Cyber vault, defined

Cyber vaults are ultra-secure storage solutions that isolate backups either physically or logically from primary storage. 

Cyber vaults are a protection against catastrophic security failures caused by ransomware, wiper malware, rogue administrators or insider threats, and other cyberattacks. During normal operations, data is regularly pulled from primary storage to the cyber vault, typically via a one-way or restricted network path. It operates like a tire spike strip—data can move from the primary storage to the cyber vault, but not the reverse.

The exception is recovery: when an organization needs to restore data from the vault, data flows back to production under tightly controlled conditions. The data stored in the cyber vault is immutable: it cannot be altered or deleted, either permanently or within a pre-arranged time frame.

Cyber vaults can be a valuable component of an overall cyber resilience strategy. Cyber resilience is a modern way of thinking about cybersecurity in terms of business continuity. It assumes certain truths, namely that risks cannot be entirely eliminated and that therefore the way in which an organization responds to an attack or threat is just as important as the attempts to prevent an attack in the first place.

How does a cyber vault work?

There are different data protection configurations for cyber vaults, each with its own strengths and weaknesses:

Physical cyber vault

Physical cyber vaults provide the highest level of data security for backups by using what’s called a physical air gap. Physical cyber vaults have no active connection to the outside world at all. There are two main types of physical cyber vaults.

Fully manual

In a textbook fully manual physical cyber vault, the backup storage has no network access whatsoever. Data is transferred manually on removable storage media, which might be solid-state drives (SSDs), hard disk drives (HDDs), USB drives or linear tape-open (LTO).

LTO is a magnetic tape standard that can hold an astounding amount of data, up to 40 TB (100 TB compressed), onto a single cartridge. It is beneficial for security and long-term storage, however, it is sequential, meaning that to retrieve data, the system must physically wind through the tape before arriving at the requested data (*transfer speeds are high when winding is complete). Though it’s a somewhat low-tech and minimally automated system—it even has an old-timey nickname, “sneakernet”—this system is still used by governments and in other high-risk industries. 

Fully manual cyber vaults function like a traditional bank vault: a person must walk the valuables into a secure room to transmit data. This method eliminates the network-based attack surface—the cyber vault has no network connection—but there is a risk of human error.

The liaison between primary and cyber vault storage can be absent or otherwise compromised. Theoretically, the physical storage can even be used as a Trojan horse: ransomware or other malware can be loaded onto the storage device, which the administrator then unknowingly adds to the cyber vault.

Operational air gap (sometimes called a drawbridge or intermittent air gap)

In an operational air gap system, the cyber vault is technically kept wired to the primary storage, but that connection is inactive except during a highly controlled, temporary transfer period. By default, the switch ports or cables are kept unpowered or disabled, replicating the effect of total disconnection. 

On initial setup, the cyber vault’s network connection is activated. The cyber vault pulls a complete and total backup of the chosen primary storage, then is powered off until the next regular backup time.

Then, at regular intervals, the network connection is powered on. This is often a daily occurrence after work hours. At that time the cyber vault initiates an encrypted data transfer. This transfer might use a Transport Layer Security (TLS) connection, which encrypts individual application streams, or Internet Protocol Security (IPsec), which encrypts every packet traveling between the primary storage and cyber vault.

When this data transfer is initiated, the vault uses per-session authentication that is only valid for that specific transfer window to request any data changes or new data. This part is important: the cyber vault pulls the data, rather than the primary storage pushing the data. The vault holds the only credentials for the transfer, and the primary storage cannot initiate a connection to the vault. An attacker that gains access to production systems has no path to reach the backups. 

When the transfer is complete, the vault severs the connection automatically, essentially withdrawing the drawbridge and reinstating the physical air gap.

Logical cyber vault

A logical or cloud-based cyber vault is an evolution of the cyber vault concept, but not necessarily a replacement for it. Logical cyber vaults create a “virtual air gap” rather than a physical one by deploying a separate cloud storage system. Often this system is managed by a dedicated backup as a service (BaaS) vendor.

Logical cyber vaults replicate the function of a physical cyber vault at a lower expense (and with added convenience), though they are generally considered less secure. That said, logical cyber vaults are often more secure than local backup systems and provide many of the same benefits as a physical cyber vault.

How a logical cyber vault works

At regular intervals, automated processes within the vault account make application programming interface (API) calls to open a secure, encrypted network path. This is the digital equivalent of powering on the switch ports in a physical drawbridge system. The vault then pulls data from primary storage via HTTPS, rather than less secure protocols such as Server Message Block (SMB) or File Transfer Protocol (FTP).

This path uses a private IP address and services that keep traffic off the public internet. Zero-trust access controls are often used to further reduce the risk of a data breach. When the transfer is complete, an automation closes the connection and revokes access: the digital drawbridge goes back up.

Key features of a cyber vault

Cyber vaults include several security features to provide necessary controls and protections. These features fall into three categories: immutability (makes data impossible to delete or overwrite), strict access control, and intelligent threat detection. 

Immutable storage

Immutable storage secures backups using the write once, read many (WORM) model: data remains accessible to those with authorization but cannot be altered outside certain circumstances. In cloud vaults, immutability is implemented through object locking; in physical vaults, through WORM tape or retention-locked back up appliances.

Immutability can be set for a fixed length of time, during which nobody, not even an administrator or CEO, can delete, overwrite or alter the data. Alternately, it can be applied indefinitely, remaining in place until a specific authorized admin manually removes it.

Quorum authorization

In some classic action movies, a missile or bomb can only be activated when two or more people turn a key at the same time— known as the “two-man” rule in military and nuclear security. This model has a digital equivalent, known as quorum authorization, multi-person authorization (MPA) or “M of N” control. The latter refers to the requirement that a minimal number (M) of a larger group of authorized administrators (N) is required to perform a given action.

In quorum authentication, an administrator can request an action, such as shortening retention periods or changing vault access. This request is typically time-sensitive and requires that multiple authorized users approve the request by logging in with biometrics or hardware keys within the designated period.

Intelligent monitoring

Modern cyber vaults increasingly incorporate artificial intelligence (AI) and machine learning (ML) models to streamline and optimize the data backup process. These features can analyze incoming data for entropy—the randomness, disorder or unpredictability of data. Some files, such as uncompressed database files, have very low entropy, while encrypted files have high entropy. If the entropy analysis suddenly spikes in a situation where entropy is typically low, monitoring systems can flag the spike as suspicious. 

Intelligent monitoring features can also provide additional security by measuring current patterns against historical ones. For example, if daily backup volume changes significantly, AI monitoring tools can issue an alert and lock the system until security is verified.

In addition, monitoring solutions can search for indicators of dormant malware or check for unusual backup activity (such as an administrator logging in from an unusual location). Sometimes a cyber vault with these analytical features is referred to as a cyber recovery vault.

Authors

Dan Nosowitz

Staff Writer, Automation & ITOps

IBM Think

Michael Goodwin

Staff Editor, Automation & ITOps

IBM Think

Related solutions
IBM FlashSystem Cyber Resilience

Flash storage with built‑in, AI‑driven protection and immutable snapshots to defend against cyberattacks and enable fast recovery.

Explore FlashSystem Cyber Resilience
Storage data resilience solutions

Protect and safeguard your data against failures, cyberattacks, and disasters with AI‑powered threat detection, immutable snapshots, and enterprise‑grade storage resilience.

Explore storage data resilience solutions
Threat management services

AI-powered detection, monitoring, and rapid response to protect IT, OT, and hybrid-cloud environments.

Explore threat management services
Take the next step

IBM FlashSystem Cyber Resilience and Storage for Data Resilience — AI‑powered protection, immutable backups, and fast recovery for secure, reliable data.

  1. Explore FlashSystem Cyber Resilience
  2. Explore storage data resilience solutions