RECOVERY RESERVE
Offline Backup Guide: Protect Your Data When the Network Cannot Be Trusted

Offline backups matter because ransomware, account compromise and service outages can remove access to both live files and poorly designed backup copies. The goal is independent recovery, not simply creating more copies.
This page focuses on protection, continuity and recovery. It does not provide instructions for carrying out cyber intrusion.
The immediate answer
The core rule is separation: keep important data in more than one place and make sure at least one recovery copy is not continuously reachable from the system it protects. Decide what must be recoverable, store the copy securely, retain useful versions and test that you can restore files before an emergency makes the test unavoidable.
Decide what is worth recovering before copying everything
Start with irreplaceable and operationally important data: family photos, identification copies, financial records, business documents, contacts, medical information and configuration needed to restore essential systems. Large indiscriminate backups are harder to manage and test. Write down what is included and when it was last copied. For businesses, include the data and settings required to resume the minimum viable operation rather than assuming the cloud application itself will always be available.
Keep one copy outside the normal blast radius
An offline backup is disconnected from the system it protects when it is not being updated. That might be an external drive stored securely, or another protected method that an attacker cannot modify using ordinary day-to-day credentials. NCSC guidance stresses that connected storage can be affected by malware and recommends multiple backups in different places. Separation is the feature that turns a duplicate file into a recovery asset.
Protect the backup physically and digitally
A removable drive can be stolen, damaged by fire or left somewhere nobody can find. Store it securely, consider encryption for sensitive data and make sure the people responsible for recovery know how to unlock it. Do not write the encryption secret on the drive itself. If a backup is stored off-site, consider how it would be reached during a local emergency and whether a second copy is needed for the most important records.
Test restoration, not just successful copying
Backup software saying “complete” does not prove recovery works. Periodically restore a sample of important files to another location and confirm that they open. Businesses should test the process needed to rebuild an essential workstation or service. Record how long it takes and which credentials are required. A restore test often discovers missing folders, expired passwords or undocumented software dependencies while there is still time to fix them.
Keep more than one generation
If corruption or malicious encryption sits unnoticed for days, a single rolling backup can copy the damaged data over the good version. Retain earlier versions for an appropriate period and do not overwrite every recovery point immediately. NCSC guidance notes the value of keeping backups for long enough to cover delayed detection. For households, even a simple monthly archive of the most important files can add meaningful resilience.
Create a small offline emergency information pack
Alongside digital backup, keep printable information you would need if no device or account could be opened: essential contacts, insurance details, medication list, device recovery instructions and the location of important documents. This is not a substitute for secure digital storage. It is a bridge that lets the household or business function while technical recovery is still under way.
Continue from here
Build this topic into a wider plan, then see how the same dependency could fail in an AI-collapse scenario.
Evidence desk
The defensive guidance on this page uses current UK cyber-security advice. Where the page discusses AI-driven escalation or autonomous attack chains, that material is labelled as scenario analysis rather than presented as a guaranteed future event.
OFFLINE FALLBACK
Cyber resilience is part of household resilience.
The 72-hour field manual covers power, communications, money, food, water and the paper information you need when digital systems stop cooperating.
Continue
More Cyber & Digital Resilience guides → · Cyber and preparedness tools →