An air-gapped backup is a backup copy that is physically disconnected from your production network, so an attacker or a mistake in your main environment has no network path to it. The term comes from the literal gap of air between an offline tape or disk and any network. Many providers also use the term for logically isolated or vaulted copies: backups kept online in a separate environment, with separate credentials and controlled transfer windows. These “logical air gaps” are alternatives to a strict air gap rather than the same thing, and how well they hold up depends on how access to them is separated.
At a glance
- A strict air gap means the copy is physically disconnected, with no network path, such as rotated tape or removable disk.
- Logically isolated or vaulted copies, often marketed as “logical air gaps”, stay online but use a separate account, network path, credentials and admin controls.
- Isolation strength varies widely, so verify network reachability, console access, credential separation, deletion authority and transfer windows.
- It is often paired with immutable backup, which locks copies against change, and is a common way to meet the “one offline, air-gapped or immutable copy” in extended versions of the 3-2-1 rule.
- It protects a copy of your data; it doesn’t stop attacks or guarantee the copy is free of malware.
What problem it solves
Modern ransomware operators know that working backups are the main reason victims refuse to pay. Many attacks hunt for backup servers, consoles and storage first, then delete or encrypt them before encrypting production. If every backup copy is online and managed with the same domain accounts, an attacker who has those accounts can often reach all of them.
A physically air-gapped copy breaks that chain, because there is no network path from production to reach it. A well-isolated vault narrows it: if the copy sits outside the network and identity systems the attacker controls, compromising production doesn’t automatically mean compromising the copy. The same separation helps against a malicious insider, a misconfigured script that deletes backups, or a site disaster that takes out everything connected to it.
How it works
Physical air gap. Backups are written to media that is then disconnected and stored elsewhere, such as tape cartridges or removable drives rotated offsite. While offline, the copy can’t be reached over a network at all. The trade-offs are manual handling, slower restores and the risk of media being lost or not rotated on schedule.
Logically isolated copies (“logical air gaps”). The copy is kept online but isolated: a separate cloud account or tenant, a backup vault managed by the provider, separate credentials that aren’t tied to your main directory, and limited connections that open only to transfer data. Some services describe a short connection window followed by the copy being cut off again. Because some network path remains, the protection depends on details: how the vault is reachable over the network, who can reach its console, whether its credentials are separate from your directory, who can delete copies, and when and how transfer windows open.
Combining controls. Many setups combine isolation with immutability, multifactor approval for deletion, and alerts on unusual activity in the backup system. A backup retention policy decides how long isolated copies are kept, which should cover how long an attacker might go unnoticed.
Recovery. Restoring from an isolated copy is usually slower than from a local one, and the copy still needs checking for malware before it goes back into production, ideally coordinated with your incident response (IR) process.
When it matters for buyers
- When cyber insurance renews. Insurers often ask whether you keep an offline, isolated or immutable copy.
- After a peer is hit by ransomware. A common question is whether any of your copies would survive an attacker with domain admin rights.
- When choosing a backup service. Providers mean very different things by “air-gapped” or “isolated vault”; compare the actual separation.
- When setting recovery targets. Isolated copies may be older or slower to restore, which affects your recovery point objective (RPO) and how long recovery takes.
- When revisiting the 3-2-1 rule. An offline or isolated copy is a common way to meet the extra protected copy in extended versions of the 3-2-1 backup rule.
Questions to ask vendors
- What exactly separates the isolated copy from our environment: network, account, credentials, physical media, or a combination?
- Can anyone using our main admin accounts or identity provider delete or change the isolated copy? Can your staff?
- Is the isolated copy also immutable, and for how long?
- How often is the isolated copy updated, and how old could our newest isolated copy be when we need it?
- How long would a full restore from the isolated copy take, and has that been tested?
- Is the isolated vault included in the price, or a separate tier or add-on?
How it differs from immutable backup
Air gapping and immutability answer different questions. An air gap is about reach: can an attacker, or a mistake, get to the copy at all? Immutability is about change: once someone reaches the copy, can they alter or delete it before the lock expires? An immutable copy that sits on your main network is still visible to an attacker, who may wait out short locks or attack the console. An isolated copy without immutability may be safe from outside attackers but exposed to anyone who can reach the vault. That is why many backup services, including many backup as a service (BaaS) offerings, combine both. Our backup as a service overview covers how providers protect backup copies.
