An air-gapped copy is a backup or recovery copy kept logically or physically isolated from primary systems and routine administrative access. It reduces the chance that ransomware, misconfiguration, or attacker activity can encrypt or destroy the last recoverable version of critical data.
What an Air-Gapped Copy Is
An air-gapped copy is more than “just another backup.” Its defining feature is that recovery data is separated from routine administrative paths, so compromise of the primary environment does not automatically reach the last recoverable copy.
How Air-Gapped Copies Protect Recovery
The main security value is breaking the attacker’s path to the backup. If ransomware, destructive malware, or an insider can encrypt or delete online backups through shared credentials or management access, recovery options can disappear at the same time as production systems.
An air-gapped copy reduces that coupling by keeping the recovery copy outside the normal trust and control plane. That isolation may be physical, such as removable media or an offline vault, or logical, such as a separately controlled repository with no routine network reachability from the production environment.
The practical outcome is resilience: recovery can still be possible even when the primary environment is compromised, misconfigured, or unavailable. This is why air-gapping is often discussed alongside NIST Cybersecurity Framework 2.0 recovery planning and CIS Benchmarks for hardening systems that host backup infrastructure.
What Makes an Air-Gapped Copy Different from Ordinary Backups
Many backup systems are protected by permissions, snapshots, or immutability, but those controls still leave the copy within the reachable administrative environment. An air-gapped copy adds a stronger separation boundary, so access to production systems does not equal access to the recovery set.
That distinction matters because backup compromise is often an access problem, not only a storage problem. If backup consoles, API keys, or administrative sessions are shared with production workflows, an attacker who gains those pathways can target both systems and recovery assets together.
In mature environments, the air gap is part of a broader control design that includes separate credentials, separate operational approval, and a recovery process that is intentionally slower but harder to sabotage. For cryptographic material used in protecting backup media, NIST SP 800-57 Key Management is relevant where encryption keys themselves must be kept distinct from the data they protect.
Operational Trade-Offs and Recovery Limits
Air-gapped copies improve survivability, but they also add friction. They can slow restore operations, require manual handling, and introduce the risk of stale backups if offline copies are not refreshed on a disciplined schedule.
The control is only effective when the recovery path is tested. If the copy is isolated but unreadable, incomplete, or never exercised in a restore drill, the organization may discover too late that it has preserved data but not recoverability. The same is true if the gap is partial, such as backup servers that are separated from users but still reachable from privileged admin workstations.
Because the objective is to preserve a trustworthy recovery point, air-gapped copies often sit within a wider resilience strategy that includes NIST SP 800-53 Rev 5 Security and Privacy Controls for access control, auditability, configuration management, and system integrity.
Where Air-Gapped Copies Fit in Modern Security Architecture
Air-gapped copies are not a replacement for backups, immutability, or identity controls. They are the highest-confidence option when the business impact of losing the last clean recovery point is severe, such as in ransomware scenarios or destructive insider incidents.
They are especially valuable when the environment has many administrators, automation paths, or third-party dependencies that could otherwise reach backup systems. In those settings, segmentation alone may be insufficient if the same identity or management plane can still reach every copy.
Used well, an air-gapped copy becomes the final insurance layer in the recovery stack: ordinary backups for speed, immutable copies for tamper resistance, and an isolated copy for worst-case restoration. For organizations that rely on this pattern as part of their broader recovery posture, the NIST Cybersecurity Framework 2.0 recovery function remains the most practical organizing model.
Risk and Threat Considerations
Air-gapped copies are most valuable when the threat is trying to eliminate every recoverable version of data. Ransomware operators, destructive malware, and compromised insiders often target backup systems precisely because they know recovery pressure increases once the last clean copy is gone.
Failure mechanism: The gap fails when the recovery copy is still reachable through shared credentials, automation, remote admin tooling, synchronized replication, or poorly governed operational access. In that case, the backup is isolated in name but not in practice.
Impact: If the last recoverable copy is encrypted, deleted, or rendered stale, the organization can lose restoration options, extend outage duration, and increase the likelihood of paying extortion, rebuilding from partial data, or accepting major business interruption.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | RC.RP-01 — Recovery Plan Executed | Air-gapped copies directly support resilient recovery after destructive compromise. |
| PR.AA-05 — Least Privilege Access Permissions | Backup isolation depends on limiting who and what can reach recovery stores. | |
| Recommendation — Test isolated recovery copies and validate restore procedures regularly. Restrict backup access paths to the minimum required identities and roles. | ||
| NIST SP 800-53 Rev 5 | CP-9 — System Backup | Air-gapped copies are a stronger form of backup intended to preserve recoverability. |
| AC-6 — Least Privilege | Separating recovery copies from normal admin access relies on limiting privileged reach. | |
| Recommendation — Maintain protected backup copies that can survive compromise of primary systems. Constrain administrative access to backup infrastructure to the minimum necessary. | ||
| CIS Controls v8 | CIS-11 — Data Recovery | Air-gapped copies are a recovery safeguard aimed at preserving data after destructive events. |
| Recommendation — Keep offline or isolated recovery copies and verify they can be restored. | ||
| ISO/IEC 27001:2022 | A.8.13 — Information backup | The term is a backup design that strengthens backup resilience against compromise. |
| Recommendation — Protect backup copies so they remain recoverable after disruption or attack. | ||
Practitioner Guidance
Why practitioners should care: The term should be treated as a recovery assurance requirement, not a storage label. The important question is whether the copy is actually outside the routine access path that attackers or misconfigured automation could reuse.
What to watch for: Look for backup repositories that share identity, network reachability, or administrative tooling with production systems. A recovery design is only truly air-gapped if the isolation still holds during a real incident, not just during normal operations.
Practitioner takeaway: Validate the restore path as carefully as the backup path, because an air-gapped copy that cannot be restored quickly and confidently does not deliver its intended protection.