---
title: "Offline by Default: UK 2025 Breaches Survey | Firevault"
description: "The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders#webpage",
      "url": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders",
      "name": "Offline by Default: UK 2025 Breaches Survey",
      "description": "The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Offline by Default: UK 2025 Breaches Survey",
          "item": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Offline by Default: UK 2025 Breaches Survey",
      "description": "The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses…",
      "url": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2025-11-07T08:32:21+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/offline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders"
      },
      "inLanguage": "en-GB",
      "articleSection": "Opinion",
      "wordCount": 706,
      "keywords": "Offline, Opinion, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses (43%) and three in ten charities (30%) identified a breach or attack in the last 12 months. That equates to about 612,000 UK businesses and 61,000 charities being hit in a single year. That headline hides three problems that leaders cannot i",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Knowledge Vault](/learn/knowledge)/ [Opinion](/learn/knowledge?filter=opinion)

Opinion · 7 November 2025 

# Offline by Default: UK 2025 Breaches Survey

The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses…

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Foffline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Foffline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders&text=Offline%20by%20Default%3A%20UK%202025%20Breaches%20Survey%0A%0AThe%20UK%20Government%E2%80%99s%20Cyber%20Security%20Breaches%20Survey%202025%20is%20a%20useful%20reality%20check%20for%20anyone%20responsible%20for%20risk%2C%20data%2C%20or%20continuity.%20Four%20in%20ten%20businesses%E2%80%A6)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Foffline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders)[](mailto:?subject=Offline%20by%20Default%3A%20UK%202025%20Breaches%20Survey&body=The%20UK%20Government%E2%80%99s%20Cyber%20Security%20Breaches%20Survey%202025%20is%20a%20useful%20reality%20check%20for%20anyone%20responsible%20for%20risk%2C%20data%2C%20or%20continuity.%20Four%20in%20ten%20businesses%E2%80%A6%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Foffline-by-default-what-the-uks-2025-breaches-survey-really-means-for-leaders)

![A printed government survey report on a polished desk with soft directional lighting](/__l5e/assets-v1/148183a0-5cd6-459e-9752-5b6c6b5c5d3f/offline-by-default-breaches-survey-1771248019056-2x.jpg)

A printed government survey report on a polished desk with soft directional lighting

Why it matters

## What this means for organisations holding critical data

The UK Government’s Cyber Security Breaches Survey 2025 is a useful reality check for anyone responsible for risk, data, or continuity. Four in ten businesses…

In this analysis

**On this page**

The UK Government’s **[Cyber Security Breaches Survey 2025](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025#summary)** is a useful reality check for anyone responsible for risk, data, or continuity.

**Four in ten businesses (43%) and three in ten charities (30%)** identified a breach or attack in the last 12 months. That equates to about **612,000 UK businesses** and **61,000 charities** being hit in a single year.

That headline hides three problems that leaders cannot ignore:

### 1) Exposure is constant, even when the numbers look “better”

Prevalence fell from 50% in 2024 to 43% in 2025, largely because fewer micro and small firms spotted phishing. Medium and large organisations remain heavily targeted at **67%** and **74%** respectively. So risk has not gone away. It has concentrated where the impact is largest.

### 2) Controls are uneven and leave gaps attackers can exploit

Basic measures like malware protection, firewalls and backups are common, but adoption of stronger gates is still too low. Only **40%** of businesses use any form of two-factor authentication, **31%** use a VPN for remote staff, and **30%** monitor user activity.

### 3) Supply chains remain a blind spot

Only **14%** of businesses review cyber risks in their **immediate suppliers**, and just **7%** look at the **wider supply chain**. Even among large firms, only a quarter review wider supply chains. This is the same fault line attackers abused repeatedly in 2024–25.

### Governance trend to watch

Board responsibility for cyber is **27%** across all businesses, rising to **66%** in large firms. That still leaves most companies without explicit senior ownership of cyber risk, which slows decision-making when incidents hit.

### What “offline by default” changes

Most organisations accept permanent connectivity, then try to detect and recover fast enough. The survey shows where that breaks down: ransomware pressure, supplier weaknesses, and disruption even when “little” is taken.

**Offline by default** flips the equation. If your crown-jewel data is physically disconnected and identity-locked when not in use:

-   Ransomware cannot reach or encrypt the master copy.
-   Supplier outages and cloud incidents do not take your anchor data down.
-   Insider mistakes have a smaller blast radius because the source of truth is offline.

You still use online tools, but your most valuable assets live elsewhere: **physically isolated** until you choose to connect.

### A five-step plan for boards

1.  **Classify what must never be online.** Board packs, contracts, customer PII, IP, seed files, keys. Decide that these live offline by default.
2.  **Adopt 3-2-1-0.** Three copies, two media, one off-site, and **zero** permanent online exposure for the master.
3.  **Make “offline %” a KPI.** Track the share of sensitive files stored offline by default. Report it quarterly like any other risk metric.
4.  **Hard-gate access.** Enforce MFA, least privilege and time-boxed sessions when you bring data online for use. Return it offline when finished. The survey shows MFA is still under-used. Close that gap.
5.  **Fix the supply-chain weakness.** Require offline custody for partners that touch your crown-jewel data. Build it into contracts and due diligence. The current rates of supplier review are not enough.

### How Firevault implements offline by default

**Firevault** is a **secured offline data storage platform** built around three pillars:

-   **Controlled Connectivity**, you decide when systems connect.
-   **Secured Offline Access**, identity-locked access with strong MFA, short windows, full audit.
-   **Secured Offline Data**, files are physically disconnected when idle.

Our [**Vault**](/vault) is likened to a **[digital safe deposit box](/vault)** for directors, investors, legal teams, creators and anyone who cannot afford a leak or lockout. Access is intentional and brief. When work is done, assets go back offline.

For teams and enterprises, [**Storage**](/storage) and our platform modules support offline custody for regulated datasets, board information, and recovery anchors, so you can keep operations moving even when suppliers or clouds fail.

### The takeaway

The Breaches Survey shows some progress on hygiene, but it also shows persistent exposure, weak supply-chain oversight and patchy adoption of stronger controls. Do not accept permanent risk as the price of doing business. **Reduce exposure first.** Detect and respond second.

**Read the full UK Government report** to review the data for yourself.

If you want a practical roadmap to go offline by default for your most valuable data, speak with the [Firevault](/) team. We will help you decide what to take offline first and show how to keep it accessible on your terms

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Zero-Copy Cloud is Not the End of Lock-In. It is the Start of a New One](/__l5e/assets-v1/13d1c397-693e-44a7-b9e6-67b730df160d/zero-copy-cloud-lock-in-2026-2x.jpg)

Opinion 

### Zero-Copy Cloud is Not the End of Lock-In. It is the Start of a New One

SAP and Google Cloud have made data migration quietly optional. The data stays put. The operating judgment built above it does not. That is the lock-in the architecture diagram will never show.

29 Jul 2026 4 min 







](/news/zero-copy-cloud-lock-in-opinion-2026)[

![World Backup Day 2026: Backups Are Not Enough](/__l5e/assets-v1/d7a77b5b-74d6-4c42-88b9-4e64057bbe9f/world-backup-day-2026-2x.jpg)

Opinion 

### World Backup Day 2026: Backups Are Not Enough

Every 31 March, World Backup Day reminds organisations to protect their data. But in 2026, the real question is not whether you back up. It is whether your backups can survive the attack that is coming for them.

31 Mar 2026 5 min 







](/news/world-backup-day-2026-why-backups-alone-are-not-enough)[

![NCSC Annual Review 2025: A Call for Leadership](/__l5e/assets-v1/a036e289-1fb4-404b-b8fb-b5ea65e55ef5/ncsc-annual-review-2025-1771248020862-2x.jpg)

Opinion 

### NCSC Annual Review 2025: A Call for Leadership

Stop talking about prevention. Start building resilience. The National Cyber Security Centre (NCSC) Annual Review 2025 doesn’t read like a report, it reads…

7 Nov 2025 5 min 







](/news/ncsc-annual-review-2025)[

![Retail Exposure Crisis: Policy Pressure and Breach Wave](/__l5e/assets-v1/2b8767ec-6dad-4df5-86ba-14ee23170188/retail-exposure-crisis-1771248346427-2x.jpg)

Opinion 

### Retail Exposure Crisis: Policy Pressure and Breach Wave

2025: When Cybersecurity Became a Political Issue Parliament is asking a blunt question: “Why are UK retailers still leaking customer data?” Major breaches…

23 May 2025 3 min 







](/news/retails-exposure-crisis-policy-pressure-political-fallout-and-the-breach-wave-only-firevault-can-halt)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)