RECOVERY RESERVE

Offline Backup Guide: Protect Your Data When the Network Cannot Be Trusted

External backup drives connected to a laptop, graded into the site’s dark emergency visual system
Backup illustration — an offline copy can remain recoverable when the network, cloud account or primary computer cannot be trusted.

Offline backups matter because ransomware, account compromise and service outages can remove access to both live files and poorly designed backup copies. The goal is independent recovery, not simply creating more copies.

DEFENSIVE BRIEFA BACKUP CONNECTED TO THE SAME FAILURE IS NOT MUCH OF A BACKUP

This page focuses on protection, continuity and recovery. It does not provide instructions for carrying out cyber intrusion.

The immediate answer

The core rule is separation: keep important data in more than one place and make sure at least one recovery copy is not continuously reachable from the system it protects. Decide what must be recoverable, store the copy securely, retain useful versions and test that you can restore files before an emergency makes the test unavoidable.

Decide what is worth recovering before copying everything

Start with irreplaceable and operationally important data: family photos, identification copies, financial records, business documents, contacts, medical information and configuration needed to restore essential systems. Large indiscriminate backups are harder to manage and test. Write down what is included and when it was last copied. For businesses, include the data and settings required to resume the minimum viable operation rather than assuming the cloud application itself will always be available.

Keep one copy outside the normal blast radius

An offline backup is disconnected from the system it protects when it is not being updated. That might be an external drive stored securely, or another protected method that an attacker cannot modify using ordinary day-to-day credentials. NCSC guidance stresses that connected storage can be affected by malware and recommends multiple backups in different places. Separation is the feature that turns a duplicate file into a recovery asset.

Protect the backup physically and digitally

A removable drive can be stolen, damaged by fire or left somewhere nobody can find. Store it securely, consider encryption for sensitive data and make sure the people responsible for recovery know how to unlock it. Do not write the encryption secret on the drive itself. If a backup is stored off-site, consider how it would be reached during a local emergency and whether a second copy is needed for the most important records.

Test restoration, not just successful copying

Backup software saying “complete” does not prove recovery works. Periodically restore a sample of important files to another location and confirm that they open. Businesses should test the process needed to rebuild an essential workstation or service. Record how long it takes and which credentials are required. A restore test often discovers missing folders, expired passwords or undocumented software dependencies while there is still time to fix them.

Keep more than one generation

If corruption or malicious encryption sits unnoticed for days, a single rolling backup can copy the damaged data over the good version. Retain earlier versions for an appropriate period and do not overwrite every recovery point immediately. NCSC guidance notes the value of keeping backups for long enough to cover delayed detection. For households, even a simple monthly archive of the most important files can add meaningful resilience.

Create a small offline emergency information pack

Alongside digital backup, keep printable information you would need if no device or account could be opened: essential contacts, insurance details, medication list, device recovery instructions and the location of important documents. This is not a substitute for secure digital storage. It is a bridge that lets the household or business function while technical recovery is still under way.

Evidence desk

The defensive guidance on this page uses current UK cyber-security advice. Where the page discusses AI-driven escalation or autonomous attack chains, that material is labelled as scenario analysis rather than presented as a guaranteed future event.

OFFLINE FALLBACK

Cyber resilience is part of household resilience.

The 72-hour field manual covers power, communications, money, food, water and the paper information you need when digital systems stop cooperating.

FREE 72-HOUR SURVIVAL GUIDE

Continue

More Cyber & Digital Resilience guides → · Cyber and preparedness tools →

FREE 25-PAGE FIELD MANUAL

Your first 72 hours should not live in your head.

Turn the advice into a written household plan: water, power, food, communications, health continuity, information verification and movement decisions.

FREE 72-HOUR SURVIVAL GUIDE