Recent Breaches
Breaches
View All →
OSS for Industry

Offline Secure Storage for Retail

Retail businesses handle millions of customer records, payment details, and loyalty data. Offline Secure Storage (OSS) provides physical disconnection for your most sensitive data.

We Think This Is Hard to Ignore

M&S lost an estimated £300 million in profit after DragonForce ransomware encrypted customer systems that were always online. At Firevault, customer and payment data lives on hardware that physically disconnects between sessions, because connected data is the blast radius.

£300M

Estimated profit loss from M&S DragonForce ransomware

Reuters, 2025

6.5M

Co-op members' personal data stolen in single attack

BBC News, 2025

430K

Harrods customer records stolen in second attack of 2025

BBC News, September 2025

£8.3T

Global cybercrime cost in 2025

Cybersecurity Ventures 2025

Retail Reality

Retailers carry payment card data, loyalty records and millions of customer profiles that PCI-DSS treats as toxic the moment they are stored online longer than necessary. The PCI Security Standards Council recommends archiving cardholder data to media that is physically separated from the operating environment. Firevault provides exactly that separation, sharply reducing the attack surface auditors examine and the volume of data exposed in any single online incident.

Industry Risks

Retail data is a growing target.

Payment Data

Customer payment information is the primary target for retail breaches.

Customer Records

Loyalty programmes and customer profiles contain valuable personal data.

Supply Chain Risk

Third-party integrations create additional attack surfaces.

The Reality

This is already happening in retail.

M&S: DragonForce Ransomware Shut Down Online Operations

Attackers deployed DragonForce ransomware across Marks and Spencer systems, forcing the retailer to suspend online orders for months and costing an estimated £300 million in lost profit.

Reuters, 2025

Co-op: 6.5 Million Members' Data Stolen

Attackers exfiltrated personal data of all 6.5 million Co-op members in a cyber attack the CEO described as devastating. Customer names, contact details, and membership information were all taken.

BBC News, 2025

Harrods: 430,000 Customer Records Stolen in Second Attack

Hackers stole customer data from the luxury retailer via a compromised supplier, the second cyber attack to hit Harrods in the same year.

BBC News, September 2025

How Firevault Stops This

Remove customer data from every system attackers can reach.

Customer records, payment archives, and loyalty data are taken off retail networks and written to dedicated RAID 1 drives inside a Firevault Bunker. Those drives have no internet connection. No IP address. No API. When authorised staff need access, a physical connection is created after identity verification. When the session ends, the drives disconnect.

  • Customer and payment data removed from retail networks and placed on hardware with no network connection. Ransomware cannot encrypt what is not online
  • PCI-DSS compliant storage with identity-verified access. Stolen credentials cannot unlock physically disconnected hardware
  • Scalable from single-site to national multi-store operations with centralised offline protection
  • Supports GDPR, PCI-DSS, and Cyber Essentials through the strongest technical measure, physical disconnection

Take Customer Data Off Retail Networks

Step 1 of 3

Customer records, payment archives, and loyalty data are taken off retail networks and written to physically disconnected RAID 1 drives inside a Firevault Bunker. No cloud. No API. No attack surface.

“Cardholder data should be retained only for as long as needed for legal, regulatory or business purposes, and should be stored using methods that minimise exposure of the data while at rest.”
Source: PCI-DSS v4.0, Requirement 3.2

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Choose Your Protection

Which OSS Fits?

300GB

Low Use Vault, Deep Cold Storage

From £74.99/mo

inc. VAT · £0 due today

Deep cold storage for loyalty programme data and archived customer records accessed periodically.

What 300GB holds

~60,000 high-res photos
~150,000 PDF documents
~1,200 hours of voice recordings
~75 hours of HD video

Use Cases for Retail

  • Loyalty programme historical data
  • Archived customer profiles
  • Legacy supplier contracts
  • Seasonal campaign archives
  • Closed store records

Specifications

Capacity

300GB

Access

2 windows/week

Authentication

Identity-locked

Commitment

36 months

Security & Compliance

NATO-Approved FacilityDSIT-ReferencedGDPR Art. 32Cyber Essentials Plus

How to Get Started

Step 1

Discovery Call

Understand what you need to protect and how you operate.

Step 2

Vault Configuration

Select your tier, capacity, and access model.

Step 3

Identity Verification

Complete KYC/AML and set up multi-factor authentication.

Step 4

Go Live

Data ingestion, access policy activation, and ongoing support.

OSS Butterfly for Retail

One Vault, every channel, every stage of the trading period.

Offline Secure Storage sits at the centre of the retailer, owned by the executive accountable for customer trust, payment integrity and brand reputation. Customer acquisition and sign-up feed the live customer and order file on one set of wings; suppliers, channels and the live trading periods the retailer is running in parallel form the other. Nothing is reachable between sessions, and every touch is logged for PCI DSS, the ICO and the cyber-insurance market.

CEO
COO
CFO
Firevault butterfly mark
CISO
Head of E-commerce
Head of Customer
Firevault OSS
disconnect to protect
Upper Left Wing

Customer Acquisition and Sign-up

  • Web account creation captured into the customer's vault on first sign-up
  • In-store loyalty enrolment lodged with consent receipts attached
  • Marketing opt-in, GDPR lawful-basis and preference centre recorded
  • Age and identity verification evidence stored for restricted lines
  • Click-and-collect and trade-account onboarding handed to the order file
  • Newsletter, app and SMS sign-ups reconciled into one customer record
Upper Right Wing

Customer and Order File

  • Membership and account records
  • Loyalty and rewards balances
  • Order, basket and wishlist history
  • Payment tokens and PCI vault
  • Returns, refunds and chargebacks
  • Complaints and CX correspondence
  • Marketing consent and preferences
  • Address book and delivery records
Lower Left Wing

Suppliers and Channels

  • Payment processors, acquirers and card schemes
  • 3PL, fulfilment and last-mile carriers
  • Marketing, CRM and loyalty partners
  • External auditors and PCI assessors
  • Cyber, credit-risk and product-liability insurers
Lower Right Wing

Live Trading Periods

  • PeakPK
  • Seasonal SaleSLE
  • NPD LaunchNPD
  • ClearanceCLR
  • Business as UsualBAU
Archived DataClosed seasons, completed promotions and long-retention loyalty data, retained offline under the retailer's sole control.

Questions

Frequently Asked

Ready to take the next step?

See how Firevault can protect your most sensitive data with physically disconnected storage.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®