An air gap protects backup data by preventing the same incident from reaching production and every recovery copy. Isolation may be physical, logical or time-based, but these approaches do not cover the same threats and none works without disciplined operation.
Key point: removable media is isolated only after it has been ejected, removed from compromised identities and systems, stored under control and proven readable through restoration.
What is a backup air gap?
An air gap is a separation designed to prevent one technical path, privileged identity or administrative error from reaching production and all backups. It is not a single product. It combines architecture, access controls, retention and an operating procedure.
The goal is to retain at least one identifiable, sufficiently recent and usable copy when connected systems are encrypted, deleted, corrupted or unavailable. Isolation therefore complements monitoring and restore testing; it does not replace them.
Physical air gap: a verifiable hardware break
A physical air gap removes the active connection. After the job, removable media is ejected or the storage system is physically disconnected. With no network or management path left, remote credentials and automated malware cannot directly alter that copy.
- Main strength: the break is visible and does not depend solely on a software rule.
- Operational requirement: rotation, transport, storage and return must be documented and performed.
- Residual risk: media left in the reader, badly labelled, damaged, unencrypted or lost may not provide recoverable protection.
An RDX cartridge rotation provides physical separation when the cartridge is actually removed, checked into the register and stored securely. See the five-step media rotation guide for the daily process.
Logical air gap: isolate access paths
A logical air gap usually keeps the copy on connected infrastructure while reducing exposure through network segmentation, separate identities, time-limited access, immutable storage or a repository that production cannot modify directly.
- Main strength: backup and recovery operations can be automated and fast.
- Operational requirement: privilege separation, retention and monitoring must be designed and reviewed.
- Residual risk: an overpowered account, shared management console, API key or reversible retention setting can reopen the path to the copy.
Operational or time-based isolation
Some designs expose a repository only during a controlled backup window, then revoke access or unmount it. This limits exposure time but still depends on reliable automation, clocking, credentials and alerting. Treat it as a layer, not as equivalent to a permanently disconnected medium.
Physical versus logical air gap
| Criterion | Physical isolation | Logical isolation |
|---|---|---|
| Active path | Removed after ejection or disconnection | Restricted by network, identity and policy |
| Automation | Requires media handling | Can be highly automated |
| Remote attack exposure | Very low while disconnected | Depends on configuration and management separation |
| Recovery speed | Includes retrieval and connection time | Often faster to access |
| Evidence | Custody log, media inventory, restore test | Access test, retention test, audit logs, restore test |
| Typical weakness | Process not followed or media mishandled | Privilege or policy misconfiguration |
How to choose the right isolation model
Use the business impact and threat model rather than a label. Consider how quickly copies must be restored, how long attackers could remain undetected, which identities administer the repositories and whether staff can sustain physical handling. Many organisations combine both models.
- Use a local logical or immutable copy for rapid recovery.
- Maintain removable offline media for a strong independent recovery path.
- Keep at least one validated copy off site.
- Separate administrators and emergency credentials.
- Retain enough historical points to survive delayed detection.
- Test deletion resistance and restoration, not just configuration screens.
What an air gap does not solve
Isolation cannot correct a backup that is incomplete, already encrypted before capture or retained for too short a period. It also does not provide compatible recovery hardware, encryption keys or trained staff. Combine the air gap with protected monitoring, capacity management, documented dependencies and recurring restore tests.
Example of a layered design
A practical design may use dedicated local storage for rapid restores, an immutable or separately administered repository for automated retention, and rotating RDX media for physical isolation and off-site custody. Each layer has a different owner and control path, while the restore programme deliberately exercises all three.
Control questions before calling a copy air-gapped
- Can production administrators delete or shorten retention?
- Can the backup console reach every copy with the same identity?
- Is the medium physically removed after the job?
- Where is the off-site copy and who confirms handover?
- Are encryption keys and compatible readers available during an outage?
- When was this exact recovery path last tested?
Isolation is a process, not a checkbox
Document the expected state after every job, monitor exceptions and rehearse retrieval. A design is resilient only if the team can prove which copy is isolated, who can reach it, how old it is and how long a verified restore takes. Review the model after changes to infrastructure, administrators, suppliers or retention.
Choose an appropriate isolation strategy
Describe your attack paths, recovery targets and current copies to compare physical, logical and combined air-gap options.
Share this guide

