---
title: "When Access Fails: Continuity Needs Offline Sec… | Firevault"
description: "Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline,…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity#webpage",
      "url": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity",
      "name": "When Access Fails: Continuity Needs Offline Sec…",
      "description": "Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline,…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "When Access Fails: Continuity Needs Offline Secure Storage",
          "item": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "When Access Fails: Continuity Needs Offline Secure Storage",
      "description": "Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.",
      "url": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-18T07:58:32.908511+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity"
      },
      "inLanguage": "en-GB",
      "articleSection": "Industry Insight",
      "wordCount": 1792,
      "keywords": "When, Industry Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Wildfire, flood, heat and grid stress are the disruptions that make the news, so continuity planning tends to be written around them. That framing is too narrow. The organisations we work with lose access to their own records for reasons that have nothing to do with weather: a cloud region fails, a subsea cable is cut, a software supplier is breached, an identity provider locks out every user, an ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How Do I Know Which Records Belong Offline?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Start from recovery rather than from storage. List the decisions and actions required in the first 72 hours of a serious disruption, then identify the records each one depends on. Anything on that list which exists only inside the environment you would be recovering, or only inside a single provider, belongs offline. Most organisations find the genuine set is far smaller than expected, which makes the control affordable."
          }
        },
        {
          "@type": "Question",
          "name": "Is Immutable Cloud Storage Not the Same Thing?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Immutability protects a copy from being altered or deleted. It does not remove the copy from the network, and it does not survive the loss of the platform, the region, the contract or the credentials that reach it. Immutable cloud storage and offline storage answer different questions, and mature continuity plans use both. The comparison is set out in air gap versus immutable backup."
          }
        },
        {
          "@type": "Question",
          "name": "How Quickly Can Offline Records Be Retrieved?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Retrieval is a governed process rather than an instant read, and that is deliberate. Access requires verified identity and, where appropriate, dual authorisation, with the release logged. The practical point for continuity planning is that retrieval time is known, documented and rehearsable, rather than dependent on whether a network happens to be available."
          }
        },
        {
          "@type": "Question",
          "name": "Does This Only Matter for Large Organisations?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Smaller organisations are usually more exposed, because a single site, a single provider or a single administrator often represents the whole estate. A modest offline tier holding recovery keys, contracts and insurance evidence changes the recovery profile of a small firm more than it changes that of a large one."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

It Is Not Just the GridThe Failure Mode Is Always Acces…Why Continuity Plans Still Run o…What Belongs OfflineThe Retrieval Process Is the Pro…Sector RealityWhere This Sits in Recognised Fr…A Question of ResponsibilityHow Do I Know Which Records Belo…Is Immutable Cloud Storage Not t…How Quickly Can Offline Records …Does This Only Matter for Large …What to Do NextMore Resources

[Knowledge Vault](/learn/knowledge)/ [Insight](/learn/knowledge?filter=insight)

Insight · Industry Insight · 18 August 2026 

# When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

9 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fwhen-the-grid-fails-offline-secure-storage-business-continuity)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fwhen-the-grid-fails-offline-secure-storage-business-continuity&text=When%20Access%20Fails%3A%20Continuity%20Needs%20Offline%20Secure%20Storage%0A%0AFire%20and%20grid%20failure%20are%20only%20one%20of%20six%20ways%20organisations%20lose%20access%20to%20their%20own%20records.%20A%20practical%20case%20for%20holding%20critical%20material%20offline%2C%20whatever%20the%20cause.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fwhen-the-grid-fails-offline-secure-storage-business-continuity)[](mailto:?subject=When%20Access%20Fails%3A%20Continuity%20Needs%20Offline%20Secure%20Storage&body=Fire%20and%20grid%20failure%20are%20only%20one%20of%20six%20ways%20organisations%20lose%20access%20to%20their%20own%20records.%20A%20practical%20case%20for%20holding%20critical%20material%20offline%2C%20whatever%20the%20cause.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fwhen-the-grid-fails-offline-secure-storage-business-continuity)

![A reinforced secure vault door inside a resilient concrete facility, representing physical data protection during natural disasters and infrastructure failure.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/when-the-grid-fails-offline-secure-storage-business-continuity-2026.jpg)

A reinforced secure vault door inside a resilient concrete facility, representing physical data protection during natural disasters and infrastructure failure.

Why it matters

## What this means for organisations holding critical data

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

In this analysis

1.  01 [It Is Not Just the Grid](#section-0)
2.  02 [The Failure Mode Is Always Acces…](#section-1)
3.  03 [Why Continuity Plans Still Run o…](#section-2)
4.  04 [What Belongs Offline](#section-3)
5.  05 [The Retrieval Process Is the Pro…](#section-4)
6.  06 [Sector Reality](#section-5)

**On this page**[It Is Not Just the Grid](#section-0)[The Failure Mode Is Always Acces…](#section-1)[Why Continuity Plans Still Run o…](#section-2)[What Belongs Offline](#section-3)[The Retrieval Process Is the Pro…](#section-4)[Sector Reality](#section-5)[Where This Sits in Recognised Fr…](#section-6)[A Question of Responsibility](#section-7)[How Do I Know Which Records Belo…](#section-8)[Is Immutable Cloud Storage Not t…](#section-9)[How Quickly Can Offline Records …](#section-10)[Does This Only Matter for Large …](#section-11)

Wildfire, flood, heat and grid stress are the disruptions that make the news, so continuity planning tends to be written around them. That framing is too narrow. The organisations we work with lose access to their own records for reasons that have nothing to do with weather: a cloud region fails, a subsea cable is cut, a software supplier is breached, an identity provider locks out every user, an administrator deletes the wrong container, a building becomes a crime scene. The cause changes. The consequence does not. Authorised people cannot reach authoritative records at the exact moment those records decide how fast, and how expensively, the organisation recovers.

This is not an argument against cloud computing. It is an argument against single points of failure, and an argument for holding a curated portion of what matters most somewhere that neither nature, accident, negligence nor an attacker can reach across a network.

## It Is Not Just the Grid

Continuity is a question of failure domains rather than weather. A plan is only as good as the number of independent domains it can survive. In practice, six categories account for almost every loss of access we review.

-   **Environmental.** Fire, flood, storm, extreme heat, cooling failure and the power events that follow them. Physical, local, and usually the only category the plan names.
-   **Infrastructure and connectivity.** Fibre cuts during emergency works, subsea cable damage, carrier outages, routing failures. The data is intact and unreachable at the same time.
-   **Platform and provider.** A cloud region degraded, a SaaS platform breached, a supplier entering administration, a contract terminated, a tenant suspended for billing or compliance reasons. Concentration risk that no amount of internal engineering removes.
-   **Identity and access.** A compromised or misconfigured identity provider, an expired certificate, a conditional access rule applied too widely. Every system is running and nobody can log in.
-   **Malicious action.** Ransomware, extortion without encryption, and destructive attacks that specifically target the backup estate before touching production.
-   **Human and legal.** Accidental deletion, misapplied retention policies, departing administrators, seizure of equipment, or a site that cannot be entered while an investigation proceeds.

Uptime Institute's annual outage analyses have consistently found power-related failure to be the largest single cause of significant data centre incidents, ahead of networking and cooling ([Uptime Institute](https://uptimeinstitute.com/resources/research-and-reports)). The UK National Cyber Security Centre makes the parallel point on the security side, recommending that at least one backup copy be kept offline and separated from the live network, so that an attacker who reaches the network cannot reach the copy ([NCSC backup guidance](https://www.ncsc.gov.uk/collection/device-security-guidance/managing-deployed-devices/backups)). Two disciplines, environmental resilience and cyber resilience, arrive at the same control: separation.

## The Failure Mode Is Always Access, Not Storage

In almost every disruption we review, the data still exists. What fails is the path to it. That distinction matters because most continuity investment goes into making copies, and comparatively little goes into guaranteeing that at least one copy can be reached when the usual route is gone.

A copy that shares a network, an identity system, a provider or a building with the thing it protects is not an independent copy. It is the same risk written twice.

## Why Continuity Plans Still Run on Paper

Walk into a serious incident management room and you will find paper. Paper continuity plans, paper call trees, printed recovery runbooks. The reason has nothing to do with nostalgia. Paper does not need electricity. It does not need single sign-on. It cannot be encrypted by ransomware, deleted by a script or suspended by a supplier.

Paper is also a poor long-term control. It burns and floods. It is difficult to keep current, so the version in the folder is rarely the version in force. It cannot be reached by a distributed team. It offers no record of who read what, and when, which matters when a regulator later asks how decisions were made. For decades organisations accepted those weaknesses because the alternative, keeping the same records on connected systems, felt riskier still.

That trade-off is no longer necessary. [Offline Secure Storage](/offline-secure-storage)® delivers what paper delivers, independence from the network, without giving up encryption, version control or an audit trail.

## What Belongs Offline

Offline is a tier, not a replacement. Live operations stay on connected systems. Routine backup continues to encrypted cloud storage. A small, deliberately chosen set of records is held on physically disconnected media, refreshed on a schedule and released only through identity verification.

In practice that set is usually short:

-   **Recovery material.** System recovery keys, configuration baselines, network diagrams, certificate and key escrow material. The items that make rebuilding possible, and which are frequently held only inside the environment being rebuilt.
-   **Legal and contractual records.** Deeds, leases, executed contracts, share registers, [intellectual property](/oss-for-intellectual-property) filings, matter files where a copy of record is required.
-   **Insurance and claims evidence.** Policy schedules, asset registers, valuations, condition photographs. Claims move faster when evidence survives the event.
-   **Regulatory and audit evidence.** Attestations, board minutes, decision logs, retention records that must remain provable after an incident.
-   **Identity and continuity data.** Emergency contact information, delegated authority records, supplier escalation routes, and the exit material you would need if a provider disappeared.

If a record would change the speed or the cost of your recovery, it is a candidate. If it merely supports daily work, it is not.

## The Retrieval Process Is the Product

Storage is the easy half. An offline copy that nobody can retrieve under pressure is a dark archive, and dark archives fail audits as reliably as they fail incidents. The control that makes offline storage credible is the release process: verified identity, dual authorisation where the record justifies it, defined turnaround, and an immutable log of every request and release.

That is the distinction between a disconnected copy and a governed one. It also gives continuity leaders something they can rehearse. A continuity plan that has never tested retrieval has not been tested.

## Sector Reality

Different sectors feel the same failure differently.

-   **Legal.** Matter files, undertakings and deeds carry obligations that survive any outage. Solicitors, partners and paralegals need a copy of record that does not depend on the firm's practice management system, or its hosting provider, being reachable. See [Offline Secure Storage® for legal](/oss-for-legal).
-   **Accountancy and professional services.** Client records, working papers and filing deadlines do not move because a platform failed. Deadlines are statutory; connectivity is not.
-   **Energy, water and industrial operations.** Where operational technology is involved, recovery depends on engineering material held away from the affected network. This is the same reasoning behind [Firevault Control](/solutions/control) blueprints.
-   **Healthcare and education.** Continuity of care and continuity of records both depend on documents that remain readable when the estate does not.
-   **Boards and directors.** Personal liability does not pause during a disruption, whatever caused it. Demonstrable technical measures are part of the defence. See [Offline Secure Storage® for directors and boards](/oss-for-directors-and-boards).

## Where This Sits in Recognised Frameworks

None of this is novel. ISO 22301 asks organisations to identify their minimum viable operating requirements and the resources needed to meet them, without limiting the scenarios considered. The 3-2-1-1-0 backup convention, now common in cyber insurance underwriting, asks explicitly for one offline or immutable copy and zero errors on verification, which we cover in [the 3-2-1-1-0 rule](/learn/3-2-1-1-0-backup-rule). The NCSC and FEMA both frame resilience as redundancy across independent failure domains ([FEMA continuity guidance](https://www.fema.gov/emergency-managers/national-preparedness/continuity)).

[Physically disconnected storage](/storage) is simply redundancy applied to the data layer, using a failure domain that a network event cannot cross.

## A Question of Responsibility

There is always a temptation, after a disaster, to present a product as the answer to the catastrophe that has just unfolded. That is not the intention here. Firevault was built on the belief that data protection should be physical as well as logical, and that the right moment to prepare for disruption is before it arrives.

Fires and heatwaves are warnings rather than sales opportunities, and they are only one warning among several. They remind us that infrastructure we treat as invisible is physical, contractual and fragile. The organisations that recover fastest will not be the ones with the most subscriptions. They will be the ones that kept a governed copy of what matters in a place that a fire, a fibre cut, a failed provider or a stolen credential cannot reach.

## How Do I Know Which Records Belong Offline?

Start from recovery rather than from storage. List the decisions and actions required in the first 72 hours of a serious disruption, then identify the records each one depends on. Anything on that list which exists only inside the environment you would be recovering, or only inside a single provider, belongs offline. Most organisations find the genuine set is far smaller than expected, which makes the control affordable.

## Is Immutable Cloud Storage Not the Same Thing?

Immutability protects a copy from being altered or deleted. It does not remove the copy from the network, and it does not survive the loss of the platform, the region, the contract or the credentials that reach it. Immutable cloud storage and offline storage answer different questions, and mature continuity plans use both. The comparison is set out in [air gap versus immutable backup](/learn/air-gap-vs-immutable-backup).

## How Quickly Can Offline Records Be Retrieved?

Retrieval is a governed process rather than an instant read, and that is deliberate. Access requires verified identity and, where appropriate, dual authorisation, with the release logged. The practical point for continuity planning is that retrieval time is known, documented and rehearsable, rather than dependent on whether a network happens to be available.

## Does This Only Matter for Large Organisations?

No. Smaller organisations are usually more exposed, because a single site, a single provider or a single administrator often represents the whole estate. A modest offline tier holding recovery keys, contracts and insurance evidence changes the recovery profile of a small firm more than it changes that of a large one.

## What to Do Next

The question is not whether your organisation can afford offline storage. It is whether you can afford to discover, during a fire, a flood, an outage, a supplier failure or an attack, that the records you need are on the wrong side of a broken connection.

Two practical steps. First, run the 72-hour exercise above and write down the records list. Second, test retrieval of one of those records this quarter. If either step is difficult, the plan is not yet a plan.

If you would like a second opinion on the records list, [talk to a member of the team](/contact) or [create your vault](/create-vault) and start with the material you would not want to rebuild.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation](/hero-images/cold-wallet-seed-entropy-2026-vibrant.jpg)

Industry Insight 

### Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

6 Aug 2026 4 min 







](/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough)[

![The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk](/hero-images/minnesota-water-attacks-2026-vibrant.jpg)

Industry Insight 

### The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

31 Jul 2026 5 min 







](/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk)[

![Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident](/hero-images/rogue-ai-agents-2026-vibrant.jpg)

Industry Insight 

### Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident

Firevault commentary on the first fully autonomous AI hack. Our take on what boards should do, informed by Joe Tidy's BBC reporting.

29 Jul 2026 4 min 







](/news/rogue-ai-agents-hugging-face-opinion-2026)[

![CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery](/__l5e/assets-v1/a89fcfee-ebb3-4b8f-be73-99ddac829a76/cisa-ci-fortify-isolation-recovery-1778147922771-2x.jpg)

Industry Insight 

### CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery

Insights from Mark Fermor on OT, ICS, and the underlying storage layer.

7 May 2026 7 min 







](/news/cisa-ci-fortify-isolation-recovery-firevault)[

![Data Integrity Attacks and Air Gap Defence](/__l5e/assets-v1/2afceeb3-5499-4aa5-9b5c-e555af9b8ab8/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence-1771693250462-2x.jpg)

Industry Insight 

### Data Integrity Attacks and Air Gap Defence

Data integrity attacks, a stealthier cousin to traditional ransomware, are on the rise, posing a significant threat to organisational trust and operational continuity. This article explores the growing danger of data manipulation and highlights how physically air-gapped storage offers an uncompromised defence.

21 Feb 2026 5 min 







](/news/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence)[

![Firmware Attacks and the Air Gap Defence](/__l5e/assets-v1/05135422-b1ae-4dcf-8de5-66b7067ec7ae/the-silent-sabotage-firmware-attacks-and-the-air-gap-imperative-1771434041117-2x.jpg)

Industry Insight 

### Firmware Attacks and the Air Gap Defence

Firmware attacks are a sophisticated and increasingly prevalent threat, capable of bypassing traditional security measures. This article explores the growing danger of these low-level compromises and highlights the critical role of physical air-gapped storage in providing an unbreachable last line of defence.

18 Feb 2026 5 min 







](/news/the-silent-sabotage-firmware-attacks-and-the-air-gap-imperative)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)