Guides·29 July 2026

Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
13 min read
Share
School records room at dusk with metal filing cabinets, an open drawer of paper student files and a laptop on a desk, representing offline protection of education data
Guides

Article record

GuidesCategory
29 July 2026Published
13 min readReading time
Mark FermorWritten by
School records room at dusk with metal filing cabinets, an open drawer of paper student files and a laptop on a desk, representing offline protection of education data

Why it matters

What this means for organisations holding critical data

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

A practical briefing to help you protect your students, peers and partners going forward, written for headteachers, trust leaders, governors, data protection officers, IT leads, university registrars and research administrators.

Mark Fermor · Director and Co-Founder, Firevault

The Department for Education breach, disclosed in late July 2026, exposed more than 607,000 records. Names, email addresses, telephone numbers and job titles were taken from two public-facing systems. The department is now working with the National Cyber Security Centre and the National Crime Agency.

That incident is a warning, not just a headline. The institutions that feed data into central systems now need to ask a practical question: are the students, staff and partners in our care protected going forward? Education holds some of the most sensitive personal data in the country. Safeguarding notes, social care referrals, EHCPs, SEND plans, medical conditions, immigration status, adoption arrangements, court orders, protected addresses and photographs of children cannot simply be reissued like a bank card. A child cannot be given a new childhood.

This briefing is not written for a data centre. It is written for the people who keep an education institution running day to day: the school office, the college leadership team, the university registry. It focuses on what you can do now, and next term, to protect the students, peers and partners who rely on you.

What this means for your students, peers and partners

The DfE breach was a failure outside the school gate. It is a reminder that data handed to central systems, third-party platforms and shared services remains exposed. The protection each institution needs looks different depending on who you serve.

Schools and academies

Your students are children. The data you hold is some of the most emotionally sensitive in the country: child protection logs, SEND plans, EHCPs, family contact details, medical information and photographs. A single compromised staff account or supplier breach can expose all of it.

The immediate risk is not only an Information Commissioner's Office fine. It is broken trust with parents, intervention from the local authority, and governors explaining why files that should never have left the building are now elsewhere. For multi-academy trusts, scale makes the problem worse. Centralise data across several academies and one breach can affect thousands of pupils. Trust leaders need segmented access, a tested incident plan, and an offline copy of irreplaceable records that no central system can reach.

Going forward: protect your students by separating safeguarding data from everyday drives, controlling who can retrieve it, and keeping an offline gold copy that ransomware cannot touch.

Sixth-form and further education colleges

Colleges sit between schools and universities. They hold young-adult learner records, employer and apprenticeship data, exam-board entries, bursary and financial details, and many of the same safeguarding duties because students under eighteen are still present. Their workforce is also more fluid: part-time staff, agency tutors and subcontractors move between sites.

Ties to central funding and tracking systems are why this breach matters to colleges. If a central portal can be breached, the suppliers beneath it can be too. Check that apprenticeship data, exam entries and learner records are not sitting in one shared drive with no segregation, and that ransomware would not wipe out the records exam boards, auditors and the Education and Skills Funding Agency expect to see.

Going forward: protect your peers and partners by segmenting access, clearing inherited logins, and rehearsing the first two hours of an incident.

Universities and higher education

Universities hold everything a school holds, plus the assets that generate institutional value: unpublished research, doctoral work, patent applications, grant files, commercial partnerships and intellectual property. A ransomware attack can halt research, freeze admissions, and anger funders, alumni and partners at once.

Government-held data is only one part of the picture. Universities share large datasets with research councils, funding agencies and international partners. The attack surface is wider and the users more dispersed. Separate research IP from general storage, keep a gold copy of critical datasets offline, and make sure the credentials protecting a grant file are not the same ones that open a staff email account.

Going forward: protect your partners by isolating research IP, controlling supplier access and making sure your most valuable datasets are not only in the cloud.

Priority actions: protect your students, peers and partners this term

  1. Put phishing-resistant multi-factor authentication on every staff account. Start with accounts that can reset others: senior leadership, the business manager, the data protection officer, and anyone with admin rights in your management information system.
  2. Separate safeguarding from everyday systems. Those files should never sit in a drive any teacher can browse, or be reachable from a general staff login.
  3. Take an offline copy of what you could never rebuild. Safeguarding files, SEND plans and reviews, admissions history and governance papers belong in an offline vault that an intruder on your network cannot reach.
  4. Interrogate your suppliers. Management information systems, cashless catering, parent apps, learning platforms, coach hire, photography. Ask each where the data lives, how long it is kept, and what happens when the contract ends.
  5. Clear out the places data was never meant to be. Personal email, unmanaged memory sticks, staff home laptops, forgotten machines in a cupboard, and legacy drives from systems you replaced years ago.
  6. Rehearse the first two hours. Who is called, who speaks to parents, who notifies the Information Commissioner's Office within seventy-two hours, and who can run the place on paper.

This has already happened, repeatedly

Department for Education, England, 2026

More than 607,000 records containing names, email addresses, telephone numbers and job titles were taken across two public-facing systems. The department is working with the National Cyber Security Centre and the National Crime Agency. (BBC News; The Times.)

PowerSchool, 2024 to 2025

A compromise of the PowerSchool student information system exposed data on millions of pupils and teachers across the United States and Canada, including names, addresses, dates of birth and, in some districts, medical and social security details. Paying the extortion demand did not stop districts being threatened directly afterwards. One supplier became a single point of failure for thousands of schools. (BleepingComputer.)

Vice Society and UK schools, 2022 to 2023

When ransoms were refused, files stolen from a series of English schools were published: SEND records, scans of children's passports, safeguarding information and staff contracts. (BBC News.)

Los Angeles Unified School District, 2022

Roughly 500 gigabytes from the second-largest district in the United States was published after it declined to pay. Psychological assessments of pupils were among the released files. (BBC News.)

Minneapolis Public Schools, 2023

The Medusa group released a very large archive of district files, including detailed case material on individual pupils. (The Record.)

The threat from inside the building

The Information Commissioner's Office has warned that many education incidents start with pupils and students. The motive is usually curiosity or status rather than money, and the way in is usually a weak or shared password. (BBC News.)

Where education estates come unstuck

Shared and inherited logins. Cover teachers, trainees, peripatetic staff, site teams, agency workers and postgraduate researchers all drift onto shared accounts. Each one erases the audit trail your data protection officer will need on the worst day. Issue individual accounts, and switch them off the day someone leaves.

One login that opens everything. In many institutions a single compromised account reaches the management information system, the shared drive, the photograph archive and the safeguarding folder. Segment by role, and give safeguarding its own approval step.

Backups beside the thing they protect. A backup on the same network, behind the same password, is not a backup. Ransomware hunts online backups first. This is the usual reason an institution loses years of records rather than a weekend of work.

Retention drift. Education rarely deletes anything. Former pupils, alumni, applicants who never enrolled, staff who left a decade ago: all still sitting in systems nobody patches. A record you no longer hold is a record nobody can steal.

Photographs and biometrics. Photography, fingerprint catering and facial recognition all create identifiable data about children. The Information Commissioner's Office has already reprimanded schools for facial recognition deployed without a lawful basis or an impact assessment. Ask whether the convenience justifies the record you are creating.

What good looks like

  • Individual accounts, phishing-resistant multi-factor authentication, and a leaver check every term.
  • Role-based access, with safeguarding held separately and every retrieval logged.
  • A retention schedule that is genuinely followed, legacy systems included.
  • A gold copy of irreplaceable records held offline and physically disconnected at the hardware level.
  • Supplier due diligence in a register, with processing agreements and exit terms written down.
  • An incident plan that assumes the network is gone, rehearsed annually with governors.

Why offline storage matters for protecting students, peers and partners

Almost every control in an education institution is a logical one. Passwords, permissions, firewall rules and cloud policies are instructions given to a connected system, and an attacker already inside that system can rewrite them.

Offline Secure Storage® removes the connection itself. Records in a Firevault vault sit on hardware that is physically disconnected at Layer 1 when not in use, hardware-encrypted and locked to named individuals. Someone can hold your entire online estate and still be unable to read, alter, encrypt or delete what is not attached to it. For safeguarding and SEND files, that can be the difference between an incident and a catastrophe. Disconnect to Protect®, the principle is a physical break, not another logical rule.

When you protect a safeguarding file this way, you are protecting the student behind it. When you protect research IP this way, you are protecting the peers and partners who funded and collaborated on it.

The pressure is not only regulatory

Schools and colleges may not face the financial penalties a commercial business would. That is cold comfort. Local press coverage and governance fallout are just as hard to live with, and a breach involving safeguarding or SEND data can dominate a governing body meeting for months, or invite intervention from the local authority or the Education and Skills Funding Agency.

The Department for Education is not only about schools. Sixth-form colleges, further education colleges and universities sit within its wider responsibilities and carry extra risk: research data, grant-funded intellectual property, commercial partnerships, large cohorts of young adults, and apprenticeship and employer records.

That intellectual property deserves its own line. Unpublished findings, patent applications, partnership agreements and doctoral work are not simply personal data. Losing them is a direct loss of institutional value and years of work nobody can recreate.

Reporting an incident

A personal data breach that poses a risk to individuals must reach the Information Commissioner's Office within seventy-two hours of you becoming aware of it, and where the risk is high, the individuals themselves must be told. Serious incidents should also go to the National Cyber Security Centre and Action Fraud. Log every breach, including those you decide not to report, with your reasoning.

Choosing the right Offline Secure Storage size

Most institutions overthink the technology and underthink the capacity. The right size follows from the records you could never rebuild, not the total size of your network.

What to count

Add up what you could not recreate if your online systems were encrypted or deleted tomorrow:

  • Safeguarding and child protection. Case notes, chronologies, referrals, strategy minutes and supporting evidence.
  • SEND. EHCPs and SEND plans, annual reviews, specialist reports, provision maps and medical plans.
  • Admissions and census history. Registers, attendance, leavers information and alumni files.
  • Photographs and media. Only the archival set you are obliged to keep, though whole-school photography is often the largest file set you own.
  • Governance and legal. Trust deeds, minutes, land and building documents, insurance claims, tribunal files and settlements.
  • Finance and payroll. Historical payroll, pension data, audit trails and accounts.
  • Research and IP. Unpublished research, patent applications, grant files and partnership data.

A rough sense of scale

A maintained primary school usually lands between 50 GB and 150 GB. A large secondary, sixth-form college or multi-academy trust is more often 500 GB to 2 TB once photography and media are included. Independent schools, universities and long retention histories can run larger again.

Capacity is not the deciding factor. The question is whether the storage carries the access control and audit model safeguarding data demands. Start at Vault rather than LUV, because Vault provides the identity verification, named-user control and session logging those records require.

To estimate quickly: size the folders you would want back first, multiply by three for version history and growth, then take the tier above that number.

Mapping to an OSS tier

  • Schools, academies and sixth-form colleges. A Vault plan is the starting point, with 2 TB, 4 TB and 8 TB options covering most institutions. Choose room to grow rather than a tier that fits today exactly.
  • Trusts, local authorities and university departments. Firevault Storage, from 8 TB to 300 TB, suits consolidated estates across several sites, or research and media archives.
  • Above 300 TB. Enterprise provides physically isolated, bespoke deployments for central archives, large media libraries or multiple campuses.

How many seats?

Every Firevault user is identity-verified and tied to a named individual. We agree the seat count and the holders with you during onboarding, and the decision is yours. The principle is not to give everybody access, but to give it to the people who can authorise a retrieval and stand behind the audit trail.

In practice that often means the headteacher, the data protection officer, the business manager, the designated safeguarding lead, the SENCO, the IT lead and the chair of governors. A university might add the registrar, a research data manager and a faculty contact; a trust might add its own data protection officer and a nominated person from each academy.

When in doubt, start smaller

Offline Secure Storage is a hedge, not a migration project. Start with safeguarding and SEND, the material that cannot be reissued. Once the process is proven, add admissions, photography, governance and research files. The aim is to break the single point of failure, not to mirror your network.

If the budget is tight

Funding is a common obstacle, and there are ways round it. Institutions have paid for this through the parent-teacher association, a governor sub-committee or a research integrity fund. The cost is a known annual line rather than a per-user licence that grows every September. Present it as a discrete resilience project: the gold copy of safeguarding records, SEND files and governance papers, kept in a physical vault that ransomware cannot reach. One fundraising evening can cover it.

If you would like a walkthrough of how Offline Secure Storage would apply to your school, college, university or trust, speak to a member of the team.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Guides29 July 202613 min read

Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

Protecting Students, Peers and Partners: A Practical Education Data Briefing
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy