---
title: "Employment Documentation Is a Breach Readiness… | Firevault"
url: https://fire-vault.com/news/employment-documentation-breach-readiness
description: "Breach readiness does not start with the alert. It starts in the employment contract, the staff handbook and the policies that tell people what they are…"
lang: en-GB
---

Insight · 4 July 2026

# Employment Documentation Is a Breach Readiness Control

Breach readiness does not start with the alert. It starts in the employment contract, the staff handbook and the policies that tell people what they are responsible for. Mark Fermor on why vague duties become the firm's problem.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Femployment-documentation-breach-readiness
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Femployment-documentation-breach-readiness&text=Employment%20Documentation%20Is%20a%20Breach%20Readiness%20Control%0A%0ABreach%20readiness%20does%20not%20start%20with%20the%20alert.%20It%20starts%20in%20the%20employment%20contract%2C%20the%20staff%20handbook%20and%20the%20policies%20that%20tell%20people%20what%20they%20are%20responsible%20for.%20Mark%20Fermor%20on%20why%20vague%20duties%20become%20the%20firm%27s%20problem.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Femployment-documentation-breach-readiness

Image: Stack of employment documents on a desk with a vault motif glowing in the background (https://fire-vault.com/__l5e/assets-v1/e059ee4b-c9e6-43dc-8d50-9d3373b0e26d/news-employment-documentation-hero-2x.jpg)

Stack of employment documents on a desk with a vault motif glowing in the background

Why it matters

## What this means for organisations holding critical data

Breach response is often treated as something that starts after an incident. In practice, part of breach readiness starts much earlier. It starts with whether people understand their responsibilities before anything goes wrong.

## Breach readiness starts before the breach

Most organisations treat breach response as something that begins when the alert fires. The plan sits with security. The playbook sits with legal. The retainer sits with an incident response firm. All of that matters. None of it addresses the months before the alert, when the people inside the business are quietly deciding, day by day, how carefully to handle information they were never explicitly told to protect.

If the documents that govern that behaviour are vague, the response will be vague too.

## What the paperwork should actually say

Employment contracts, staff handbooks and internal policies should make it explicit how employees are expected to handle confidential information, how to report suspected incidents, which systems are approved for what work, and how to protect business data day to day.

Not a single clause buried on page forty. Named systems. Named data categories. Named reporting routes. Named consequences. A member of staff should be able to read the relevant section and understand, without a lawyer beside them, what they are allowed to do and what they are not.

## Why this matters most in professional services

Legal, accountancy, wealth management, consultancy and advisory firms sit on client files, financial records, legal documents, identity data and commercially sensitive material every day. The person opening those files at nine in the morning is often the same person the regulator asks about at the enquiry.

When duties are vague, the firm carries the consequence. The regulator does not accept "we assumed they knew" as a control. Neither does a client whose confidential matter has ended up somewhere it should not.

## Policies do not replace technical controls

To be clear, a handbook clause is not a substitute for security engineering. Physical severance, offline storage and role-based access controls limit what can be reached in the first place. That is the ceiling on the damage.

Documentation limits what people are permitted to do with what they can reach, and creates the accountability trail when something goes wrong. One without the other is half a control. Technical controls without documented duties leave you unable to attribute anything after the fact. Documented duties without technical controls leave the duties unenforceable.

## The Firevault position

If a person has access to the crown jewels, their duties should not be vague.

The archival copy of client data, matter files, financial records and identity information should live on infrastructure that most staff cannot reach at all. The small number of people who can should have named, documented, auditable responsibilities for handling it. Firebreak enforces the technical severance at the network layer. The handbook enforces the human one on the desk. Both are required, and neither is optional in a professional services setting.

Mark Fermor, co-founder of Firevault, puts it plainly. The firms that recover well from an incident are the ones that already knew, on paper, exactly who was responsible for what. The firms that struggle are the ones still working out the answer in the middle of the fire.

## What to review this quarter

- Check that the employment contract references confidential information handling in specific terms, not generic boilerplate.
- Check that the staff handbook names the approved systems and the incident reporting route, and that both are current.
- Check that access to the most sensitive archives is limited by role and documented per named individual.
- Check that leavers are removed from those systems the same day their notice ends, and that this is logged.
- Rehearse an incident where the first question is "who had access to this data on this date" and see how long the answer takes.

If any of those checks take more than a few minutes to satisfy, the paperwork is doing less work than it should be. Fix that before you need it.

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Custody**Named, access-controlled hardware in a Firevault Bunker

**Evidence**Access windows and retrieval events are recorded

**Separation**Physical isolation that satisfies offline copy requirements

**Jurisdiction**Stored where your regulatory position requires

Related Reading

## You may also find these useful

Insight

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. New research shows no hacking was required: server-side marketing API keys sat in the public JavaScript of all three airport websites, unrotated, for more than four years.

27 Aug 2026 8 min
https://fire-vault.com/news/manchester-airports-group-data-breach-87-million-customers-2026

Insight

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min
https://fire-vault.com/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026

Insight

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min
https://fire-vault.com/news/beacon-charity-database-breach-hiv-charity-health-data-2026

Insight

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min
https://fire-vault.com/news/iran-linked-hackers-uk-power-plant-shutdown-2026

Insight

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min
https://fire-vault.com/news/gta-6-leaks-rockstar-development-footage-2026

Insight

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min
https://fire-vault.com/news/nine-pbs-archives-cloud-vendor-shutdown-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/employment-documentation-breach-readiness#webpage",
    "url": "https://fire-vault.com/news/employment-documentation-breach-readiness",
    "name": "Employment Documentation Is a Breach Readiness…",
    "description": "Breach readiness does not start with the alert. It starts in the employment contract, the staff handbook and the policies that tell people what they are…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/e059ee4b-c9e6-43dc-8d50-9d3373b0e26d/news-employment-documentation-hero-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/employment-documentation-breach-readiness#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/employment-documentation-breach-readiness#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Employment Documentation Is a Breach Readiness Control",
        "item": "https://fire-vault.com/news/employment-documentation-breach-readiness"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Employment Documentation Is a Breach Readiness Control",
    "description": "Breach readiness does not start with the alert. It starts in the employment contract, the staff handbook and the policies that tell people what they are responsible for. Mark Fermor on why vague duties become the firm's problem.",
    "url": "https://fire-vault.com/news/employment-documentation-breach-readiness",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/e059ee4b-c9e6-43dc-8d50-9d3373b0e26d/news-employment-documentation-hero-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/e059ee4b-c9e6-43dc-8d50-9d3373b0e26d/news-employment-documentation-hero-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/e059ee4b-c9e6-43dc-8d50-9d3373b0e26d/news-employment-documentation-hero-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/e059ee4b-c9e6-43dc-8d50-9d3373b0e26d/news-employment-documentation-hero-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-07-04T12:30:00+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/employment-documentation-breach-readiness"
    },
    "inLanguage": "en-GB",
    "articleSection": "Insight",
    "wordCount": 675,
    "keywords": "Employment, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "Breach response is often treated as something that starts after an incident. In practice, part of breach readiness starts much earlier. It starts with whether people understand their responsibilities before anything goes wrong. ## Breach readiness starts before the breach Most organisations treat breach response as something that begins when the alert fires. The plan sits with security. The playbo",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "Does a staff handbook clause count as a security control?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Not on its own. Documentation supports accountability and makes duties clear, but it does not stop unauthorised access. It sits alongside technical controls such as role-based access, offline storage and physical severance. Together they form the control. Separately, each is only half of one."
        }
      },
      {
        "@type": "Question",
        "name": "Which employees need the strictest documentation?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Anyone who can reach client files, financial records, identity data, legal documents or commercially sensitive material. In professional services that is most of the fee-earning workforce and much of the support function. Their contracts, handbook and internal policies should name the systems, the data categories and the reporting routes explicitly."
        }
      },
      {
        "@type": "Question",
        "name": "How does Firevault relate to employment documentation?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Firevault provides the technical severance that limits what any individual, compromised account or intruder can reach. Firebreak isolates operational and archival environments at the physical layer. Offline Secure Storage holds the archival gold copy beyond reach of the live network. Employment documentation then governs how the small number of authorised people handle those archives. The two together are the control."
        }
      }
    ]
  }
]
```