Recent Breaches
Breaches
View All →

Security & Trust Centre

Compliance, Assurance,
and Governance.

Understand how Firevault protects your data through architectural security, identity verification, and governance controls. Every claim verified with sources.

Offline by default
Identity locked access
Hardware encrypted
Create Your Vault
Security Architecture

Built on Physical Disconnection

When data is offline, there is no network path for attackers to exploit. This is security by architecture, not by configuration.

Physical Disconnection

Your data resides on hardware that is physically disconnected from networks. No IP address, no attack surface, no remote exploitation.

Layer 1 physical air gapNo network exposureZero standing connections

Hardware Encryption

All data is protected by Quantum Key Encryption and hardware level AES-256. Encryption keys never leave the secure enclave.

Quantum Key EncryptionAES-256 at hardware levelKey isolation

Identity Verification

Every account is verified through Know Your Customer (KYC) and Anti-Money Laundering (AML) checks at onboarding, permanently linking the account to a confirmed identity. Access then requires Multi-Factor Authentication (MFA) at every session.

Know Your Customer and AML at onboardingMulti-Factor Authentication at every sessionIdentity-linked account

Zero Standing Privileges

No administrator has persistent access. Every session is explicitly authorised for a defined purpose and time window.

No persistent accessTime-limited sessionsAudit trail
Third-Party Verified

Certifications & Assurance

Security Audits

Regular third-party penetration testing and security assessments by accredited firms.

Secure Facilities

Data stored in carefully selected Tier 3+ Firevault Bunkers with 24/7 physical security and clear jurisdictional boundaries.

Vetted Personnel

All staff undergo background checks and security clearance as required.

Key Management

Cryptographic keys managed using hardware security modules with strict access controls.

Compliance Alignment

How Offline Secure Storage (OSS) Helps Customers Align

Firevault's physical disconnection and hardware encryption help organisations meet regulatory requirements across financial services, healthcare, legal, and other regulated sectors.

CAF 4.0

Physical isolation supports NCSC Cyber Assessment Framework objectives for critical infrastructure

NIS2

Offline storage helps meet network and information systems security requirements

PCI DSS

Hardware encryption and access controls support payment card data protection

FCA

Demonstrates operational resilience controls for financial services regulatory compliance

GDPR

Physical disconnection helps demonstrate appropriate technical measures for personal data protection

ISO 27001

Supports information security controls through hardware encryption and access management

SOC 2

Offline architecture provides verifiable evidence for security and availability controls

Cyber Essentials Plus

Layer 1 physical air gap storage aligns with UK Government cybersecurity requirements

Verified Sources

The Firevault Trust Index

What We Say. Where We Say It. Why It Is True.

Whether you are a legal team, investor, analyst, journalist, or procurement officer, this section exists to provide clarity and credibility for every stat, fact, and claim.

What we said

The exact claim or statistic we have published

Where we said it

The pages on our site where you will find it

Where it comes from

The original source with verification link

1The Scale of Digital Theft

Claim
Where We Use It
Source

"Cybercrime costs £8.3 trillion annually (2025 projection)."

HomepageMeet FirevaultInvestors

"50 billion+ online files stolen per year."

Homepage Hero EyebrowMeet FirevaultBreaches Page

"54% of online data is classified as sensitive."

Why FirevaultSolution Pages

"Every 2 seconds, a cyberattack threatens exposure."

Why FirevaultReal Threats Section

2The Cost of Breach and Ransomware

Claim
Where We Use It
Source

"Average global data breach cost is £3.5 million."

HomepageMeet FirevaultBrand Notes

"Average UK data breach cost is £3.5 million."

Homepage StatsInvestorsSolution Pages

"Average US data breach cost is £8.1 million."

Trust Index

"Average Middle East data breach cost is £5.7 million."

Trust Index

"It takes an average of 277 days to identify and contain a breach."

Why FirevaultSolution Pages

"Ransomware attacks have risen by 105%."

Why FirevaultRansomware Risk Page

3Individual and Personal Fraud

Claim
Where We Use It
Source

"Average scam victim loss in the UK is £879."

Vault PageIndividuals PageCustomer Fraud Page

"Average fraud loss for millennials (29 to 44 year olds) is £1,457."

Individuals PageTrust Index

"Average APP fraud loss is £2,423 per case."

Customer Fraud PageTrust Index

"Average HNWI cyber loss is £2.7 million."

HNWI PageFamily Offices Page

4Director and Executive Liability

Claim
Where We Use It
Source

"94% of breaches target executive-level information."

Directors PageExecutive Leadership Page

"Average breach cost when board data is compromised: £4.7 million."

Directors PageRisk Governance Page

"Maximum ICO director personal liability: £500,000."

Directors PageRegulatory Fines Page

"D and O insurance claims have increased 40% year-on-year due to cyber incidents."

Directors PageRisk Governance Page

5Sector-Specific Breach Costs

Claim
Where We Use It
Source

"Average breach cost in healthcare: £10.9 million, highest of any sector globally."

Healthcare Page

"Average breach cost in financial services: £4.45 million."

Banking PageFinance Role Page

"Average breach cost in professional services: £4.2 million."

Legal PageProfessional Services Page

"Average breach cost in retail: £4.1 million."

Retail Page

"Average breach cost in energy sector: £4.7 million."

Energy PageCritical Infrastructure Page

"Average breach cost for UK small businesses: £165,000."

SME Page

6SME and Small Business Risk

Claim
Where We Use It
Source

"43% of all cyber attacks target small businesses."

SME PageReal Threats Section

"60% of small businesses close within 6 months of a cyber attack."

SME PageWhy Firevault

"82% of ransomware attacks target businesses under 1,000 employees."

SME PageRansomware Risk Page

"89% of law firms were targeted by cyber attacks in 2024."

Legal Page

7Compliance and Regulatory

Claim
Where We Use It
Source

"GDPR fines can reach up to €20 million or 4% of annual global turnover."

Compliance PagesDPO Role Page

"NIS2 maximum fine: £17 million+ for critical infrastructure failures."

Critical Infrastructure PageDefence Page

"UK businesses face mandatory 72 hours breach notification requirements."

Compliance PagesDirectors Page

8Recent High-Profile Breaches

Claim
Where We Use It
Source

"M and S suffered a major cyber incident affecting customer data in 2025."

Homepage TickerBreaches Page

"JLR (Jaguar Land Rover) experienced a ransomware attack exposing internal systems."

Homepage TickerBreaches Page

"PayPal disclosed a credential stuffing attack affecting 35,000 accounts."

Homepage TickerBreaches Page

"The Co-op reported a significant data breach in 2025."

Homepage TickerBreaches Page

9Firevault: Verified Product Claims

Claim
Where We Use It
Source

"Firevault is the world's first offline secure storage platform. Others may claim to offer an offline vault, a vault, or offline storage, but no one else delivers offline secure storage: physically disconnected, hardware encrypted, identity-locked, and managed as a complete platform."

HomepageMeet FirevaultPress and Media+1
Internal product architecture and competitive analysis

"Vault by Firevault is a digital safe deposit box for individuals, SMEs and professionals."

Vault PageCreate Your VaultSolution Pages
Product definition

"Storage by Firevault is scalable offline secure storage for businesses and service providers."

Storage PageEnterprise Solution Pages
Product definition

"Quantum key encryption for key exchange combined with hardware-level AES-256 encryption for data at rest."

Security PageFAQTechnical Summaries
Engineering documentation

"Physically disconnected and offline by default. No IP address, no standing access, no attack surface."

Why FirevaultOur DifferenceVault User Commitment
Engineering documentation

"Identity-locked with KYC, MFA, and legal successor control (Vault Buddy)."

Create Your VaultResilience and Legacy Page
KYC and succession workflow

"No third-party access. No remote admin. Not even Firevault can access your data."

Vault User CommitmentOur Difference
Firevault policy and architecture

"All vaults require a 36-month minimum commitment."

Create Your VaultPricingFAQ
Customer plan structure

"Stored in Firevault Bunkers, physically secured colocation facilities in the United Kingdom."

Trust SectionMeet FirevaultBunkers Page
Firevault infrastructure policy

"Zero data breaches since inception."

Trust SectionHomepageFooter
Firevault security record

"2TB, 4TB and 8TB vaults are physically returned with 24/7 access. 300GB vaults are downloaded via two weekly access windows."

FAQVault PageCreate Your Vault
Product access policy

"Each vault is assigned to one owner and one mobile phone account. Sharing is only permitted via Butterfly deployment mode."

FAQVault Page
Product access policy

References

  1. [1]Cybersecurity Ventures 2025 Almanac — https://cybersecurityventures.com/cybersecurity-almanac-2025/
  2. [2]Thales Data Threat Report 2025 — https://cpl.thalesgroup.com/data-threat-report
  3. [3]ENISA Threat Landscape 2024 — https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024
  4. [4]IBM Cost of a Data Breach Report 2025 — https://www.ibm.com/reports/data-breach
  5. [5]Sophos State of Ransomware 2024 — https://assets.sophos.com/X24WTUEQ/at/3bxxmz2zj7cbsxzmnhn7cft/sophos-state-of-ransomware-2024.pdf
  6. [6]GASA/Cifas State of Scams Report 2025 — https://www.cifas.org.uk/newsroom/9.4billion_stolenfromconsumers
  7. [7]UK Finance Annual Fraud Report 2025 — https://www.ukfinance.org.uk/policy-and-guidance/reports-and-publications/annual-fraud-report-2025
  8. [8]Campden Wealth Report — https://www.campdenwealth.com/
  9. [9]Verizon DBIR 2024 — https://www.verizon.com/business/resources/reports/dbir/
  10. [10]ICO enforcement guidance — https://ico.org.uk/
  11. [11]Allianz Risk Barometer 2024 — https://www.agcs.allianz.com/news-and-insights/reports/allianz-risk-barometer.html
  12. [12]UK Government Cyber Breaches Survey 2024 — https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024
  13. [13]National Cyber Security Alliance — https://staysafeonline.org/
  14. [14]Sophos State of Ransomware 2024 — https://www.sophos.com/en-us/content/state-of-ransomware
  15. [15]SRA/National Cyber Security Centre — https://www.ncsc.gov.uk/
  16. [16]GDPR Article 83 — https://gdpr.eu/fines/
  17. [17]NIS2 Directive — https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
  18. [18]ICO guidance — https://ico.org.uk/for-organisations/report-a-breach/
  19. [19]BBC News — https://www.bbc.co.uk/news/articles/cwy0x8dk9y4o
  20. [20]BleepingComputer — https://www.bleepingcomputer.com/news/security/jaguar-land-rover-hit-by-hellcat-ransomware-data-stolen/
  21. [21]BleepingComputer — https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/
  22. [22]BBC News — https://www.bbc.co.uk/news/articles/cz9r4p9lp0wo

For due diligence

For procurement audits

For compliance and press

We update this guide regularly. If you need official verification or source documents, reach out:

Statistics Last Verified

January 2026

All claims verified against original sources. Next scheduled review: April 2026.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Verify our security for yourself

Review our Trust Index, request a penetration test report, or book a technical deep-dive with our team.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®