
When ransomware lands, the first thing modern strains do isn't encrypt your files — it's find and destroy your backups. If your only copy is reachable over the network, it's reachable by the attacker too.
The backup paradox
For years, "we have backups" was a reasonable answer to "what's your ransomware plan?". It no longer is. Attackers now spend days inside a network before triggering encryption, and they spend that time enumerating backup servers, deleting snapshots and revoking retention policies. By the time the ransom note appears, the safety net has already been cut.
The fix is conceptually simple: keep at least one copy of your data that the live environment physically or logically cannot reach or alter. That is the air gap.
What "air-gapped" really means
A true air gap separates your protected copy from the production network so completely that a compromised domain admin, a rogue insider or a piece of malware simply has no path to it. In practice this is delivered through a combination of:
- Network isolation — the backup tier is unreachable from production except during tightly controlled, one-way transfer windows.
- Immutability (WORM) — once written, data cannot be modified or deleted before its retention expires, even with stolen credentials.
- Separate authentication — the vault uses its own identity plane, so a breach of your directory doesn't hand over the backups.
The 3-2-1-1 rule
The classic 3-2-1 rule — three copies, on two media, with one off-site — still holds. The modern addition is a second "1": one copy that is air-gapped and immutable. It's the copy you restore from when everything else has been tampered with.
The question is no longer "do we have a backup?" but "do we have a backup the attacker couldn't touch?"
Recovery is the real test
An air-gapped copy you've never tested restoring is a hope, not a plan. Recovery objectives matter: how recent is the last clean copy (your RPO), and how fast can you bring services back (your RTO)? Anomaly detection helps here too — spotting the ransomware signature or the unusual deletion spike early means you can isolate and recover before the blast radius grows.
How OctoVault approaches it
OctoVault keeps an isolated, write-once copy of your data on a dedicated air-gapped tier, with AI monitoring backup streams for ransomware behaviour and deletion anomalies. Combined with sub-15-minute recovery points and point-in-time restore, it turns "we were hit" into "we recovered" — measured in minutes, not days.


