Air gapping reduces risk because it removes the reachable path that ransomware and adjacent threat activity rely on to spread. Immutable storage protects data from alteration, but it does not stop a threat from reaching the repository in the first place. By isolating backup targets, organisations reduce the chance that a compromised environment can move laterally into recovery data.
air gapping changes the attacker’s problem from “can I protect the data once I reach it?” to “can I reach it at all?” immutable storage helps preserve stored data from tampering, but it still assumes the repository is reachable from a compromised environment. Air gapping removes that reachable path, which is why it adds value even when immutability is already present.
Why immutability and isolation solve different problems
Immutable storage is a protection against alteration after data is written. That is valuable for backup integrity, but it does not prevent an attacker or ransomware process from discovering the target, authenticating to it, or attempting destructive actions around it. Air gapping addresses reachability and trust boundary placement, which is a different control objective from write-once or tamper-resistant storage. The two controls are complementary, not interchangeable.
In practice, ransomware rarely needs to defeat immutability to create business impact. If it can access the backup plane, it may try to delete snapshots, encrypt adjacent systems, disrupt catalogues, or stage around the immutable copy so recovery is delayed. Air gapping reduces that exposure by removing the live network path that compromise relies on.
What air gapping changes in a ransomware kill chain
Ransomware succeeds when initial access becomes lateral movement and then recovery suppression. A reachable backup target can be scanned, mapped, and targeted from the same compromised environment that is already under attacker control. Air gapping interrupts that sequence by separating the backup target from the production trust zone, so the attacker must overcome a much harder and more visible access problem before backup data is even in play.
That distinction matters most during a real incident. Immutable storage may preserve clean copies, but if the attacker can still reach the repository, the organisation may face credential abuse, management-plane abuse, or disruptive actions against backup services themselves. Air gapping narrows those options and improves the odds that at least one recovery path remains outside the blast radius of the compromise.
Why the combination is stronger than either control alone
For recovery planning, immutability and air gapping answer two different questions: can the data be changed, and can the attacker touch it? Immutable storage is strongest when you expect insider mistakes, accidental overwrite, or limited tampering attempts. Air gapping is strongest when you want to deny a compromised environment any practical route into recovery data. Together they reduce both corruption risk and reachability risk.
This is why practitioners often treat immutable storage as a durability control and air gapping as a containment control. When both are present, ransomware has to defeat isolation before it can even contend with immutability. That layered posture is especially important where backup systems share credentials, management planes, or administrative pathways with production.
Risk and Threat Considerations
The main risk is overtrusting immutability as if it were isolation. If the backup repository remains online, reachable, or administratively connected to the compromised environment, ransomware may still interfere with recovery even if it cannot rewrite the protected objects themselves.
Failure mechanism: Attackers exploit any reachable management, authentication, or network path into the backup plane, then use that foothold to delete, disable, or delay access to recovery data, even when the underlying stored objects are immutable.
Impact: The organisation can lose restoration speed, clean recovery confidence, or both, which turns a data-protection control into only a partial safeguard during a live ransomware event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.DS-01 — Data-at-Rest | Immutable backups and isolated recovery data directly concern protection of data at rest. |
| PR.IR-01 — Identity Management, Authentication, and Access Control | Air gapping reduces reachable access paths into the backup plane, not just data tampering. | |
| RC.RP-01 — Recovery Plan is Executed | The question is fundamentally about preserving viable recovery during ransomware. | |
| Recommendation — Protect backup data at rest with controls that preserve recovery integrity under compromise. Restrict access paths so compromised production access cannot reach recovery systems. Design recovery arrangements so clean restoration remains available during an incident. | ||
| NIST SP 800-53 Rev 5 | SC-7 — Boundary Protection | Air gapping is a boundary and segmentation control that blocks lateral reachability. |
| CP-9 — System Backup | Immutable storage and isolated backups are core backup resilience mechanisms. | |
| IA-2 — Identification and Authentication (Organizational Users) | The risk includes attacker misuse of credentials to reach backup systems. | |
| Recommendation — Separate recovery assets with boundary controls that block direct compromise paths. Maintain backups so recovery data remains available even after a ransomware event. Harden authentication to prevent compromised admin access from reaching recovery infrastructure. | ||
| CIS Controls v8 | CIS-11 — Data Recovery | Backup integrity and recoverability are the central subject of the question. |
| CIS-12 — Network Infrastructure Management | Air gapping depends on deliberate network separation from the production environment. | |
| Recommendation — Test recovery paths so immutable copies remain useful when production is compromised. Segment backup networks so ransomware cannot traverse from production to recovery. | ||
| ISO/IEC 27001:2022 | A.8.13 — Information backup | The question concerns how backup protection methods combine to preserve recoverability. |
| A.8.20 — Network security | Air gapping is a network security measure that limits reachability to backups. | |
| Recommendation — Define backup arrangements that preserve recovery capability under destructive attacks. Use network separation to keep recovery systems outside the attacker’s reachable path. | ||
Practitioner Guidance
What to verify: Confirm that the backup target is not merely immutable, but also operationally isolated from the production environment, including admin paths, API access, and shared identity dependencies. If a compromised production credential can still influence the backup plane, the air gap is not doing its full job.
What good looks like: Recovery data is reachable only through tightly controlled, intentionally separate access paths, and those paths are not continuously exposed to the same runtime that would be affected by ransomware.
Practitioner takeaway: Treat immutability as protection of the copy and air gapping as protection of the path; ransomware resilience improves most when both the data and the route to it are defended.
Related resources from NHI Mgmt Group
- Why do organisations struggle to reduce cloud data risk even when they already have data security tools in place?
- Why does MFA reduce cyber risk in a Cyber Essentials programme even when other controls are already in place?
- Why does data sprawl increase risk even when security tools are already in place?
- Why do cloud ransomware attacks on storage environments often succeed even when traditional endpoint controls are in place?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org