OSS, Compliance & Risk

ISO 27001 with Offline Secure Storage

ISO 27001 requires a systematic approach to information security. Offline Secure Storage (OSS) maps directly to Annex A physical and environmental controls.

  • Annex A.11 physical gaps
  • Access-control failures
  • Certified-but-breached exposure
  • Third-party control drift
View All Compliance
Rows of locked server cabinets inside a secure Firevault data hall
The evidence
01
ICO fine to Capita, ISO 27001 certified at time of breach
£14MICO fine to Capita, ISO 27001 certified at time of breachICO, October 2025
02
People affected despite Capita holding ISO 27001
6M+People affected despite Capita holding ISO 27001ICO, October 2025
03
Average time to identify and contain a breach
277 daysAverage time to identify and contain a breachIBM Cost of a Data Breach 2024
04
Average cost of a data breach globally
£4.5MAverage cost of a data breach globallyIBM Cost of a Data Breach 2024
The Gap

ISO 27001 requires physical security controls.

01

Annex A.11 Physical Security

Physical security perimeters and environmental controls are mandatory, not optional.

02

Asset Management

Critical information assets must be identified, classified, and appropriately protected.

03

Access Control

Logical and physical access controls must be proportional to asset sensitivity.

The reality

Certification alone does not prevent breaches.

Every incident below is a matter of public record. Each one involved data that was reachable from a live network at the moment of compromise.

01

Capita: £14M Fine Despite Holding ISO 27001 Certification

Capita held ISO 27001 certification at the time of its breach. The ICO still fined the company £14 million, demonstrating that certification without physical protection is insufficient.

ICO, October 2025

02

LastPass: £1.2M Fine Despite Security Company Status

LastPass, a company whose entire business is security, was fined £1.2 million by the ICO for failures that allowed hackers to steal personal data of 1.6 million UK customers.

ICO, December 2025

03

M&S: Third-Party Compromise Bypassed Certified Controls

Attackers bypassed M&S security controls by compromising a third-party provider, demonstrating that ISO 27001 supply chain controls must extend to physical protection.

Reuters, 2025

We Think This Is Hard to Ignore

M&S had ISO 27001 certification when DragonForce ransomware bypassed their certified controls via a third-party compromise. At Firevault, classified information assets live on hardware with no network connection, because Annex A.11 physical security means nothing if the data is always online.
How OSS Maps

Direct mapping to ISO 27001 controls.

Offline Secure Storage (OSS) provides physical infrastructure that directly satisfies multiple Annex A controls.

  • Physical security perimeters (A.11.1), purpose-built secure facilities
  • Equipment security (A.11.2), tamper-evident, monitored environments
  • Access control (A.9), authenticated, audited access sessions
  • Operations security (A.12), controlled processing environments

Take Classified Assets Off Standard Infrastructure

Step 1 of 3

Classified information assets are taken off standard infrastructure and written to physically disconnected RAID 1 drives inside a Firevault Bunker. This directly satisfies Annex A.11 physical security perimeter controls.

Featured In

TechRadar Pro logoYahoo Finance logoChannel Insider logoSecurity Buyer logoSecurityBrief logo
Commercial Advantage

Win Business, Earn Trust, and Build Reputation with Butterfly

Butterfly is an operational model that helps organisations structure sensitive data to close deals faster, strengthen client relationships, and demonstrate the governance maturity that wins enterprise contracts.

Built on the VPPP framework (Vault, Policy, Permissions, Purpose), Butterfly maps your sensitive data and assigns dedicated Vaults by role, relationship, and purpose, turning data stewardship into a competitive advantage.

Deal Readiness

Governed materials ready to share with confidence

Client Trust

Demonstrate stewardship that earns loyalty

Board Confidence

Clear governance that inspires stakeholders

Enterprise Scale

Structure data governance across your organisation

Butterfly deployment model

Who Uses Butterfly?

  • Sales Teams

    Secure client proposals, pricing, and commercial intelligence

  • Service Providers

    Exchange sensitive documents with clients through governed Vaults

  • Businesses

    Protect strategic plans, IP, and competitive intelligence

  • Family Offices

    Structure data governance across principals, staff, and advisors

Questions

Frequently Asked

CAF-aligned

Mapped to CAF outcomes, not certified against CAF.

Firevault is not certified against the NCSC Cyber Assessment Framework. CAF is a self-assessment framework for essential service operators. The sections below show how our products help you evidence CAF outcomes in your own submission.

Offline Secure Storage and CAF

Using Offline Secure Storage supports CAF Objective B (Protecting against cyber attack) and Objective D (Minimising the impact of incidents). Gold copies live on hardware that is physically disconnected between sessions, giving operators evidence of protective isolation and a recoverable state.

Supports outcomes

B3 Data SecurityB5 Resilient Networks & SystemsD1 Response & Recovery Planning
How OSS maps

Taking Control, deploying Blueprints and CAF

Deploying a Control Blueprint supports CAF Objective A (Managing security risk) and Objective C (Detecting cyber security events). Blueprints document identity-verified access, session logging and segregation between operational and archived data, so the controls can be pointed at CAF outcomes in a self-assessment.

Supports outcomes

A2 Risk ManagementA4 Supply ChainC1 Security Monitoring
See Control Blueprints

Deploying Firebreak and CAF

Deploying Firebreak supports CAF Objective B (Protecting against cyber attack) at the network boundary of operational technology environments. Firebreak enforces physical-layer separation between OT and IT, giving CNI operators evidence of controlled paths for CAF network security outcomes.

Supports outcomes

B2 Identity & Access ControlB4 System SecurityB5 Resilient Networks & Systems
Explore Firebreak

Firevault maps controls to CAF outcomes to help essential service operators evidence their own self-assessment. Full mapping detail is available on request.