For years, the standard defence against data loss was "having backups". Modern ransomware has invalidated that premise: today's groups encrypt nothing until they have located and destroyed the backup copies. If your backup is reachable from the compromised network, to the attacker it is just another directory to wipe before launching the encryption and demanding the ransom.
The answer to this new scenario is called an air gap: a copy deliberately placed out of the reach of any attacker who controls the network, either because it is physically disconnected or because a logical barrier — independent credentials, immutability, an isolated network — makes it impossible to tamper with.
In this article we explain what an air gap actually is, the difference between its physical and logical variants, how it fits into the 3-2-1-1-0 rule, the mistakes that turn a false air gap into a trap, and how to implement it in practice with Veeam Cloud Connect and immutable S3 storage — no tapes, no manual processes.
What an Air Gap Is in Backup
The term air gap comes from network security: a physically isolated system with no connection to external networks cannot be attacked over the network. Applied to backup, an air gap is a copy that an attacker with full control of your production environment cannot encrypt, delete or alter — not even with domain administrator credentials in hand.
The key is not where the copy lives, but what separates it from the attacker. A replica in another city, mounted over SMB with the same domain credentials, is not an air gap: it is just another target with more latency. By contrast, a tape stored in a safe or an immutable repository with credentials foreign to the customer's domain does qualify, because the attacker's path to the copy is cut.
There are two ways to achieve it: a physical air gap (the media is literally disconnected) and a logical or virtual air gap (the media is connected, but barriers of immutability, credentials and network make it unreachable). Both serve the same purpose; they differ in cost, automation and recovery speed.
Why Ransomware Attacks Backups First
Today's ransomware is not an executable that encrypts the first thing it finds: these are human-operated campaigns that spend days or weeks inside the network before acting. During that dwell time, the attacker escalates privileges, maps the infrastructure and specifically locates the backup systems: Veeam or other backup consoles, NAS repositories, storage array snapshots and cloud copies reachable with the stolen credentials.
The reason is purely economic: a victim who can restore does not pay. That is why the ransomware playbook starts by deleting snapshots, disabling backup jobs and encrypting or wiping the repositories; only then is production encrypted. Agencies such as CISA through its StopRansomware programme therefore recommend keeping offline and immutable copies as a core resilience measure.
The practical conclusion is uncomfortable but clear: every backup reachable from the compromised domain must be written off when designing the recovery plan. The question that defines your resilience is not how many copies you have, but how many survive an attacker with full control of your Active Directory.
Physical Air Gap: Tapes, Ejected Disks and Manual Rotation
The physical air gap is the classic method: the media holding the copy is disconnected and stored offline. Its usual forms are LTO tapes ejected from the library and kept in a safe or at another location, USB or RDX disks rotated manually, and the periodic transport of media to a second site.
Its great advantage is absolute disconnection: no exploit, stolen credential or misconfiguration can reach a tape stored in a drawer. On top of that, tape's per-TB cost remains the lowest on the market for long-term archiving.
The drawbacks are operational: rotation depends on manual processes that fail (the tape nobody ejected, the disk left plugged in over the weekend of the attack), the RTO is high because media has to be located, transported and mounted, scalability is limited, and between one rotation and the next there is an unprotected window that can span days.
Logical Air Gap: Immutability, Separate Credentials and Isolated Network
The logical or virtual air gap keeps the copy connected and writable, but raises barriers that prevent it from being modified or deleted even by an attacker with maximum privileges. It rests on three mutually reinforcing pillars:
- check_circle Immutable storage: with S3 Object Lock in compliance mode, written objects cannot be deleted or overwritten during the retention period — not even by the account administrator. It is the digital equivalent of WORM tape.
- check_circle Veeam hardened repositories: Linux servers with filesystem-level immutability, no domain membership and single-use credentials during deployment. Not even the Veeam console itself can delete restore points ahead of time.
- check_circle Separate credentials and network: the repository does not accept the customer's domain credentials and lives in a different network segment or administrative infrastructure. Compromising the production Active Directory provides no route to the copy.
We explain the difference between a protected copy and a merely remote one in detail in our article on immutable vs mutable backups: immutability provides the technical guarantee, while the separation of credentials and network provides the isolation. Together they replicate the effect of the disconnected tape — but with full automation and instant restores.
The Air Gap in the 3-2-1-1-0 Rule
The classic 3-2-1 rule evolved into 3-2-1-1-0 precisely because of ransomware. Each digit plays a specific role:
- check_circle 3 copies of the data: production plus at least two independent backups.
- check_circle 2 different media types: for example, local disk and object storage, so a single technology failure cannot affect both.
- check_circle 1 copy offsite, surviving fires, theft or local disasters.
- check_circle 1 offline or immutable copy: the air gap. This is the digit ransomware added — a copy that survives even if the whole network is compromised.
- check_circle 0 verified errors: restores are tested periodically and automatically. A backup that has never been restored is a hypothesis, not a guarantee.
Rule of thumb:
If a compromised domain administrator can delete a copy with the credentials they already hold, that copy is not an air gap. The definitive test: could you restore tomorrow if an attacker gained full control of your Active Directory today?
Comparison: Physical vs Logical Air Gap
Both approaches serve the same goal — a copy out of the attacker's reach — but their operational profiles are very different:
| Criterion | Physical air gap (tapes, disks) | Logical air gap (immutable) |
|---|---|---|
| Cost | Low per TB on tape, but high in manual operations | Medium and predictable, no manual handling |
| RTO | High: locate, transport and mount media | Low: restore directly from the repository |
| Automation | Limited: manual rotation and ejection | Full: automatic copy and immutability policies |
| Scalability | Limited: more data = more media and more handling | High: grows with the object storage |
| Human error | High: forgotten rotations, media left connected | Low: no intervention in the daily cycle |
| Protection window | Since the last rotation (hours or days) | Continuous: every copy is protected as it is written |
| Typical use case | Long-term archiving, regulatory compliance | Day-to-day ransomware protection |
They are not mutually exclusive: many organisations combine a logical air gap for daily protection with tapes for yearly archiving. But if you can only implement one, the logical variant offers continuous protection without depending on someone remembering to eject a tape.
How to Implement It with Veeam Cloud Connect and Immutable S3
The fastest way to obtain a logical air gap without deploying your own infrastructure is to delegate it to a provider: a "managed air gap". At EasyDataHost we build it on two complementary services:
- arrow_right Offsite backup with Veeam Cloud Connect: your Veeam jobs send a copy to our datacenter using tenant credentials that are completely independent of your domain. An attacker controlling your Active Directory has no administrative route to the remote repository.
- arrow_right S3 storage with Object Lock: restore points are written as immutable objects for the retention period you define. Even with stolen S3 credentials, they cannot be deleted or overwritten ahead of time.
- arrow_right The provider's administration plane: the backup infrastructure lives in our network, managed with our credentials and our controls, in our own datacenter in Spain with ISO 27001 certification and ENS compliance. The "air gap" is the boundary between your domain and ours.
The result combines the best of both worlds: the protection of a disconnected copy with the automation and RTO of an online one. Copies leave every night with no manual intervention, become immutable as they are written and are ready to restore in minutes, not days.
Common Mistakes: False Air Gaps
Post-incident ransomware analyses keep surfacing the same design mistakes, all sharing one pattern: copies that looked protected but were reachable from the compromised network:
- check_circle A NAS mounted over SMB is not an air gap: if the repository is a shared folder reachable with domain credentials, ransomware encrypts it like any other network resource. It is the most frequent false air gap.
- check_circle A snapshot is not a backup: it lives on the same storage array as the data it protects. If the attacker compromises the array or the hypervisor, snapshots are wiped with a single command. They are for reverting mistakes, not for surviving an attack.
- check_circle Backup credentials in the same AD domain: if the backup server and its service accounts belong to the production Active Directory, compromising the domain means compromising the backup. Backup system accounts must be local or belong to a separate administrative domain.
- check_circle Immutability an administrator can disable: "governance" modes or retention periods the account owner can shorten will not resist an attacker holding those credentials. For an air gap, immutability must be compliance-grade.
- check_circle Never testing restores: the "0" in the rule exists for a reason. An immutable but corrupt or incomplete copy reveals its uselessness on the worst possible day.
Frequently Asked Questions
Does a cloud copy count as an air gap?
Yes, as long as it is a real logical air gap: credentials independent from the customer's domain, immutability enabled (S3 Object Lock or a hardened repository) and a separate administration plane. A service like Veeam Cloud Connect with immutable storage acts as an air gap managed by the provider. A cloud folder mounted as a network drive with the same corporate credentials is not one.
Does a physical air gap with tapes still make sense?
Yes, for long-term archiving and very large volumes, where the per-TB cost of LTO tape remains unbeatable. Its drawbacks are a high RTO, dependence on manual processes and the exposure window between rotations. For most SMEs, a logical air gap with immutable storage offers a better balance of protection, automation and restore speed.
What is the difference between immutability and air gap?
They are complementary concepts. Immutability prevents data from being modified or deleted during a defined period, even if the attacker reaches it. An air gap directly prevents the attacker from reaching the copy at all. Modern logical air gaps combine both: separate credentials and network (isolation) plus S3 Object Lock or hardened repositories (immutability), so the copy survives even a full domain compromise.
Conclusion
Ransomware has turned the backup into its first target, and that forces us to design copies assuming the entire network may be compromised:
- arrow_right An air gap is a copy out of the attacker's reach: physically disconnected or protected by immutability, independent credentials and an isolated network.
- arrow_right The physical air gap (tapes, rotated disks) offers total disconnection at the cost of high RTO, manual processes and human error. The logical variant offers continuous, automated protection with instant restores.
- arrow_right In the 3-2-1-1-0 rule, the last "1" is precisely that offline or immutable copy, and the "0" demands periodic restore verification.
- arrow_right With EasyDataHost's Veeam Cloud Connect and S3 Object Lock you get a managed air gap: credentials independent of your domain, compliance-grade immutability and our own datacenter in Spain.
If you want to check whether your backup strategy would survive a full compromise of your network, contact our team: we will review your backup architecture and propose the right air gap design, no strings attached.