Air-Gapped Backup
A backup stored on media physically disconnected from networks, protecting against remote attacks.
Also known as: Air Gap Backup, Isolated Backup, Disconnected Backup
Category: Concepts
Tags: backup, security, ransomware-protection, isolation
Explanation
An air-gapped backup is a data protection strategy where backup media is physically isolated from any network connection, creating an impenetrable barrier against remote cyberattacks, particularly ransomware. The term "air gap" refers to the literal gap of air between the backup storage and any connected systems.
**Why air-gapped backups matter**:
Modern ransomware attacks specifically target backup systems to maximize damage and force victims to pay ransoms. By encrypting or destroying backups, attackers eliminate recovery options. Air-gapped backups provide a last line of defense that cannot be reached through network-based attacks.
**Implementation approaches**:
- **Removable media**: External hard drives, tapes, or USB drives physically disconnected after backup
- **Tape rotation**: Regular tape backups with media stored offline in secure locations
- **Scheduled disconnection**: Automated systems that disconnect backup storage after backup windows
- **Physical vaults**: Off-site storage facilities with no network connectivity
**Best practices**:
- Rotate multiple backup sets to maintain recent and historical copies
- Store air-gapped media in secure, climate-controlled locations
- Test restoration from air-gapped backups regularly
- Document and follow strict procedures for media handling
- Combine with other backup strategies (following 3-2-1 rule)
**Challenges and considerations**:
- Longer backup and recovery times due to physical media handling
- Requires disciplined processes and procedures
- Higher operational overhead than online backups
- Media degradation over time requires monitoring
- Balance between protection and recovery speed
**When air-gapped backups are essential**:
- Critical systems in high-risk environments
- Organizations handling sensitive data
- Compliance requirements mandating offline copies
- Protection against sophisticated ransomware threats
Air-gapped backups represent the gold standard for ransomware protection, ensuring that at least one recovery path remains available even after the most devastating cyberattacks.
Related Concepts
← Back to all concepts