---
title: "Lock the Door: the last line of defence | Firevault"
description: "Cyber Essentials asks you to lock the door - offline secure storage that can help remove exposed access paths to your most critical data."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/lock-the-door#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Lock the Door: the last line of defence",
          "item": "https://fire-vault.com/lock-the-door"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "name": "Lock the Door. Then Take the Crown Jewels Off the Network.",
      "description": "Cyber Essentials reduces common routes into connected systems. Offline Secure Storage changes what an attacker can still reach if those systems are compromised.",
      "url": "https://fire-vault.com/lock-the-door",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the Lock the Door campaign?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Lock the Door is a UK Government campaign launched in February 2026 by the Department for Science, Innovation and Technology and the National Cyber Security Centre. It encourages businesses to adopt the Cyber Essentials scheme to protect against common cyber threats. The campaign highlights that cyber threats cost UK businesses £14.7 billion annually and that half of all small firms have experienced a breach in the last 12 months."
          }
        },
        {
          "@type": "Question",
          "name": "What is Cyber Essentials?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Cyber Essentials is a government-backed certification scheme developed by the NCSC. It focuses on five key controls: firewalls, secure configuration, software updates, user access control, and malware protection. Organisations with Cyber Essentials in place made 92 per cent fewer insurance claims last year."
          }
        },
        {
          "@type": "Question",
          "name": "What is the difference between defence and resilience?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Defence keeps attackers out of connected systems. Resilience reduces what an attacker can still reach when those systems are compromised. Cyber Essentials is defence. Offline Secure Storage is an additional architectural control for selected data that does not need to remain continuously connected. Offline Secure Storage is not a substitute for Cyber Essentials."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/lock-the-door#webpage",
      "url": "https://fire-vault.com/lock-the-door",
      "name": "Lock the Door: the last line of defence",
      "description": "Cyber Essentials asks you to lock the door - offline secure storage that can help remove exposed access paths to your most critical data.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-home.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/lock-the-door#breadcrumb"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

UK Government campaign response, 2026 

# Lock the door. Then take the crown jewels off the network. 

Cyber Essentials reduces common routes into connected systems. Offline Secure Storage® changes what an attacker can still reach if those systems are compromised.

-   Cyber Essentials aligned
-   Physically disconnected by default
-   UK CNI-grade Bunkers

[Find what should be offline](/get-started/business)[See defence and resilience](#difference)

What changes when the asset is offline 

Internet attack path 

Connected systems 

Physical  
break 

Offline asset 

**No standing network path to the stored asset**When offline, the storage is physically disconnected. Access is deliberately established only when required. 

Disconnected 

Firevault supports Cyber Essentials. Offline Secure Storage is an additional resilience layer, not a replacement for baseline cyber controls.

Defence and resilience

Attack pathWhat goes offlineLayered strategy60-second checkCampaign source

Source: UK Government, DSIT and NCSC, 17 February 2026 

01 

Estimated annual cost of cyber threats to UK businesses

£14.7bn Estimated annual cost of cyber threats to UK businesses 

02 

Small firms experienced a breach or attack in the last 12 months

1 in 2 Small firms experienced a breach or attack in the last 12 months 

03 

Of medium and large businesses suffered a cyber incident

82% Of medium and large businesses suffered a cyber incident 

04 

Fewer insurance claims reported by organisations with Cyber Essentials

92% Fewer insurance claims reported by organisations with Cyber Essentials 

01 Defence and resilience 

## Cyber Essentials protects the connected estate. #OSS protects what does not need to stay connected.

The stronger idea is not one or the other. It is to make the connected environment harder to compromise, while reducing how much critical data remains continuously exposed to it.

01 · Lock the door

### Cyber Essentials

Five baseline controls designed to reduce exposure to common attacks across internet-connected systems.

-   01 
    
    **Firewalls**
    
    Control traffic entering and leaving your networks.
    
-   02 
    
    **Secure configuration**
    
    Remove unnecessary services and insecure defaults.
    
-   03 
    
    **Software updates**
    
    Reduce exposure to known vulnerabilities.
    
-   04 
    
    **User access control**
    
    Limit accounts, permissions and privilege.
    
-   05 
    
    **Malware protection**
    
    Help prevent and contain malicious software.
    

02 · Reduce what is reachable

### Offline Secure Storage®

For data that does not need permanent network exposure, the resilience control is architectural: physically disconnect it by default.

-   01 
    
    **Physical disconnection**
    
    The stored asset has no standing network path while offline.
    
-   02 
    
    **Dedicated hardware**
    
    Critical assets are held on customer-specific storage, not a shared cloud service.
    
-   03 
    
    **Controlled access**
    
    Connectivity is deliberately established for approved access, then removed again.
    
-   04 
    
    **Recovery independence**
    
    Keep clean copies outside the same connected attack path as production.
    
-   05 
    
    **Evidence of control**
    
    Make offline an operational state you can prove, not just a backup policy.
    

02 The structural question 

## What can the attacker still reach after the first control fails?

Security programmes often focus on stopping entry. The resilience question starts one step later: if identity, endpoint or network controls are bypassed, what remains inside the same reachable environment?

**Typical connected attack path**Example, not a threat model for every organisation 

01 **Identity or endpoint compromised**

02 **Privileges and sessions abused**

03 **Connected storage discovered**

04 **Backups, data or admin planes targeted**

05 **Business impact expands**

**#OSS changes step 03.**

If selected assets are physically offline, compromise of the connected estate does not automatically provide a live path to those copies.

Path removed while offline 

03 Do not take everything offline 

## Take the right things offline.

Offline storage works best when it is applied deliberately to the small proportion of data whose loss, theft or corruption would create disproportionate harm.

IP 

### Intellectual property

Source code, designs, patents, research, engineering files and proprietary methods.

GC 

### Gold copies

Known-clean recovery data kept outside the connected production and backup estate.

PII 

### Sensitive personal data

Identity, customer, employee, medical or other high-impact personal records.

BRD 

### Board and executive records

Strategic documents, confidential decisions, transaction material and governance evidence.

LEG 

### Privileged and legal material

Client files, litigation evidence, matter archives and other information where confidentiality matters.

OPS 

### Operational recovery assets

Configuration, runbooks, credentials and documentation needed to recover without the primary environment.

04 A layered strategy 

## Lock the door. Limit the path. Protect the asset. Prove recovery.

A practical sequence, rather than a long comparison between two technologies.

01 / Defend

### Implement Cyber Essentials

Start with the five controls the UK Government and NCSC are asking organisations to put in place.

Connected defence 

02 / Reduce

### Reduce standing access

Remove unnecessary pathways, privileges and always-on access to systems that do not require them.

Attack-surface control 

03 / Disconnect

### Move crown jewels offline

Physically disconnect selected data and digital assets when they are not being used.

Offline Secure Storage® 

04 / Recover

### Test independent recovery

Know what you can restore, from where, under whose authority and without relying on the compromised environment.

Business resilience 

05 60-second check 

## How exposed are your crown jewels?

Select the statements that are true today. This is a simple discussion aid, not a security assessment.

**0/6**

There may be a resilience gap worth examining. Start by identifying the data your business cannot afford to lose or expose.

[Talk through your result](/contact)

-   **Our crown-jewel data is clearly identified.**We know which information would create the greatest harm if stolen, encrypted or lost. 
-   **We hold a clean copy outside our primary environment.**Recovery does not depend entirely on the same identity, network or admin plane. 
-   **At least one critical copy is physically offline.**Not simply immutable or logically separated, but without a standing network path. 
-   **Access to offline copies is controlled and auditable.**We know who can request access and what has to happen before connectivity is restored. 
-   **We have tested recovery without production systems.**Our continuity plan has been exercised against a realistic compromise scenario. 
-   **Cyber Essentials is in place or actively being implemented.**Our baseline connected controls are not being replaced by an offline strategy. 

06 Side by side 

## Defence and resilience solve different parts of the same problem.

The distinction should be simple enough to understand in seconds, without diminishing the value of Cyber Essentials.

Question

Cyber Essentials

Cyber Essentials + #OSS

**How do we reduce common attack routes?**Five baseline security controls across the connected estate. The same baseline controls remain essential. 

**What happens if an attacker still gets in?**Incident response and recovery controls take over. Selected data can already sit outside the live network path. 

**Can ransomware reach every recovery copy?**Depends on the organisation's backup and access architecture. A physically offline copy has no live network path while disconnected. 

**Is critical data continuously reachable?**May be, depending on the service and configuration. Not when the selected OSS asset is in its offline state. 

**Important: Offline Secure Storage® is not a substitute for Cyber Essentials.**

Cyber Essentials helps protect connected systems from common attacks. Offline Secure Storage is an additional architectural control for selected data that does not need to remain continuously connected.

**Campaign source.** UK Government, Department for Science, Innovation and Technology and the National Cyber Security Centre, "Businesses urged to lock the door on cyber criminals as new government campaign launches", published 17 February 2026.

[Read the GOV.UK source](https://www.gov.uk/government/news/businesses-urged-to-lock-the-door-on-cyber-criminals-as-new-government-campaign-launches)

07 The next question 

## Which data should still be reachable if your connected estate is compromised?

Map your crown jewels, decide what genuinely needs permanent connectivity, and build an offline layer around the assets that do not.

[Find what should be offline](/get-started/business)[How #OSS works](/why-oss)