---
title: "How 4.1TB of breached data cost South Staffords… | Firevault"
description: "The ICO has fined South Staffordshire Water £963,900 after a phishing email went undetected for 20 months, leading to 4.1 TB of personal data appearing on the…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026#webpage",
      "url": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026",
      "name": "How 4.1TB of breached data cost South Staffords…",
      "description": "The ICO has fined South Staffordshire Water £963,900 after a phishing email went undetected for 20 months, leading to 4.1 TB of personal data appearing on the…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/south-staffordshire-water-ico-fine-963900-data-breach-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "How 4.1TB of breached data cost South Staffordshire Water £963,900",
          "item": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "How 4.1TB of breached data cost South Staffordshire Water £963,900",
      "description": "The ICO has fined South Staffordshire Water £963,900 after a phishing email went undetected for 20 months, leading to 4.1 TB of personal data appearing on the dark web. Why physical disconnection breaks this chain.",
      "url": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/south-staffordshire-water-ico-fine-963900-data-breach-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/south-staffordshire-water-ico-fine-963900-data-breach-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/south-staffordshire-water-ico-fine-963900-data-breach-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/south-staffordshire-water-ico-fine-963900-data-breach-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-05-11T09:00:00+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Cyber Attack",
      "wordCount": 1524,
      "keywords": "Cyber Attack, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "The Information Commissioner's Office has fined South Staffordshire Plc and South Staffordshire Water Plc a combined £963,900 after a cyber attack exposed the personal information of 633,887 customers and employees on the dark web. The case is one of the clearest recent examples of why a connected, software defended estate is not enough to protect regulated personal data, and why an offline copy o",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Could Offline Secure Storage have prevented the South Staffordshire Water breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Offline Secure Storage would not have stopped the phishing email itself, but it would have removed the data of record from the attacker's reach. A vault with no network interface present in its default state cannot be scanned, pivoted into or exfiltrated from a compromised workstation, regardless of how long the attacker dwells inside the connected estate. The 4.1 terabytes that ended up on the dark web could not have been pulled from a physically disconnected vault."
          }
        },
        {
          "@type": "Question",
          "name": "What is the ICO's expectation for critical national infrastructure operators?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The ICO's position, set out by Ian Hulme on 11 May 2026, is that proactive security is a legal requirement and not an optional extra. Operators handling large volumes of personal information are expected to apply established controls including least privilege access, comprehensive logging and monitoring, supported and patched software, and regular internal and external vulnerability scanning. Critical national infrastructure operators are held to that standard explicitly."
          }
        },
        {
          "@type": "Question",
          "name": "How does physical disconnection differ from an air-gapped backup?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Many systems described as air gapped still have a network interface that is logically disabled or segmented. Logical controls can be misconfigured, overridden or exploited. Firevault uses physical disconnection at Layer 1, meaning the network capability is absent rather than switched off. Connection only exists when a verified user, who has cleared KYC, AML and multi factor authentication, deliberately initiates it."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

How the breach unfoldedWho was affectedWhat the ICO foundWhere Offline Secure Storage cha…Mapping to the regulatory expect…What CNI operators should do nowThe Firevault positionMore Resources

[Knowledge Vault](/learn/knowledge)/ [Insight](/learn/knowledge?filter=insight)

Insight · Cyber Attack · 11 May 2026 

# How 4.1TB of breached data cost South Staffordshire Water £963,900

The ICO has fined South Staffordshire Water £963,900 after a phishing email went undetected for 20 months, leading to 4.1 TB of personal data appearing on the dark web. Why physical disconnection breaks this chain.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

8 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-staffordshire-water-ico-fine-963900-data-breach-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-staffordshire-water-ico-fine-963900-data-breach-2026&text=How%204.1TB%20of%20breached%20data%20cost%20South%20Staffordshire%20Water%20%C2%A3963%2C900%0A%0AThe%20ICO%20has%20fined%20South%20Staffordshire%20Water%20%C2%A3963%2C900%20after%20a%20phishing%20email%20went%20undetected%20for%2020%20months%2C%20leading%20to%204.1%20TB%20of%20personal%20data%20appearing%20on%20the%20dark%20web.%20Why%20physical%20disconnection%20breaks%20this%20chain.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-staffordshire-water-ico-fine-963900-data-breach-2026)[](mailto:?subject=How%204.1TB%20of%20breached%20data%20cost%20South%20Staffordshire%20Water%20%C2%A3963%2C900&body=The%20ICO%20has%20fined%20South%20Staffordshire%20Water%20%C2%A3963%2C900%20after%20a%20phishing%20email%20went%20undetected%20for%2020%20months%2C%20leading%20to%204.1%20TB%20of%20personal%20data%20appearing%20on%20the%20dark%20web.%20Why%20physical%20disconnection%20breaks%20this%20chain.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-staffordshire-water-ico-fine-963900-data-breach-2026)

![UK water treatment site at dusk with a magenta data-glitch overlay, illustrating the South Staffordshire Water cyber attack and ICO fine](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/south-staffordshire-water-ico-fine-963900-data-breach-2026.jpg)

UK water treatment site at dusk with a magenta data-glitch overlay, illustrating the South Staffordshire Water cyber attack and ICO fine

Why it matters

## What this means for organisations holding critical data

The ICO has fined South Staffordshire Water £963,900 after a phishing email went undetected for 20 months, leading to 4.1 TB of personal data appearing on the dark web. Why physical disconnection breaks this chain.

In this analysis

1.  01 [How the breach unfolded](#section-0)
2.  02 [Who was affected](#section-1)
3.  03 [What the ICO found](#section-2)
4.  04 [Where Offline Secure Storage cha…](#section-3)
5.  05 [Mapping to the regulatory expect…](#section-4)
6.  06 [What CNI operators should do now](#section-5)

**On this page**[How the breach unfolded](#section-0)[Who was affected](#section-1)[What the ICO found](#section-2)[Where Offline Secure Storage cha…](#section-3)[Mapping to the regulatory expect…](#section-4)[What CNI operators should do now](#section-5)

The Information Commissioner's Office has fined South Staffordshire Plc and South Staffordshire Water Plc a combined £963,900 after a cyber attack exposed the personal information of 633,887 customers and employees on the dark web. The case is one of the clearest recent examples of why a connected, software defended estate is not enough to protect regulated personal data, and why an offline copy of the data of record has become a baseline expectation for critical national infrastructure.

The ICO announced the penalty on 11 May 2026, following a voluntary settlement in which South Staffordshire admitted the infringement and agreed to pay the reduced fine without appeal. A forty per cent reduction was applied in recognition of the early admission.

## How the breach unfolded

The intrusion can be traced back to September 2020, when a member of staff opened an attachment delivered by a phishing email. That single click installed malicious software that remained undetected inside the network for twenty months. In May 2022 the attacker moved laterally and obtained domain administrator privileges, the highest level of access available on the corporate IT estate.

The breach was only identified when IT performance issues prompted an internal investigation on 15 July 2022. South Staffordshire reported the personal [data breach](/learn/breaches) to the ICO on 24 July 2022. Two days later, on 26 July, staff discovered a ransom note that the attacker had attempted to distribute internally. Between August and November 2022, more than 4.1 terabytes of data appeared on the dark web.

## Who was affected

At the time of the attack South Staffordshire held personal information relating to approximately 1.85 million customers, around 750,000 of them current and 1.1 million former, as well as 2,791 current employees and at least 2,298 former employees.

The 633,887 records subsequently published on the dark web in August 2022 included full names, physical addresses, email addresses, dates of birth, gender and telephone numbers. For employees the leaked data included HR information and National Insurance numbers. For customers the leaked data included account information, usernames and passwords for the South Staffordshire Water online services, bank account numbers and sort codes. For a small percentage of customers on the Priority Services Register, the leaked information was sufficient to allow disabilities to be inferred.

## What the ICO found

The ICO concluded that South Staffordshire had failed to implement appropriate security controls under UK data protection law. The findings included:

-   Limited controls that allowed the attacker to escalate to administrator privileges after gaining an initial foothold on the network.
-   Inadequate monitoring and logging. Only five per cent of the IT environment was being monitored, meaning malicious activity was not detected for the full twenty months.
-   Use of obsolete and unsupported software on some devices, including Windows Server 2003.
-   Inadequate vulnerability management, including unpatched critical systems and the absence of regular internal or external security scans.

Ian Hulme, the ICO's Interim Executive Director for Regulatory Supervision, set out the regulator's expectation in plain terms.

> "Customers do not have the choice over which water company serves them. They are required to share their personal information and place their trust in that provider. It is therefore essential that water companies honour that trust by taking their data protection responsibilities seriously. The steps that South Staffordshire failed to take are established, widely understood and effective controls to protect computer networks. The ICO expects all organisations, and particularly those handling large volumes of personal information as part of critical national infrastructure, to have these in place. Waiting for performance issues or a ransom note to discover a breach is not acceptable. Proactive security is a legal requirement, not an optional extra."

## Where Offline Secure Storage changes the outcome

Mark Fermor, co-founder of Firevault, has been consistent on this point. If data is reachable, it is exposed. The South Staffordshire case is a textbook demonstration of how that reachability compounds at every stage of an attack.

**Phishing only succeeds because the data is reachable from the user estate.** A phishing email that drops malware onto an office workstation is only useful to an attacker if that workstation, or anything it can reach, holds something worth stealing. [Offline Secure Storage](/offline-secure-storage) holds the gold copy of regulated personal data on dedicated hardware with no network interface present in its default state. A phished workstation cannot reach what is not on the network.

**Twenty months of dwell time only matters because the network is always on.** Dwell time is the gap between intrusion and detection. Attackers use it to map the estate, escalate privileges and stage exfiltration. An offline, identity locked vault has nothing to map and nothing to pivot into. There is no IP address to scan, no port to probe and no service to enumerate.

**4.1 terabytes cannot leave a vault that has no outbound path.** Exfiltration at that scale requires a sustained network route from the storage to the open internet. Physical disconnection at Layer 1 removes that route entirely. The vault is not on the same network as the attacker, and it cannot be brought onto that network by remote command.

**Domain administrator compromise is irrelevant to a vault that is not on the domain.** The most damaging moment in the South Staffordshire timeline was the escalation to domain admin in May 2022. A vault that is not joined to the corporate domain, has no Active Directory trust and accepts no remote administration is not affected by that escalation. Identity locked access through KYC, AML and multi factor authentication binds connection to a verified human action, not to a credential that an attacker can steal or replay.

**Customer PII and employee HR data are exactly the workload Offline Secure Storage is designed for.** Names, addresses, dates of birth, National Insurance numbers, bank details and Priority Services Register flags do not need to sit on a frequently accessed, internet adjacent system. They need to be kept, kept accurately and kept private. That is the workload profile that Firevault Bunkers exist to serve.

## Mapping to the regulatory expectation

Mr Hulme's statement is unambiguous. Proactive security is a legal requirement. For operators of critical national infrastructure that expectation already lives inside the NIS Regulations, the incoming NIS2 transposition obligations for in scope operators, the NCSC Cyber Assessment Framework and the [Cyber Essentials](/solutions/oss/compliance/cyber-essentials) baseline. Each of those frameworks treats the ability to preserve, isolate and restore a clean copy of essential data as a core control, not an optional one.

The 3-2-1-0 principle remains the cleanest shorthand. Three copies of the data, on two different media, with at least one copy held offsite, and zero errors at restore. The "one offsite" line is increasingly read by regulators and insurers as "one offline". Offline Secure Storage is how Firevault delivers that final, isolated copy in Firevault Bunkers, with identity locked access and physical disconnection between sessions.

## What CNI operators should do now

The ICO has set out four questions that every operator should be able to answer in the affirmative. They are worth restating, with one addition.

1.  Are controls in place so that users and systems can only access what they genuinely need?
2.  Are logging and monitoring controls in place providing sufficient coverage of the IT environment, and are alerts being acted upon?
3.  Are all systems patched and supported? Legacy or end of life software represents a significant and avoidable risk.
4.  Is vulnerability management part of regular operational practice, including both internal and external scanning?
5.  Is at least one copy of your regulated personal data held on Offline Secure Storage, physically disconnected from the network, so that a successful intrusion of the connected estate cannot extract, encrypt or publish it?

The fifth question is the one that turns a breach into a contained incident rather than a 4.1 terabyte dark web disclosure.

## The Firevault position

Software defences are necessary. They are not, on their own, sufficient. The South Staffordshire case shows what happens when a connected estate is breached and the data of record sits inside that connected estate. Firevault exists to take that data out of reach, by design, and to hold it on dedicated hardware in carefully selected colocation bunkers with identity locked access.

If you operate critical national infrastructure, or hold large volumes of personal information on behalf of customers who have no choice but to trust you, the case for an offline copy is no longer a debate about cost. It is a question of regulatory exposure, customer harm and the reputational cost of a ransom note arriving before your monitoring does.

Learn more about [Offline Secure Storage for critical national infrastructure](/solutions/oss/industries/critical-infrastructure), read [what Offline Secure Storage actually is](/offline-secure-storage), see how Firevault aligns with [UK and international compliance frameworks](/compliance), or read about [complete control by design](/why-oss/control).

**How Firevault helps**

-   **[Offline Secure Storage](/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
-   **[Control](/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.

_Talk to Firevault about [Disconnect to Protect®](/about) for your organisation._

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![Peppa Pig and Transformers owner Hasbro hit by cyber-attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/hasbro-cyber-attack-peppa-pig-transformers-2026.jpg)

Cyber Attack 

### Peppa Pig and Transformers owner Hasbro hit by cyber-attack

Toy and entertainment giant Hasbro, owner of Peppa Pig, Transformers and Monopoly, has confirmed unauthorised access to its network. The breach was discovered on 28 March 2026 and could delay product deliveries for several weeks.

1 Apr 2026 3 min 







](/news/hasbro-cyber-attack-peppa-pig-transformers-2026)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)[

![Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Insight 

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min 







](/news/beacon-charity-database-breach-hiv-charity-health-data-2026)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)