Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Education

Campus Network Segmentation and Safeguarding Controls

Educational institutions manage open campus networks alongside sensitive research data, student safeguarding records, and financial systems. The culture of openness that enables learning also creates significant cybersecurity challenges.

Back to Control
Control by Firevault product icon

Key threats addressed

Ransomware on campusSafeguarding data exposureResearch IP theftStudent BYOD compromiseNation-state academic espionageExam system tampering

Education

When a student's personal device and the school's safeguarding database share the same network, every compromised student laptop is a potential path to the most sensitive data an institution holds.

100%

Safeguarding data isolation from campus networks

Zero

Direct paths between research and admin systems

4

Campus zones with independent governance

Full

DfE and Ofsted safeguarding evidence

The Challenge

Educational networks balance openness with protection.

Safeguarding Data Risks

Student safeguarding records, SEN data, and child protection information must be rigorously protected while remaining accessible to authorised pastoral staff.

Open Campus Networks

Universities and schools operate open networks for learning that also connect to sensitive administrative, financial, and research systems.

Research Data Theft

University research data, particularly in defence, pharmaceutical, and technology sectors, is targeted by nation-state actors for intellectual property theft.

The Scenario

Scenario: University Ransomware and Research Data Theft

Ransomware enters through a compromised student laptop on the campus Wi-Fi network. It propagates across the flat campus network, reaching administrative systems, research servers, and the student records database. The university loses access to exam results during clearing week, research data for three funded projects is encrypted, and safeguarding records for vulnerable students are exposed. With Control, the campus network is physically separated into student, research, administrative, and safeguarding zones. The ransomware cannot propagate beyond the student zone because the network paths to other zones do not exist.

"The ransomware came in through a first-year student's laptop. Twelve hours later, it had encrypted our research servers, our student records, and our finance system. We lost three years of PhD research data because the backups were on the same network."

Module deployment · education network

Where each Control module is deployed across staff, students, research and suppliers.

Education networks carry staff, students, research and a long tail of suppliers. Control puts a real boundary at the places that matter, in line with the JISC reference architecture.

Grounded in the JISC reference architecture and NCSC guidance for HE / FE / schools.

E0

Internet / Janet

External

External services
Cloud
FV-Firebreak module iconFirebreakFV-Validate module iconValidate

External traffic stops at the perimeter.

E1

Perimeter

DMZ · trust boundary

Reverse proxy
VPN
FV-Isolate module iconIsolateFV-Validate module iconValidate

Identity sits behind its own boundary.

E2

Identity

IT

Federated SSO
Eduroam
FV-Lock module iconLock

System access ties to named users.

E3

Staff and student systems

IT

VLE
Records
Library
FV-Isolate module iconIsolateFV-Transfer module iconTransferFV-Lock module iconLock

Research data moves on a controlled, named route.

E4

Research

Data

Datasets
HPC
Lab kit

Sensitive research is a separate fabric.

Sensitive research is a separate fabric.

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Research datasets, exam records, statutory archives and any data you must keep recoverable.

Offline by design · secure by default

Modules & symbols

FV-Firebreak module iconFirebreakPhysical sever
FV-Validate module iconValidateIntegrity check
FV-Isolate module iconIsolateZone boundary
FV-Lock module iconLockNamed access
FV-Transfer module iconTransferControlled move
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. FV-Firebreak module icon

    Firebreak

    On the E0 to E1 link

    A real hardware off switch on the perimeter, ready to drop the live path between the public estate and operations.

  2. FV-Validate module icon

    Validate

    On the E0 to E1 link and the E1 to E2 link

    Inbound traffic and identity requests are checked for origin and authority before they progress.

  3. FV-Isolate module icon

    Isolate

    On the E1 to E2 link and the E3 to E4 link

    Identity and research sit on their own physical fabrics. A compromise on the staff or student side does not walk into sensitive research.

  4. FV-Lock module icon

    Lock

    On the E2 to E3 link and the E3 to E4 link

    Access ties to named users with the right entitlement.

  5. FV-Transfer module icon

    Transfer

    On the E3 to E4 link

    When data feeds research, Transfer governs the route, the de-identification and the landing point.

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

Data Sovereignty

All safeguarding and student data remains within the agreed jurisdiction in secured Firevault Bunkers, meeting DfE data handling requirements.

Safeguarding Access Controls

Access to safeguarding records requires authorisation from designated safeguarding leads with full audit logging.

DfE and Ofsted Evidence

Automated compliance logging supports DfE cyber security standards, Ofsted safeguarding requirements, and GDPR obligations.

Campus Cellular Management

Out-of-band management via cellular connectivity ensures governance capability independent of the campus network.

Safeguarding Audit Trail

Every access to safeguarding data is recorded in tamper-proof logs for regulatory inspection and child protection reviews.

Research Data Recovery

Verified baselines of research-system configuration enable restoration of funded project work regardless of campus network compromise.

Demo to Live

Adoption Guide

Step 1

Campus Network Assessment

Map all network paths between student access, research systems, administrative infrastructure, and safeguarding data to identify segmentation gaps.

Step 2

Campus Zone Design

Design physically separated zones for student access, research, administration, and safeguarding with Control modules at each boundary.

Step 3

Department Pilot

Deploy in a representative faculty or department with full zone separation, safeguarding data governance, and compliance logging.

Step 4

Institution-Wide Deployment

Full deployment across the campus with verified configuration baselines, continuous compliance evidence, and cellular management capability.

Step 1

Campus Network Assessment

Map all network paths between student access, research systems, administrative infrastructure, and safeguarding data to identify segmentation gaps.

Step 2

Campus Zone Design

Design physically separated zones for student access, research, administration, and safeguarding with Control modules at each boundary.

Step 3

Department Pilot

Deploy in a representative faculty or department with full zone separation, safeguarding data governance, and compliance logging.

Step 4

Institution-Wide Deployment

Full deployment across the campus with verified configuration baselines, continuous compliance evidence, and cellular management capability.

Questions

Frequently Asked

Education blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy