategy, M&A documentation, and investigation materials. These are assets whose mere exposure creates liability, regardless of whether they are modified.

### 4\. Governance Documentation

Incident response playbooks, [business continuity](/solutions/oss) plans, recovery procedures, and regulatory notification templates. These documents were written for the exact scenario in which they become inaccessible. They must survive the incident they describe.

### 5\. Identity-Critical Data

Biometric templates, identity verification records, and authentication system configurations. Once compromised, identity data cannot be reissued. You cannot change someone's fingerprint.

## Conducting the Audit

1.  **Assemble stakeholders.** Include IT, legal, finance, operations, and the board secretary. Crown jewels are not exclusively technical assets.
2.  **Map dependencies.** For each critical business process, trace the chain of dependencies backwards until you reach the foundational assets. These are your candidates.
3.  **Apply the three questions.** Systematically evaluate each candidate against the encryption, exfiltration, and modification tests.
4.  **Classify and prioritise.** Not all crown jewels require immediate action. Prioritise based on current exposure and consequence severity.
5.  **Document and govern.** Create a Crown Jewels Register with ownership, update schedules, and access controls for each asset.

## Common Mistakes

-   **Including too much.** If your crown jewels list exceeds 50 items, you have not been selective enough. Physical disconnection is for the vital few, not the trivial many.
-   **Forgetting non-digital assets.** The combination to the server room safe, the location of physical backup tapes, the personal mobile numbers of your incident response team: these are crown jewels too.
-   **Static lists.** Crown jewels change as the organisation evolves. The audit should be repeated annually and after any significant organisational change.

## Conclusion

The Crown Jewels Audit transforms data protection from a blanket exercise into a precise, strategic discipline. By identifying exactly which assets deserve physical disconnection, organisations can allocate their strongest protections where they matter most, and demonstrate to regulators, insurers, and boards that their approach is deliberate, proportionate, and governed.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
    
    A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.
    
    Read guide ](/learn/guides/ncsc-caf-guide)
-   [
    
    ### NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
    
    A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.
    
    Read guide ](/learn/guides/nist-csf-2-0-guide)
-   [
    
    ### Cyber Insurance and Physical Controls
    
    Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.
    
    Read guide ](/learn/guides/cyber-insurance-physical-controls)
-   [
    
    ### Credential Governance: Managing Your Keys
    
    Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.
    
    Read guide ](/learn/guides/credential-governance)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up