---
title: "Operating Without Systems Guide: incident | Firevault"
description: "When every connected system is encrypted or compromised, how does your team actually operate? This guide covers the practical reality of incident response…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/operating-without-systems#webpage",
      "url": "https://fire-vault.com/learn/guides/operating-without-systems",
      "name": "Operating Without Systems Guide: incident",
      "description": "When every connected system is encrypted or compromised, how does your team actually operate? This guide covers the practical reality of incident response…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Foperating-without-systems.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/operating-without-systems#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/operating-without-systems#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Operating Without Systems: Incident Response",
          "item": "https://fire-vault.com/learn/guides/operating-without-systems"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Operating Without Systems: Incident Response",
      "description": "When every connected system is encrypted or compromised, how does your team actually operate? This guide covers the practical reality of incident response when your tools, communications, and documentation are all unavailable.",
      "url": "https://fire-vault.com/learn/guides/operating-without-systems",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Foperating-without-systems.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:16:21.25498+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/operating-without-systems"
      },
      "inLanguage": "en-GB",
      "articleSection": "Incident Response",
      "wordCount": 592,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The First Thirty MinutesCommunication Without Infrastruc…Decision-Making Without DataRecovery Without CredentialsThe First 24 Hours: A Practical …What This Looks Like in PracticeConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Incident Response 

Incident Response · 19 February 2026 

# Operating Without Systems: Incident Response

When every connected system is encrypted or compromised, how does your team actually operate? This guide covers the practical reality of incident response when your tools, communications, and documentation are all unavailable.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Foperating-without-systems)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Foperating-without-systems&text=Operating%20Without%20Systems%3A%20Incident%20Response%0A%0AWhen%20every%20connected%20system%20is%20encrypted%20or%20compromised%2C%20how%20does%20your%20team%20actually%20operate%3F%20This%20guide%20covers%20the%20practical%20reality%20of%20incident%20response%20when%20your%20tools%2C%20communications%2C%20and%20documentation%20are%20all%20unavailable.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Foperating-without-systems)[](mailto:?subject=Operating%20Without%20Systems%3A%20Incident%20Response&body=When%20every%20connected%20system%20is%20encrypted%20or%20compromised%2C%20how%20does%20your%20team%20actually%20operate%3F%20This%20guide%20covers%20the%20practical%20reality%20of%20incident%20response%20when%20your%20tools%2C%20communications%2C%20and%20documentation%20are%20all%20unavailable.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Foperating-without-systems)

![Operating Without Systems: Incident Response](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Foperating-without-systems.jpg)

Incident Response 

Why it matters

## What this means for organisations holding critical data

When every connected system is encrypted or compromised, how does your team actually operate? This guide covers the practical reality of incident response when your tools, communications, and documentation are all unavailable.

**On this page**[The First Thirty Minutes](#section-0)[Communication Without Infrastruc…](#section-1)[Decision-Making Without Data](#section-2)[Recovery Without Credentials](#section-3)[The First 24 Hours: A Practical …](#section-4)[What This Looks Like in Practice](#section-5)[Conclusion](#section-6)

On this page

1.  [The First Thirty Minutes](#section-0)
2.  [Communication Without Infrastructure](#section-1)
3.  [Decision-Making Without Data](#section-2)
4.  [Recovery Without Credentials](#section-3)
5.  [The First 24 Hours: A Practical Sequence](#section-4)
6.  [What This Looks Like in Practice](#section-5)
7.  [Conclusion](#section-6)

## The First Thirty Minutes

The call comes at 3:00 AM. Ransomware has been deployed across your infrastructure. Domain controllers are encrypted. Email is down. The VPN concentrator is offline. Your team cannot access the building management system, the phone system, or the incident response platform.

This is not a drill scenario. It is the lived experience of thousands of UK organisations every year. And the first thirty minutes determine everything that follows.

## Communication Without Infrastructure

The most immediate challenge is coordination. Your team needs to communicate, but every corporate communication channel depends on infrastructure that may be compromised.

### Pre-Staged Communication Channels

-   **Personal mobile numbers:** A printed or offline-stored list of key personnel mobile numbers enables basic coordination
-   **Pre-configured messaging groups:** Signal or WhatsApp groups created before the incident, using personal devices, provide encrypted team communication
-   **Out-of-band conference bridges:** Pre-arranged dial-in numbers for conference calls that do not depend on corporate infrastructure

Every one of these requires prior preparation. The contact list must exist before the incident. The messaging groups must be created before the incident. The conference bridge must be arranged before the incident. [Offline Secure Storage](/offline-secure-storage)® ensures this preparation survives the incident.

## Decision-Making Without Data

Your monitoring dashboards are encrypted. Your asset inventory is inaccessible. Your network topology documentation is on SharePoint. How do you make informed containment decisions?

### Pre-Staged Decision Support

-   **Network topology maps:** Printed or offline-stored diagrams of your network architecture enable containment decisions without access to monitoring tools
-   **Critical services list:** A prioritised list of business services and their infrastructure dependencies guides recovery sequencing
-   **Vendor contact matrix:** Third-party support contacts, contract numbers, and escalation procedures enable external assistance

## Recovery Without Credentials

Your backup console requires Active Directory authentication. Your cloud console uses SSO. Your password manager is on a server that is encrypted. How do you actually begin recovery?

### Break-Glass Credential Packs

Maintain offline copies of every credential needed to begin recovery from a total compromise:

-   Local administrator passwords for key servers
-   Backup console local authentication credentials
-   Cloud console root account credentials (not federated)
-   DNS registrar account access
-   Certificate authority root key material
-   Firewall and switch local admin credentials

## The First 24 Hours: A Practical Sequence

1.  **Hour 0 to 1:** Establish communication, assess scope, activate incident response team using offline contact details
2.  **Hour 1 to 4:** Contain the attack using network topology documentation. Isolate affected segments. Preserve forensic evidence
3.  **Hour 4 to 12:** Begin recovery using offline credentials. Prioritise identity infrastructure (domain controllers), then communication (email), then business-critical applications
4.  **Hour 12 to 24:** Initiate regulatory notification using pre-staged templates. Brief the board. Engage external support using vendor contact matrix

## What This Looks Like in Practice

An organisation with offline secure storage accesses their Vault within the first hour. They retrieve the incident response pack containing contact lists, credential packs, network documentation, and notification templates. Within four hours, they have contained the attack and begun recovery. Within 24 hours, they have restored core business services and initiated regulatory notification.

An organisation without offline preparation spends the first 24 hours trying to work out who to call, what credentials they need, and how to access their backup systems. Recovery takes weeks instead of hours.

## Conclusion

Operating without systems is not a theoretical exercise. It is the reality of major cyber incidents. The organisations that recover in hours are those that prepared for exactly this scenario by maintaining critical response assets in [physically disconnected storage](/storage). The preparation must happen before the incident. The offline storage must be in place before the attack. There is no improvisation that compensates for prior governance.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Backup and Recovery Architecture Guide: 3-2-1, 3-2-1-1-0, Immutability and Offline Copies
    
    The consolidated technical guide to backup and recovery architecture: what 3-2-1 and 3-2-1-1-0 mean, how immutability actually works, where offline copies differ, and how to design and test a recovery path.
    
    Read guide ](/learn/guides/backup-and-recovery-architecture-guide)
-   [
    
    ### Cost of Paying Ransoms: Why Payers Still Lose
    
    Paying a ransom does not end a ransomware incident. It begins a longer, more expensive, and more damaging process that organisations without recovery independence are forced into. Understanding the true cost changes the calculation entirely.
    
    Read guide ](/learn/guides/cost-of-paying-ransoms)
-   [
    
    ### Credential Governance: Managing Your Keys
    
    Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.
    
    Read guide ](/learn/guides/credential-governance)
-   [
    
    ### Recovery Independence: No Compromise
    
    The single greatest weakness in most disaster recovery strategies is circular dependency: the plan to recover from a system compromise is stored on systems that can themselves be compromised. Recovery independence eliminates this fatal flaw.
    
    Read guide ](/learn/guides/recovery-independence)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up