Recent Breaches
Breaches
View All →
Offline Secure Storage (OSS) for Directors

Protect Directors from Fines & Liability

Under GDPR, NIS2, and UK data protection law, directors are personally liable for data breaches. Offline Secure Storage (OSS) provides demonstrable, appropriate technical measures.

Why OSS

We Think This Is Hard to Ignore

94% of breaches target executive-level information, and directors face up to £500,000 in personal liability. At Firevault, we provide the only storage with a physical audit trail that proves data was unreachable by design.

€20M or 4%

Maximum GDPR fine per breach

GDPR Article 83

£500,000

Maximum ICO director personal liability

ICO

94%

Of breaches target executive-level information

Verizon DBIR 2024

£4.7M

Average breach cost when board data is compromised

IBM 2024

What is at Risk

Directors carry more risk than they realise.

Personal Liability

Directors can be personally fined and disqualified for data protection failures.

Inadequate Measures

Cloud-only storage may not satisfy 'appropriate technical measures' under GDPR Article 32.

Board Exposure

Board papers, strategy documents, and governance records are high-value targets.

The Reality

Directors are already paying the price.

Capita: £14M Fine, ICO Held Directors Accountable

The ICO fined Capita £14 million for security failures, explicitly citing inadequate technical measures that directors should have ensured were in place.

ICO, October 2025

LastPass: £1.2M Fine for Failures Unacceptable in a Security Company

The ICO ruled that the company managing the world's passwords failed its users, fining it £1.2 million for inadequate security measures.

ICO, December 2025

Care Home Director: Convicted for Blocking Data Access Request

A care home director in Bridlington was found guilty and fined for refusing to respond to a subject access request, demonstrating personal liability extends beyond breaches.

ICO, September 2025

The Scenario

The ICO letter arrives.

A breach exposed 12,000 customer records. The ICO asks one question: 'What appropriate technical measures did you take?' Your cloud provider's SLA is not enough. But your Firevault audit trail shows physically disconnected storage, authenticated access, and tamper-evident environments.

"The directors who could answer the question kept their careers."

How Firevault Stops This

Create evidence of control the ICO cannot ignore.

Board papers, governance records, and sensitive data are removed from shared drives, email threads, and cloud platforms, and placed on dedicated RAID 1 drives inside a Firevault Bunker. Every access session is identity-verified and logged: who accessed what, when, and for how long. When the session ends, the drives disconnect physically. That audit trail is the answer to 'What appropriate technical measures did you take?' It is not a policy document. It is evidence.

  • Appropriate technical measures, sensitive data is removed from connected systems and placed on hardware with no network connection. This is the strongest measure a director can demonstrate
  • Documented evidence of control, every access session is identity-verified and logged. The ICO does not accept policies. They accept proof that data was protected
  • Board papers removed from shared drives, no longer sitting in email inboxes, collaboration tools, or file shares where a breach exposes them
  • Physical disconnection between sessions, regulatory evidence that data was architecturally unreachable, not just protected by a password

Take Sensitive Data Off Connected Systems

Step 1 of 3

Board papers, governance records, and compliance evidence are removed from shared drives, email threads, and cloud platforms. They are written to dedicated offline drives inside a Firevault Bunker. The data no longer exists on any system an attacker, or a negligent employee, can reach.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Choose Your Protection

Which OSS Fits?

300GB

Low Use Vault, Deep Cold Storage

From £74.99/mo

inc. VAT · £0 due today

Deep cold storage for board minutes, governance documents, and records accessed periodically for audits.

What 300GB holds

~60,000 high-res photos
~150,000 PDF documents
~1,200 hours of voice recordings
~75 hours of HD video

Use Cases for Director Protection

  • Board minutes and meeting records
  • Director correspondence and decisions
  • Governance and compliance policy archives
  • Regulatory submission preparation files
  • Historic audit and investigation records

Specifications

Capacity

300GB

Access

2 windows/week

Authentication

Identity-locked

Commitment

36 months

Security & Compliance

NATO-Approved FacilityDSIT-ReferencedGDPR Art. 32Cyber Essentials Plus

How to Get Started

Step 1

Discovery Call

Understand what you need to protect and how you operate.

Step 2

Vault Configuration

Select your tier, capacity, and access model.

Step 3

Identity Verification

Complete KYC/AML and set up multi-factor authentication.

Step 4

Go Live

Data ingestion, access policy activation, and ongoing support.

OSS Butterfly for the Board

One Vault, every party, every stage of the board cycle.

Offline Secure Storage sits at the centre of the boardroom, owned by the directors personally accountable for governance, conduct and disclosure. Pre-reads and briefings feed the live board file on one set of wings; the governance network and the live committees that run in parallel form the other. Nothing is reachable between sessions, and every touch is logged for auditors, regulators and the directors themselves.

Chair
CEO
CFO
Firevault butterfly mark
Company Secretary
SID
Lead NED
Firevault OSS
disconnect to protect
Upper Left Wing

Board Intake

  • Board papers and pre-reads issued through controlled channels
  • Briefings, management accounts and KPI packs lodged ahead of meetings
  • Conflicts of interest and related-party declarations captured at intake
  • Whistleblowing reports and protected disclosures logged on receipt
  • External counsel opinions and skilled-person reports recorded on file
  • Materiality assessments and disclosure triggers kept with the agenda
Upper Right Wing

Live Board File

  • Minutes, resolutions and written consents
  • Register of decisions and reserved matters
  • Conflicts and related-party register
  • Risk register and principal-risk assessments
  • Cyber, ESG and operational-resilience reports
  • Director duties and section-172 evidence
  • Audit findings and management responses
  • Disclosure log and announcement drafts
Lower Left Wing

Governance Network

  • External auditors and reporting accountants
  • Corporate counsel and litigation lawyers
  • Sector regulators, FCA, PRA and the ICO
  • Cyber insurers and D&O brokers
  • Investor relations, registrars and proxy advisors
Lower Right Wing

Live Committees

  • AuditAUD
  • RiskRSK
  • RemunerationREM
  • NominationNOM
  • DisclosureDIS
Archived DataClosed-year board packs, completed committee cycles and statutory-retention records, held offline under the directors' sole control.

Questions

Frequently Asked

Ready to take the next step?

See how Firevault can protect your most sensitive data with physically disconnected storage.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®