---
title: "Southampton council reported seven serious data… | Firevault"
description: "Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026#webpage",
      "url": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026",
      "name": "Southampton council reported seven serious data…",
      "description": "Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/southampton-council-data-breaches-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details",
          "item": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details",
      "description": "Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.",
      "url": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/southampton-council-data-breaches-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/southampton-council-data-breaches-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/southampton-council-data-breaches-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/southampton-council-data-breaches-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-16T09:00:00+00:00",
      "dateModified": "2026-09-18T05:34:48.098055+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/southampton-council-seven-serious-data-breaches-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 806,
      "keywords": "Southampton, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Southampton City Council reported seven data breaches to the Information Commissioner''s Office in the past year, each deemed serious enough to require notification to the regulator, according to a report by the Daily Echo. The incidents, set out in a report to the council''s governance committee by data protection officer Christ Thornton, paint a picture of risk spread across every format the cou",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened at Southampton City Council?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The council reported seven data breaches to the Information Commissioner''s Office in 2025/26. Incidents included a social worker losing a notebook containing the names, addresses and key safe numbers of 224 people, a council officer accessing and sharing a tenant''s information with a family member, the premature destruction of 167 children''s social care records, 75 missing asbestos reporting forms, a compromised financial assessment provider and around 80,000 miscatalogued social care files."
          }
        },
        {
          "@type": "Question",
          "name": "How many people were affected by the lost notebook?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The lost social worker''s notebook contained the names, addresses and key safe numbers of 224 individuals. Key safe numbers are physical access credentials, which makes the loss a safeguarding concern as well as a data protection incident."
          }
        },
        {
          "@type": "Question",
          "name": "Did the ICO take enforcement action?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The ICO decided against opening a criminal investigation into the officer who shared a tenant''s information, and told the council it was satisfied with the remediation measures taken across the seven incidents. The ICO also invited the council to support its Better Care Records campaign."
          }
        },
        {
          "@type": "Question",
          "name": "How common were data incidents at the council?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "In 2025/26, 179 data security incidents were reported to the council''s governance and information team, down from 198 the previous year. Seventy two per cent were confirmed as data breaches, and information sent electronically to the wrong recipient was the most common cause."
          }
        },
        {
          "@type": "Question",
          "name": "Why does miscataloguing of files matter?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Records that cannot be found cannot be protected. Miscatalogued archives undermine retention schedules, destruction rules and subject access requests, and they make it impossible for an organisation to say honestly what it holds and where."
          }
        },
        {
          "@type": "Question",
          "name": "What should other organisations learn from this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Treat paper records as endpoints with the same controls as digital systems, add verification steps to reduce wrong-recipient email errors, audit archives proactively, and move historical records that do not need to be online into disconnected storage such as Offline Secure Storage so they cannot be browsed, emailed or copied."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

A lost notebook is a data breachThe insider problem, againEighty thousand miscatalogued filesWhat organisations should take f…SourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 16 September 2026 · Breaking 

# Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthampton-council-seven-serious-data-breaches-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthampton-council-seven-serious-data-breaches-2026&text=Southampton%20council%20reported%20seven%20serious%20data%20breaches%20in%20a%20year%2C%20including%20a%20lost%20notebook%20with%20224%20residents'%20details%0A%0ASouthampton%20City%20Council%20referred%20seven%20incidents%20to%20the%20Information%20Commissioner's%20Office%20in%202025%2F26%2C%20including%20a%20social%20worker's%20lost%20notebook%20containing%20the%20names%2C%20addresses%20and%20key%20safe%20numbers%20of%20224%20people.%20Mark%20Fermor%20on%20what%20a%20notebook%2C%20a%20miscatalogued%20archive%20and%20a%20curious%20officer%20tell%20us%20about%20the%20data%20organisations%20still%20cannot%20control.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthampton-council-seven-serious-data-breaches-2026)[](mailto:?subject=Southampton%20council%20reported%20seven%20serious%20data%20breaches%20in%20a%20year%2C%20including%20a%20lost%20notebook%20with%20224%20residents'%20details&body=Southampton%20City%20Council%20referred%20seven%20incidents%20to%20the%20Information%20Commissioner's%20Office%20in%202025%2F26%2C%20including%20a%20social%20worker's%20lost%20notebook%20containing%20the%20names%2C%20addresses%20and%20key%20safe%20numbers%20of%20224%20people.%20Mark%20Fermor%20on%20what%20a%20notebook%2C%20a%20miscatalogued%20archive%20and%20a%20curious%20officer%20tell%20us%20about%20the%20data%20organisations%20still%20cannot%20control.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fsouthampton-council-seven-serious-data-breaches-2026)

![A paper notebook of handwritten names dissolving into cyan data streams above a dark desk, with a civic building in the background and a single magenta thread highlighting one leaked line](/news/southampton-council-data-breaches-2026.jpg)

A paper notebook of handwritten names dissolving into cyan data streams above a dark desk, with a civic building in the background and a single magenta thread highlighting one leaked line

Why it matters

## What this means for organisations holding critical data

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

In this analysis

1.  01 [A lost notebook is a data breach](#section-0)
2.  02 [The insider problem, again](#section-1)
3.  03 [Eighty thousand miscatalogued files](#section-2)
4.  04 [What organisations should take f…](#section-3)

**On this page**[A lost notebook is a data breach](#section-0)[The insider problem, again](#section-1)[Eighty thousand miscatalogued files](#section-2)[What organisations should take f…](#section-3)

Southampton City Council reported seven data breaches to the Information Commissioner''s Office in the past year, each deemed serious enough to require notification to the regulator, according to a report by the Daily Echo.

The incidents, set out in a report to the council''s governance committee by data protection officer Christ Thornton, paint a picture of risk spread across every format the council touches. In one case, a social worker lost a notebook containing the names, addresses and key safe numbers of 224 individuals. In another, inaccurate information about a person was shared with police. A council officer accessed information relating to a tenant and shared it with a family member, a case referred to the ICO as a potential criminal offence, though the regulator decided against opening a criminal investigation.

Other incidents included 167 children''s social care records being destroyed prematurely, 75 asbestos reporting forms going missing, the compromise of a financial assessment provider''s system and the miscataloguing of around 80,000 social care files.

Across 2025/26, 179 data security incidents were reported to the council''s governance and information team, down from 198 the previous year. Investigations found 72 per cent of reported incidents were confirmed data breaches, with information sent electronically to the wrong recipient the most common cause.

Mr Thornton told the committee the ICO was satisfied with the council''s remediation measures and had invited the authority to support its Better Care Records campaign. No questions were asked about the breaches at the meeting.

## A lost notebook is a data breach

It is tempting to read a list like this and separate the serious incidents from the mundane. That instinct is wrong. A notebook containing names, home addresses and key safe numbers is not stationery. It is a structured extract of some of the most sensitive information a council holds, travelling in a bag, readable by anyone who picks it up, with no access log, no encryption and no way to revoke it.

Key safe numbers in particular deserve attention. They are, in effect, physical access credentials to the homes of people who often receive care. Their loss is not an administrative embarrassment. It is a safeguarding event.

The fact that a notebook appears on the same incident register as a compromised supplier system and an 80,000-file cataloguing failure is itself the lesson. Sensitive data does not respect the boundary between digital and physical. Wherever it is copied, carried or written down, it becomes breachable in exactly the same way.

## The insider problem, again

Two of the seven incidents involve people, not systems: an officer accessing a tenant''s record and sharing it with a family member, and inaccurate information passed to police. This is the same failure mode seen in the Southport court files case and the ambulance service record access before it: legitimate credentials used for an illegitimate purpose.

No perimeter defence addresses this, because there is no perimeter crossing. The only effective responses are least-privilege access scoped to role and need, complete audit logging, proactive review of that logging, and consequences understood in advance. It is to the council''s credit that these incidents were identified and reported. The harder question is how long they went unnoticed before review found them.

## Eighty thousand miscatalogued files

The miscataloguing of around 80,000 social care files may prove the most consequential item on the list. Miscataloguing is a silent breach multiplier: records that cannot be found cannot be protected, retention rules cannot be enforced on them, subject access requests cannot be answered fully, and destruction schedules either fail or, as the premature destruction of 167 children''s records shows, execute against the wrong information.

This is the unglamorous core of data governance. An archive that nobody can accurately index is an archive nobody can honestly claim to control.

## What organisations should take from this

First, treat paper as an endpoint. If staff need information in the field, control the extract: minimum necessary data, no physical access credentials, tracked issue and return, and prompt destruction.

Second, measure your wrong-recipient rate. It was the most common cause here and it is the most common cause almost everywhere. Verification steps at send time are cheap. Breach notifications are not.

Third, audit your archive before someone else does. Records you cannot locate are records you cannot protect, and retention you cannot enforce is risk you are carrying unknowingly.

Fourth, disconnect what does not need to be connected. Historical care records, closed case files and legacy archives have no requirement to sit on live, reachable systems. Data that is not online cannot be casually browsed, wrongly emailed or quietly copied. [Offline Secure Storage](/offline-secure-storage) is built for exactly this class of data: the records an organisation must keep but does not need connected.

## Sources

-   [Daily Echo: Names and addresses of 224 people exposed in council data breach](https://www.dailyecho.co.uk/news/26554501.names-addresses-224-people-exposed-council-data-breach/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

Breach Analysis 

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min 







](/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![CenterPoint Energy confirms hackers stole customer data through an exposed API](/news/centerpoint-energy-cyberattack-2026.jpg)

Breach Analysis 

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min 







](/news/centerpoint-energy-confirms-cyberattack-data-theft-2026)[

![Southport court files breach: the access was authorised, the purpose was not](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Breach Analysis 

### Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

16 Sept 2026 5 min 







](/news/southport-court-files-insider-access-breach-2026)[

![Military flight plan reportedly triggered the NATS outage, unless you ask the MoD](/news/nats-outage-military-flight-plan-2026.jpg)

Breach Analysis 

### Military flight plan reportedly triggered the NATS outage, unless you ask the MoD

Flight data filed for a UK military aircraft reportedly set off the 8 September NATS failure, according to the Financial Times. The Ministry of Defence says there was no error on its part. Mark Fermor on what a single filing emptying the national schedule says about resilience.

12 Sept 2026 5 min 







](/news/nats-outage-military-flight-plan-resilience-2026)[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)

![Firevault brand mark](/assets/icon-white-DNqdto3B.png)

[![Firevault - physical control for critical data](/assets/logo-white-official-BKfZ19hm.png)](/)

International cyber resilience

## Protect what matters. Control what moves. 

Firevault is an international cyber resilience company specialising in Offline Secure Storage® and OT cyber security, helping organisations protect critical data and govern how systems connect and how data moves.

[hello@fire-vault.com](mailto:hello@fire-vault.com)Europe, US and Middle East 

Cyber security certified 

[

![Cyber Essentials Certified](https://fire-vault.com/__l5e/assets-v1/6f8f42a2-89e1-4c20-938f-3f34d30bc90c/cyber-essentials-2026.png)

![Cyber Essentials Plus Certified](https://fire-vault.com/__l5e/assets-v1/8a77bf2c-6711-4762-b093-c4d650153bc9/cyber-essentials-plus-2026.png)

](https://registry.blockmarktech.com/certificates/)

Start here

### Not sure what you need?

Use the OSS Concierge to find the right protection or control approach for your organisation.

[Find your starting point ](/find-my-oss)

![](/__l5e/assets-v1/e145930c-a2bf-43ae-909c-46634f0fa813/oss-family-mark.png) 

01  · Data protection & storage

[](/offline-secure-storage)

[

### Offline Secure Storage®

](/offline-secure-storage)

Physically disconnected by default, identity verified and built on dedicated hardware, from 300GB personal storage to enterprise-scale infrastructure.

[OSS overview](/offline-secure-storage)[LUV](/luv)[Vault](/vault)[Storage](/storage)[Enterprise](/enterprise)[Bunkers](/bunkers)

![](/__l5e/assets-v1/952d28ee-22a7-4947-9f83-214fa336b124/control-icon.png) 

02  · Network evolution and rapid protection

[](/control)

[

### Control

](/control)

Nine governance modules across FIRE and VAULT, composed into Control Blueprints around the outcome, environment and risk you need to manage.

[Control overview](/control)[Nine modules](/control/nine-modules)[Blueprints](/control-blueprints)[Firebreak](/control/modules/firebreak)[Control by industry](/control-for-industry)

### Knowledge

-   [Knowledge Vault ](/learn/knowledge)
-   [Buyer guides ](/learn/guides/by-role)
-   [Technical guides ](/learn/guides/technical)
-   [Firevault Playbooks ](/playbooks)
-   [White papers ](/learn/whitepapers)
-   [Learn and explainers ](/learn)
-   [Breach tracker ](/learn/breaches)
-   [FAQs ](/learn/faq)

### Firevault

-   [About Firevault ](/about)
-   [Security ](/security)
-   [Partners ](/partners)
-   [Press and media ](/press-media)
-   [Help Centre ](/help)
-   [Careers ](/careers)
-   [Invest in Firevault ](/investors)
-   [Contact ](/contact)

© 2026 Firevault Limited · Company No. 16320803 · VAT No. 490 8551 64 · Registered in England and Wales 

[Site Map](/sitemap)[Privacy Charter](/privacy-charter)[Terms](/terms)[Planet Pledge](/planet-pledge)[Vault Commitment](/vault-commitment)[LUV Commitment](/luv-commitment)[Cookie Policy](/cookies)

[](https://www.linkedin.com/company/firevault-limited)[](https://twitter.com/firevaultuk)

![Firevault](/favicon.svg)

Protecting business data? Ask us.