Recent Breaches
Breaches
View All →
OSS for Industry

Offline Secure Storage for Education

Schools, MATs, and universities hold some of the most sensitive personal data in existence, safeguarding records, SEND files, and child protection logs. Offline Secure Storage (OSS) provides physical disconnection for your most vulnerable data.

We Think This Is Hard to Ignore

The NCSC reported 327 cyber incidents targeting UK education in 2024, with ransomware encrypting safeguarding and student records on connected school networks. At Firevault, pupil data lives on hardware that is physically disconnected, because children's records deserve the strongest protection available.

327

Cyber incidents reported by UK schools in 2024

NCSC Annual Review, 2025

£14M

ICO fine to Capita, which processes education data

ICO, October 2025

6.5M

Personal records stolen in single Co-op attack

BBC News, 2025

72hrs

ICO breach notification deadline for pupil data

ICO Guidance

Schools & Education Reality

Schools, colleges and universities now hold safeguarding records, SEND files and family contact details that a single phishing email can put on the dark web. The Department for Education's Cyber Security Standards expect institutions to protect these records, but most settings still rely entirely on cloud backup. Firevault keeps the most sensitive student and staff records offline, so a ransomware incident on the school network cannot become a child-safeguarding breach.

Industry Risks

Education data is uniquely sensitive.

Safeguarding Records

Child protection logs and safeguarding records require the highest standard of confidentiality and protection.

Ransomware Targeting

Education is now the most targeted sector for ransomware, the NCSC has issued multiple alerts.

Regulatory Pressure

Ofsted, ICO, GDPR, and KCSIE mandate robust technical measures for pupil data protection.

The Reality

This is already happening in education.

NCSC: 327 Cyber Incidents Reported by UK Schools in 2024

The National Cyber Security Centre reported a record number of cyber incidents affecting UK schools, with ransomware and data exfiltration the most common attack types targeting pupil records.

NCSC Annual Review, 2025

Capita: £14M Fine Affects Education Data Processing

Capita processes data for hundreds of schools and local authorities. The ICO fined the outsourcer £14 million after hackers accessed personal data of over 6 million people, including education records.

ICO, October 2025

Co-op: Pharmacy and Membership Data of 6.5 Million Stolen

The Co-op attack demonstrated how organisations holding data across multiple sectors, including education partnerships, are vulnerable to mass data exfiltration.

BBC News, 2025

How Firevault Stops This

Remove pupil data from every system attackers can reach.

Safeguarding records, SEND files, and child protection logs are taken off school networks and written to dedicated RAID 1 drives inside a Firevault Bunker. Those drives have no internet connection. No IP address. No API. When authorised staff need access, a physical connection is created after identity verification. When the session ends, the drives disconnect.

  • Safeguarding data removed from school networks and placed on hardware with no network connection. Ransomware cannot encrypt what is not online
  • SEND records isolated with identity-verified access. Stolen staff credentials cannot unlock physically disconnected hardware
  • Full audit trail for Ofsted, ICO, KCSIE, and GDPR compliance. Every access session is logged and attributable
  • Scalable from single schools to multi-academy trusts with centralised offline protection

Take Pupil Data Off School Networks

Step 1 of 3

Safeguarding records, SEND files, and child protection logs are taken off school networks and written to physically disconnected RAID 1 drives inside a Firevault Bunker. No cloud. No shared drive. No attack surface.

“Schools and colleges should hold backup copies of essential data on devices that are not permanently connected to the live network so that ransomware cannot encrypt them.”
Source: DfE Cyber Security Standards for Schools and Colleges, 2023

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Choose Your Protection

Which OSS Fits?

300GB

Low Use Vault, Deep Cold Storage

From £74.99/mo

inc. VAT · £0 due today

Built for sensitive records that should not sit exposed on always-connected systems. Deep cold storage with scheduled access windows.

What 300GB holds

~60,000 high-res photos
~150,000 PDF documents
~1,200 hours of voice recordings
~75 hours of HD video

Use Cases for Education

  • Safeguarding and child protection files
  • SEND and pupil support records
  • HR and disciplinary records
  • Governance, legal and incident files
  • Archived complaints and case materials

Specifications

Capacity

300GB

Access

2 windows/week

Authentication

Identity-locked

Commitment

36 months

Security & Compliance

NATO-Approved FacilityDSIT-ReferencedGDPR Art. 32Cyber Essentials Plus

How to Get Started

Step 1

Discovery Call

Understand what you need to protect and how you operate.

Step 2

Vault Configuration

Select your tier, capacity, and access model.

Step 3

Identity Verification

Complete KYC/AML and set up multi-factor authentication.

Step 4

Go Live

Data ingestion, access policy activation, and ongoing support.

OSS Butterfly for Education

One Vault, every safeguard, every stage of the cohort.

Offline Secure Storage sits at the centre of the school or multi-academy trust, owned by the Head Teacher, the Trust CEO and the Designated Safeguarding Lead. Admissions and safeguarding intake feed the live pupil record on one set of wings; the statutory and safeguarding network and the live cohorts the school is teaching in parallel form the other. Nothing is reachable between sessions, and every touch is logged to KCSIE and DfE standard.

Head Teacher
Trust CEO
DSL
Firevault butterfly mark
DPO
SENDCo
Bursar
Firevault OSS
disconnect to protect
Upper Left Wing

Admissions and Safeguarding Intake

  • Admissions applications and in-year transfers captured at the gate
  • DSL referrals and CPOMS entries lodged on the day of disclosure
  • Children Missing Education and CIN notifications recorded in
  • EHCP applications and SEND assessments staged for the local authority
  • Looked-after and previously looked-after status flagged at intake
  • Free-school-meal and pupil-premium evidence captured at enrolment
Upper Right Wing

Pupil Record

  • CPOMS and safeguarding chronologies
  • SEND and EHCP plans
  • Attendance, exclusion and behaviour data
  • Assessment and progress records
  • Free-school-meal and pupil-premium status
  • Looked-after and previously looked-after flags
  • Photographs and biometric records
  • Medical notes and care plans
Lower Left Wing

Statutory and Safeguarding Network

  • Local authority and MASH safeguarding teams
  • Ofsted inspectors and ESFA
  • Children's social care and youth offending
  • CAMHS and school health services
  • Examination boards and awarding bodies
Lower Right Wing

Live Cohorts

  • ReceptionEYFS
  • Key Stage 1KS1
  • Key Stage 2KS2
  • Key Stage 3KS3
  • Sixth FormKS5
Archived DataLeaver records, historical cohorts and long-retention safeguarding files, held offline under the trust's sole control.

Questions

Frequently Asked

Ready to take the next step?

See how Firevault can protect your most sensitive data with physically disconnected storage.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®