---
title: "Protecting Students, Peers and Partners: A Prac… | Firevault"
description: "A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/guide-safeguarding-education-data#webpage",
      "url": "https://fire-vault.com/news/guide-safeguarding-education-data",
      "name": "Protecting Students, Peers and Partners: A Prac…",
      "description": "A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/guide-safeguarding-education-data#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/guide-safeguarding-education-data#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Protecting Students, Peers and Partners: A Practical Education Data Briefing",
          "item": "https://fire-vault.com/news/guide-safeguarding-education-data"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Protecting Students, Peers and Partners: A Practical Education Data Briefing",
      "description": "A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.",
      "url": "https://fire-vault.com/news/guide-safeguarding-education-data",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-29T19:48:49.913548+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/guide-safeguarding-education-data"
      },
      "inLanguage": "en-GB",
      "articleSection": "Guides",
      "wordCount": 2457,
      "keywords": "Protecting, Guides, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "A practical briefing to help you protect your students, peers and partners going forward, written for headteachers, trust leaders, governors, data protection officers, IT leads, university registrars and research administrators. Mark Fermor · Director and Co-Founder, Firevault The Department for Education breach, disclosed in late July 2026, exposed more than 607,000 records. Names, email addresse",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Who is this guide for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Headteachers, trust leaders, governors, data protection officers, school business managers and IT leads responsible for pupil records, safeguarding files and supplier oversight."
          }
        },
        {
          "@type": "Question",
          "name": "What is the single most important action for a school?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Hold an offline copy of the records you could never rebuild, and put phishing-resistant multi-factor authentication on every account that can reach pupil data."
          }
        },
        {
          "@type": "Question",
          "name": "Why is children's data treated as higher risk?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Safeguarding notes, medical details, care arrangements and protected addresses cannot be reissued or cancelled. Once published, the harm is permanent and follows the child."
          }
        },
        {
          "@type": "Question",
          "name": "How quickly must a school report a data breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A personal data breach that poses a risk to individuals must be reported to the Information Commissioner's Office within seventy-two hours of the school becoming aware of it, and affected people must be told where the risk is high."
          }
        },
        {
          "@type": "Question",
          "name": "Are pupils themselves a threat?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. The Information Commissioner's Office has warned that many education incidents involve pupils using shared or observed credentials, often for status rather than financial gain."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What this means for your student…Priority actions: protect your s…This has already happened, repea…Where education estates come uns…What good looks likeWhy offline storage matters for …The pressure is not only regulatoryReporting an incidentChoosing the right Offline Secur…More Resources

[Knowledge Vault](/learn/knowledge)/ [Guide](/learn/knowledge?filter=guides)

Guide · 29 July 2026 

# Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

13 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fguide-safeguarding-education-data)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fguide-safeguarding-education-data&text=Protecting%20Students%2C%20Peers%20and%20Partners%3A%20A%20Practical%20Education%20Data%20Briefing%0A%0AA%20practical%2C%20forward-looking%20briefing%20to%20help%20schools%2C%20colleges%20and%20universities%20protect%20students%2C%20staff%20and%20partner%20data%20after%20the%20Department%20for%20Education%20breach.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fguide-safeguarding-education-data)[](mailto:?subject=Protecting%20Students%2C%20Peers%20and%20Partners%3A%20A%20Practical%20Education%20Data%20Briefing&body=A%20practical%2C%20forward-looking%20briefing%20to%20help%20schools%2C%20colleges%20and%20universities%20protect%20students%2C%20staff%20and%20partner%20data%20after%20the%20Department%20for%20Education%20breach.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fguide-safeguarding-education-data)

![School records room at dusk with metal filing cabinets, an open drawer of paper student files and a laptop on a desk, representing offline protection of education data](/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg)

School records room at dusk with metal filing cabinets, an open drawer of paper student files and a laptop on a desk, representing offline protection of education data

Why it matters

## What this means for organisations holding critical data

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

In this analysis

1.  01 [What this means for your student…](#section-0)
2.  02 [Priority actions: protect your s…](#section-1)
3.  03 [This has already happened, repea…](#section-2)
4.  04 [Where education estates come uns…](#section-3)
5.  05 [What good looks like](#section-4)
6.  06 [Why offline storage matters for …](#section-5)

**On this page**[What this means for your student…](#section-0)[Priority actions: protect your s…](#section-1)[This has already happened, repea…](#section-2)[Where education estates come uns…](#section-3)[What good looks like](#section-4)[Why offline storage matters for …](#section-5)[The pressure is not only regulatory](#section-6)[Reporting an incident](#section-7)

_A practical briefing to help you protect your students, peers and partners going forward, written for headteachers, trust leaders, governors, data protection officers, IT leads, university registrars and research administrators._

**Mark Fermor · Director and Co-Founder, [Firevault](https://fire-vault.com/)**

The Department for Education breach, disclosed in late July 2026, exposed more than 607,000 records. Names, email addresses, telephone numbers and job titles were taken from two public-facing systems. The department is now working with the National Cyber Security Centre and the National Crime Agency.

That incident is a warning, not just a headline. The institutions that feed data into central systems now need to ask a practical question: are the students, staff and partners in our care protected going forward? Education holds some of the most sensitive personal data in the country. Safeguarding notes, social care referrals, EHCPs, SEND plans, medical conditions, immigration status, adoption arrangements, court orders, protected addresses and photographs of children cannot simply be reissued like a bank card. A child cannot be given a new childhood.

This briefing is not written for a data centre. It is written for the people who keep an education institution running day to day: the school office, the college leadership team, the university registry. It focuses on what you can do now, and next term, to protect the students, peers and partners who rely on you.

## What this means for your students, peers and partners

The DfE breach was a failure outside the school gate. It is a reminder that data handed to central systems, third-party platforms and shared services remains exposed. The protection each institution needs looks different depending on who you serve.

### Schools and academies

Your students are children. The data you hold is some of the most emotionally sensitive in the country: child protection logs, SEND plans, EHCPs, family contact details, medical information and photographs. A single compromised staff account or supplier breach can expose all of it.

The immediate risk is not only an Information Commissioner's Office fine. It is broken trust with parents, intervention from the local authority, and governors explaining why files that should never have left the building are now elsewhere. For multi-academy trusts, scale makes the problem worse. Centralise data across several academies and one breach can affect thousands of pupils. Trust leaders need segmented access, a tested incident plan, and an offline copy of irreplaceable records that no central system can reach.

Going forward: protect your students by separating safeguarding data from everyday drives, controlling who can retrieve it, and keeping an offline gold copy that ransomware cannot touch.

### Sixth-form and further education colleges

Colleges sit between schools and universities. They hold young-adult learner records, employer and apprenticeship data, exam-board entries, bursary and financial details, and many of the same safeguarding duties because students under eighteen are still present. Their workforce is also more fluid: part-time staff, agency tutors and subcontractors move between sites.

Ties to central funding and tracking systems are why this breach matters to colleges. If a central portal can be breached, the suppliers beneath it can be too. Check that apprenticeship data, exam entries and learner records are not sitting in one shared drive with no segregation, and that ransomware would not wipe out the records exam boards, auditors and the Education and Skills Funding Agency expect to see.

Going forward: protect your peers and partners by segmenting access, clearing inherited logins, and rehearsing the first two hours of an incident.

### Universities and higher education

Universities hold everything a school holds, plus the assets that generate institutional value: unpublished research, doctoral work, patent applications, grant files, commercial partnerships and [intellectual property](/oss-for-intellectual-property). A [ransomware attack](/threats/ransomware) can halt research, freeze admissions, and anger funders, alumni and partners at once.

Government-held data is only one part of the picture. Universities share large datasets with research councils, funding agencies and international partners. The attack surface is wider and the users more dispersed. Separate research IP from general storage, keep a gold copy of critical datasets offline, and make sure the credentials protecting a grant file are not the same ones that open a staff email account.

Going forward: protect your partners by isolating research IP, controlling supplier access and making sure your most valuable datasets are not only in the cloud.

## Priority actions: protect your students, peers and partners this term

1.  **Put phishing-resistant multi-factor authentication on every staff account.** Start with accounts that can reset others: senior leadership, the business manager, the data protection officer, and anyone with admin rights in your management information system.
2.  **Separate safeguarding from everyday systems.** Those files should never sit in a drive any teacher can browse, or be reachable from a general staff login.
3.  **Take an offline copy of what you could never rebuild.** Safeguarding files, SEND plans and reviews, admissions history and governance papers belong in an offline vault that an intruder on your network cannot reach.
4.  **Interrogate your suppliers.** Management information systems, cashless catering, parent apps, learning platforms, coach hire, photography. Ask each where the data lives, how long it is kept, and what happens when the contract ends.
5.  **Clear out the places data was never meant to be.** Personal email, unmanaged memory sticks, staff home laptops, forgotten machines in a cupboard, and legacy drives from systems you replaced years ago.
6.  **Rehearse the first two hours.** Who is called, who speaks to parents, who notifies the Information Commissioner's Office within seventy-two hours, and who can run the place on paper.

## This has already happened, repeatedly

### Department for Education, England, 2026

More than 607,000 records containing names, email addresses, telephone numbers and job titles were taken across two public-facing systems. The department is working with the National Cyber Security Centre and the National Crime Agency. (BBC News; The Times.)

### PowerSchool, 2024 to 2025

A compromise of the PowerSchool student information system exposed data on millions of pupils and teachers across the United States and Canada, including names, addresses, dates of birth and, in some districts, medical and social security details. Paying the extortion demand did not stop districts being threatened directly afterwards. One supplier became a single point of failure for thousands of schools. (BleepingComputer.)

### Vice Society and UK schools, 2022 to 2023

When ransoms were refused, files stolen from a series of English schools were published: SEND records, scans of children's passports, safeguarding information and staff contracts. (BBC News.)

### Los Angeles Unified School District, 2022

Roughly 500 gigabytes from the second-largest district in the United States was published after it declined to pay. Psychological assessments of pupils were among the released files. (BBC News.)

### Minneapolis Public Schools, 2023

The Medusa group released a very large archive of district files, including detailed case material on individual pupils. (The Record.)

### The threat from inside the building

The Information Commissioner's Office has warned that many education incidents start with pupils and students. The motive is usually curiosity or status rather than money, and the way in is usually a weak or shared password. (BBC News.)

## Where education estates come unstuck

**Shared and inherited logins.** Cover teachers, trainees, peripatetic staff, site teams, agency workers and postgraduate researchers all drift onto shared accounts. Each one erases the audit trail your data protection officer will need on the worst day. Issue individual accounts, and switch them off the day someone leaves.

**One login that opens everything.** In many institutions a single compromised account reaches the management information system, the shared drive, the photograph archive and the safeguarding folder. Segment by role, and give safeguarding its own approval step.

**Backups beside the thing they protect.** A backup on the same network, behind the same password, is not a backup. Ransomware hunts online backups first. This is the usual reason an institution loses years of records rather than a weekend of work.

**Retention drift.** Education rarely deletes anything. Former pupils, alumni, applicants who never enrolled, staff who left a decade ago: all still sitting in systems nobody patches. A record you no longer hold is a record nobody can steal.

**Photographs and biometrics.** Photography, fingerprint catering and facial recognition all create identifiable data about children. The Information Commissioner's Office has already reprimanded schools for facial recognition deployed without a lawful basis or an impact assessment. Ask whether the convenience justifies the record you are creating.

## What good looks like

-   Individual accounts, phishing-resistant multi-factor authentication, and a leaver check every term.
-   Role-based access, with safeguarding held separately and every retrieval logged.
-   A retention schedule that is genuinely followed, legacy systems included.
-   A gold copy of irreplaceable records held offline and physically disconnected at the hardware level.
-   Supplier due diligence in a register, with processing agreements and exit terms written down.
-   An incident plan that assumes the network is gone, rehearsed annually with governors.

## Why offline storage matters for protecting students, peers and partners

Almost every control in an education institution is a logical one. Passwords, permissions, firewall rules and cloud policies are instructions given to a connected system, and an attacker already inside that system can rewrite them.

[Offline Secure Storage®](/offline-secure-storage) removes the connection itself. Records in a Firevault vault sit on hardware that is physically disconnected at Layer 1 when not in use, hardware-encrypted and locked to named individuals. Someone can hold your entire online estate and still be unable to read, alter, encrypt or delete what is not attached to it. For safeguarding and SEND files, that can be the difference between an incident and a catastrophe. Disconnect to Protect®, the principle is a physical break, not another logical rule.

When you protect a safeguarding file this way, you are protecting the student behind it. When you protect research IP this way, you are protecting the peers and partners who funded and collaborated on it.

## The pressure is not only regulatory

Schools and colleges may not face the financial penalties a commercial business would. That is cold comfort. Local press coverage and governance fallout are just as hard to live with, and a breach involving safeguarding or SEND data can dominate a governing body meeting for months, or invite intervention from the local authority or the Education and Skills Funding Agency.

The Department for Education is not only about schools. Sixth-form colleges, further education colleges and universities sit within its wider responsibilities and carry extra risk: research data, grant-funded intellectual property, commercial partnerships, large cohorts of young adults, and apprenticeship and employer records.

That intellectual property deserves its own line. Unpublished findings, patent applications, partnership agreements and doctoral work are not simply personal data. Losing them is a direct loss of institutional value and years of work nobody can recreate.

## Reporting an incident

A personal [data breach](/learn/breaches) that poses a risk to individuals must reach the Information Commissioner's Office within seventy-two hours of you becoming aware of it, and where the risk is high, the individuals themselves must be told. Serious incidents should also go to the National Cyber Security Centre and Action Fraud. Log every breach, including those you decide not to report, with your reasoning.

## Choosing the right Offline Secure Storage size

Most institutions overthink the technology and underthink the capacity. The right size follows from the records you could never rebuild, not the total size of your network.

### What to count

Add up what you could not recreate if your online systems were encrypted or deleted tomorrow:

-   **Safeguarding and child protection.** Case notes, chronologies, referrals, strategy minutes and supporting evidence.
-   **SEND.** EHCPs and SEND plans, annual reviews, specialist reports, provision maps and medical plans.
-   **Admissions and census history.** Registers, attendance, leavers information and alumni files.
-   **Photographs and media.** Only the archival set you are obliged to keep, though whole-school photography is often the largest file set you own.
-   **Governance and legal.** Trust deeds, minutes, land and building documents, insurance claims, tribunal files and settlements.
-   **Finance and payroll.** Historical payroll, pension data, audit trails and accounts.
-   **Research and IP.** Unpublished research, patent applications, grant files and partnership data.

### A rough sense of scale

A maintained primary school usually lands between 50 GB and 150 GB. A large secondary, sixth-form college or multi-academy trust is more often 500 GB to 2 TB once photography and media are included. Independent schools, universities and long retention histories can run larger again.

Capacity is not the deciding factor. The question is whether the storage carries the access control and audit model safeguarding data demands. Start at [Vault](/vault) rather than [LUV](/luv), because Vault provides the identity verification, named-user control and session logging those records require.

To estimate quickly: size the folders you would want back first, multiply by three for version history and growth, then take the tier above that number.

### Mapping to an OSS tier

-   **Schools, academies and sixth-form colleges.** A [Vault](/vault) plan is the starting point, with 2 TB, 4 TB and 8 TB options covering most institutions. Choose room to grow rather than a tier that fits today exactly.
-   **Trusts, local authorities and university departments.** [Firevault Storage](/storage), from 8 TB to 300 TB, suits consolidated estates across several sites, or research and media archives.
-   **Above 300 TB.** [Enterprise](/enterprise) provides physically isolated, bespoke deployments for central archives, large media libraries or multiple campuses.

### How many seats?

Every Firevault user is identity-verified and tied to a named individual. We agree the seat count and the holders with you during onboarding, and the decision is yours. The principle is not to give everybody access, but to give it to the people who can authorise a retrieval and stand behind the audit trail.

In practice that often means the headteacher, the data protection officer, the business manager, the designated safeguarding lead, the SENCO, the IT lead and the chair of governors. A university might add the registrar, a research data manager and a faculty contact; a trust might add its own data protection officer and a nominated person from each academy.

### When in doubt, start smaller

[Offline Secure Storage](/offline-secure-storage) is a hedge, not a migration project. Start with safeguarding and SEND, the material that cannot be reissued. Once the process is proven, add admissions, photography, governance and research files. The aim is to break the single point of failure, not to mirror your network.

### If the budget is tight

Funding is a common obstacle, and there are ways round it. Institutions have paid for this through the parent-teacher association, a governor sub-committee or a research integrity fund. The cost is a known annual line rather than a per-user licence that grows every September. Present it as a discrete resilience project: the gold copy of safeguarding records, SEND files and governance papers, kept in a physical vault that ransomware cannot reach. One fundraising evening can cover it.

If you would like a walkthrough of how Offline Secure Storage would apply to your school, college, university or trust, [speak to a member of the team](/contact).

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye](/__l5e/assets-v1/084c38b8-253b-4cc2-9056-c78a2fbd36c3/urgent-warning-triangle-20260714-2x.jpg)

Guides 

### Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye

Practical steps for serving and former politicians, councillors, campaigners, journalists, executives, broadcasters and anyone in the public eye, covering email security, device hygiene, threat handling and offline secure storage.

14 Jul 2026 22 min 







](/news/urgent-guide-protecting-personal-data-high-profile-public-eye)[

![500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fcontrolled-access-buyers-guide.jpg)

Guides 

### 500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide

In April 2026, approved researchers exfiltrated the health records, genetic data, and medical histories of 500,000 UK Biobank volunteers through authorised access channels, then listed the data for sale on Alibaba. The breach was not caused by a hack. It was caused by a model that assumes licence agreements can prevent data theft. This guide covers why that model fails and what physical controls replace it.

23 Apr 2026 18 min 







](/news/controlled-access-buyers-guide-offline-secure-storage)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)[

![Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Insight 

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min 







](/news/beacon-charity-database-breach-hiv-charity-health-data-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)