Physical or logical isolation of backup systems from production networks to protect against ransomware.
An air-gap isolates backup data from production systems and networks—either physically (disconnected storage) or logically (through strict access controls and network segmentation). Air-gapped backups are protected from ransomware that spreads through networks and targets connected backup systems. True air-gaps require physical disconnection; logical air-gaps use access controls, immutability, and separate credentials to achieve similar protection.
Why It Matters
The DSC Perspective:
Ransomware operators specifically target backups to prevent recovery. Air-gapped or immutable backups are essential—connected backups may be encrypted along with production data.
