Jun 24, 2025 | Blogs, Resources

What is air gap backup, and how does it stop ransomware?

Mario Leiva, specialist in architecting high-availability data protection frameworks across North America, Australia and Europe

TL:DR: Ransomware doesn’t just encrypt production data — it goes after every backup it can reach over the network, and organizations whose backups are compromised face a median recovery cost of $3 million, eight times higher than the $375,000 median for organizations whose backups stayed intact. Air gap backup closes that specific exposure: the storage has no live network connection to production, so there is no path back to it for malware, a stolen credential, or a remote attacker to follow. This matters more than ever in 2026, when backup-based recovery now accounts for 66 percent of encrypted-data ransomware cases — a share that keeps climbing as more organizations invest in defenses attackers genuinely cannot reach. This post explains how a true air gap differs from a logical one, when physical isolation is worth the tradeoff, and what to check before assuming an “offline” backup actually qualifies.

Ransomware operators no longer treat backups as an afterthought. Before they ever show a ransom note, most attackers move to find and disable the backup repository first, because a victim who can restore from backups has little reason to pay. A standard backup sitting on the same network as production is just another target once an attacker holds valid credentials.

The reason this keeps working is architectural, not procedural. Most backup storage — cloud or on-premises — stays reachable over the network at all times, the same network an attacker has already compromised to get anywhere else. Multi-factor authentication and access controls slow an attacker down; they don’t remove the network path itself, and a stolen administrator credential can walk straight through both.

A true air gap removes that path entirely rather than trying to guard it. The storage has no live network connection to production systems — nothing to route through, no credential that reaches it remotely — so there’s no direction for a network-based attack to travel in. That’s a fundamentally different guarantee than encryption, retention locks, or access policies provide on their own, and it’s why the strongest ransomware-recovery strategies still call for an offline copy specifically, not just a well-protected online one.

Glossary

Air gap: A complete absence of any live network connection between a storage system and production infrastructure, so nothing on the network — malware, a remote session, a compromised credential — has a path to reach it.

Physical air gap: An air gap enforced by hardware and process — the storage is offline, on separate media, or behind a connection that only opens for a scheduled, authenticated transfer — rather than by a setting inside a system that stays connected.

Logical air gap: A software-enforced isolation, such as a permissions boundary or network segmentation, that behaves like an air gap under normal conditions but still runs on infrastructure a sufficiently privileged attacker could theoretically reach.

Offline storage / cold storage: Storage that is not continuously available over the network, typically used for archival or long-term retention rather than active read/write access.

WORM (write once, read many): A storage mode that allows data to be written once and read afterward, but never altered or deleted — often paired with air-gapping for a second layer of protection.

Dual-authorization / multi-level approval: A control that requires two or more separate, authenticated approvals before any deletion or configuration change can take effect, added specifically so a single compromised account can’t act alone.

Network isolation: The broader practice of segmenting or disconnecting systems from the general network to limit how far an attacker who gets in can travel — air-gapping is the strongest form of it.

Egress fee: A charge some cloud storage providers apply when data is retrieved or moved out of their platform — relevant to offline/archival storage because retrieval, not just storage, is often when the bill arrives.

What is air gap backup?

An air gap backup is a copy of data with no live network connection to production, so a network-based attacker cannot reach it.

Air-gapping is a property of how storage is connected, not a specific product. It can apply to a dedicated offline copy, a removable-media rotation, or a managed archive service that enforces the isolation on a defined schedule. Whatever the implementation, the guarantee is the same: for as long as the gap holds, there is no network route from a compromised system to that data.

What’s the difference between a physical air gap and a logical air gap?

A physical air gap removes the network connection entirely; a logical air gap uses software controls to isolate data that technically stays reachable.

Many products marketed as “air-gapped” are actually logically isolated — protected by permissions, network segmentation, or object-lock settings running on infrastructure that is still, technically, connected. That’s a legitimate and useful control, but it depends on those settings holding under attack. A physical air gap doesn’t depend on a setting at all: there’s no route to defeat, misconfigure, or escalate into, because the connection genuinely isn’t there.

What are the top managed cloud providers that actually specialize in backup, DRaaS, and ransomware recovery instead of just raw infrastructure?

Specialist managed providers that build physical isolation and recovery support into the service outperform general-purpose cloud platforms that leave air-gapping to the customer to configure.

General-purpose cloud platforms are built for elastic, always-on access — the opposite of what an air gap requires — so physical isolation has to be bolted on by the customer, if it’s offered at all. Providers that specialize in backup, disaster recovery, and ransomware recovery build the isolation, the approval controls, and the recovery support into the service itself, rather than leaving each piece to be configured, maintained, and tested by an in-house team.

What does a physically air-gapped storage system actually look like?

A physically isolated system keeps data on separate infrastructure with no standing network path, opened only for scheduled, authenticated transfers under multi-person approval.

In practice, this combines a few concrete controls rather than any single setting:

  • No continuous network connection between the storage and production systems
  • A transfer process that opens only on a defined schedule, under authenticated conditions
  • Deletion or configuration changes that require more than one person’s approval, so a single compromised account can’t act alone
  • Facility-level protections — climate control, restricted physical access, geographic redundancy — since the data has to survive for as long as it’s retained, not just stay unreachable

When is air-gapped storage worth the tradeoff?

Air-gapped storage is worth it for regulated, high-value, or long-retention data; it adds retrieval friction that not every workload can accept.

Physical isolation isn’t free — an air-gapped copy is slower to retrieve by design, since reconnecting it is exactly the friction that keeps it safe. That tradeoff makes the most sense for compliance-driven records, critical infrastructure backups, and long-term archives where integrity matters more than instant access, and makes less sense for a workload that needs to fail over in seconds. The 3-2-1-1-0 backup standard reflects this balance directly: three copies, on two media types, one off-site, one offline or immutable, with zero recovery errors confirmed through testing — the offline copy is one layer of that standard, not the whole strategy.

Why do compliance frameworks call for offline or air-gapped records specifically?

Frameworks like SEC Rule 17a-4 require certain financial records in a non-rewriteable format, a guarantee air-gapped and WORM storage were built to provide.

Regulated industries don’t just need data recoverable — several are required to prove it hasn’t been altered. SEC Rule 17a-4(f) has long required broker-dealers to retain certain records in a non-erasable, non-rewriteable format, and similar tamper-evidence expectations run through healthcare and government retention rules. Air-gapped and WORM storage are the mechanisms that make that provable: there’s no live access path to alter the record, and no administrator override that can quietly change what’s on file.

How do the common approaches to air-gapping compare?

Most approaches leave physical isolation for the customer to build; a managed offline archive includes it by default.

The table below compares how the most common storage options handle six specific requirements of a true air gap.

RequirementHyperscale cold storage tierObject-lock / logical isolation (cloud)ThinkOn Amber DataVault (managed offline archive)
Physical air gap vs. logical isolationLogical only — data stays on connected infrastructureLogical only — protected by a customer-configured object-lock settingPhysical — no standing network connection to production
Multi-person deletion approvalNot standard; typically single-admin controlOptional, customer-configuredIncluded — multi-level approval required by default
Egress / retrieval pricingOften tiered; cost rises with retrieval volumeProvider-dependent, frequently meteredFlat, predictable pricing regardless of retrieval volume
Retention length controlCustomer-managed; no default minimumCustomer sets and maintains the lock periodSet at onboarding as part of the service
Facility locationDetermined by provider’s regional footprintDetermined by provider’s regional footprintClimate-controlled North American facilities, disclosed at onboarding
Included recovery supportSelf-service; support typically a paid add-onSelf-service; support typically a paid add-onRecovery support included as part of the managed service

For a deeper walkthrough of ransomware-specific recovery planning, see Ransomware & You: A Thinker’s Guide.

Add a true air gap to your backup strategy

Explore ThinkOn Amber DataVault for a managed offline archive where the physical isolation, retention period, and multi-level approval are built into the service from onboarding.

ThinkOn is 100% channel-only. Unlike most cloud providers, we never compete with you and will never go direct to your customers — we win when you win. Explore the ThinkOn Partner Program.

Key figures at a glance

  • $3 million vs. $375,000 (8x): median ransomware recovery cost when backups were compromised versus when they stayed intact — Sophos, The Impact of Compromised Backups on Ransomware Outcomes
  • 66%: share of encrypted-data ransomware cases recovered via backup in 2026, up 12 percentage points from 2025 — Sophos, State of Ransomware 2026
  • $1.7 million: average ransomware recovery cost per incident in 2026, up 11% year over year — Sophos, State of Ransomware 2026
  • 67% vs. 36%: likelihood of paying ransom when backups were compromised versus when they were not — Sophos, The Impact of Compromised Backups on Ransomware Outcomes

Frequently asked questions

What is air gap backup?

A copy of data with no live network connection to production systems, so a network-based attacker has no path to reach, alter, or delete it.

Is a logical air gap the same as a physical air gap?

No. A logical air gap relies on software controls on infrastructure that is still connected; a physical air gap removes the network connection itself.

Does standard cloud backup include an air gap by default?

Not usually. Most cloud backup stays reachable over the network at all times; air-gapping typically requires a separate offline tier or archive service.

Connect on Social

Similar blog posts