Offline Secure Storage for Education
Schools, MATs, and universities hold some of the most sensitive personal data in existence — safeguarding records, SEND files, and child protection logs. Offline Secure Storage (OSS) provides physical disconnection for your most vulnerable data.
We Think This Is Hard to Ignore
The NCSC reported 327 cyber incidents targeting UK education in 2024, with ransomware encrypting safeguarding and student records on connected school networks. At Firevault, pupil data lives on hardware that is physically disconnected, because children's records deserve the strongest protection available.
327
Cyber incidents reported by UK schools in 2024
NCSC Annual Review, 2025
£14M
ICO fine to Capita, which processes education data
ICO, October 2025
6.5M
Personal records stolen in single Co-op attack
BBC News, 2025
72hrs
ICO breach notification deadline for pupil data
ICO Guidance
Education data is uniquely sensitive.
Safeguarding Records
Child protection logs and safeguarding records require the highest standard of confidentiality and protection.
Ransomware Targeting
Education is now the most targeted sector for ransomware — the NCSC has issued multiple alerts.
Regulatory Pressure
Ofsted, ICO, GDPR, and KCSIE mandate robust technical measures for pupil data protection.
This is already happening in education.
NCSC: 327 Cyber Incidents Reported by UK Schools in 2024
The National Cyber Security Centre reported a record number of cyber incidents affecting UK schools, with ransomware and data exfiltration the most common attack types targeting pupil records.
NCSC Annual Review, 2025
Capita: £14M Fine Affects Education Data Processing
Capita processes data for hundreds of schools and local authorities. The ICO fined the outsourcer £14 million after hackers accessed personal data of over 6 million people, including education records.
ICO, October 2025
Co-op: Pharmacy and Membership Data of 6.5 Million Stolen
The Co-op attack demonstrated how organisations holding data across multiple sectors, including education partnerships, are vulnerable to mass data exfiltration.
BBC News, 2025
Remove pupil data from every system attackers can reach.
Safeguarding records, SEND files, and child protection logs are taken off school networks and written to dedicated RAID 1 drives inside a Firevault Bunker. Those drives have no internet connection. No IP address. No API. When authorised staff need access, a physical connection is created after identity verification. When the session ends, the drives disconnect.
- Safeguarding data removed from school networks and placed on hardware with no network connection. Ransomware cannot encrypt what is not online
- SEND records isolated with identity-verified access. Stolen staff credentials cannot unlock physically disconnected hardware
- Full audit trail for Ofsted, ICO, KCSIE, and GDPR compliance. Every access session is logged and attributable
- Scalable from single schools to multi-academy trusts with centralised offline protection
Take Pupil Data Off School Networks
Step 1 of 3Safeguarding records, SEND files, and child protection logs are taken off school networks and written to physically disconnected RAID 1 drives inside a Firevault Bunker. No cloud. No shared drive. No attack surface.
Choose Your Protection
Which OSS Fits?
300GB
Low Use Vault — Deep Cold Storage
From £74.99/mo
inc. VAT · £0 due today
Built for sensitive records that should not sit exposed on always-connected systems. Deep cold storage with scheduled access windows.
What 300GB holds
Use Cases for Education
- Safeguarding and child protection files
- SEND and pupil support records
- HR and disciplinary records
- Governance, legal and incident files
- Archived complaints and case materials
Specifications
Capacity
300GB
Access
2 windows/week
Authentication
Identity-locked
Commitment
36 months
Security & Compliance
How to Get Started
Step 1
Discovery Call
Understand what you need to protect and how you operate.
Step 2
Vault Configuration
Select your tier, capacity, and access model.
Step 3
Identity Verification
Complete KYC/AML and set up multi-factor authentication.
Step 4
Go Live
Data ingestion, access policy activation, and ongoing support.
Questions
Frequently Asked
Ready to take the next step?
See how Firevault can protect your most sensitive data with physically disconnected storage.