Control - data path governance for enterpriseControl

Control: network paths you can physically verify.

Nine purpose-built modules across two layers. The Fire layer decides which paths exist. The Vault layer decides what those paths are allowed to touch. Every decision is enforced in hardware you can see, hear and physically verify.

9
Modules
2
Layers
8
Blueprints
L1
Physical
FIRE, Control the path
VAULT, Protect the asset
Control - data path governance for enterprise
Control
Isolate module icon
Isolate
Validate module icon
Validate
Archive module icon
Archive
Control Blueprint
OT Air-Gap
  • FV-Isolate module icon
    IsolateSeparates OT from everything else
  • FV-Archive module icon
    ArchivePreserves operational records
  • FV-Validate module icon
    ValidateConfirms the asset before recovery

Live path control across Purdue Levels 0 to 5

01Why we built this

Software alone was never going to be enough.

The same weaknesses recur in serious incidents. Control addresses them by moving the decision into hardware, away from the network it protects.

Once inside, an attacker can move through the network

One compromised laptop is rarely the goal. It is the way in. Without a physical break in the path, the next system is only a hop away.

The off switch relies on the network it is meant to cut

If the kill command travels the same network as the threat, the attacker is already standing next to the off switch. Control moves that switch off the network entirely.

Pulling cables works, but it does not scale

Every team that has handled a real incident knows the feeling. Control gives you the same outcome on demand, from anywhere, with a clean audit trail.

02Nine modules

Four Fire modules decide the path. Five Vault modules decide the payload.

Every Control Blueprint is assembled from these nine modules. Nothing is bolted on afterwards.

Firebreak

FIRE

Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.

Isolate

FIRE

Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.

Relay

FIRE

Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.

Execute

FIRE

Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.

Validate

VAULT

Checks whether a request, command or approval should proceed before access, action or transfer is allowed.

Archive

VAULT

Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.

Unlink

VAULT

Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.

Lock

VAULT

Restricts access through identity, authority, policy, permission and operational controls.

Transfer

VAULT

Controls how sensitive assets move into, out of or between protected environments through approved paths.

03Firebreak

Firebreak is the physical control point.

Where a Blueprint calls for a Layer 1 cut, Firebreak delivers it. Per-zone, independently, in milliseconds, over a command path that never touches the production network.

See the Firebreak range
Compromised
Affected hosts
FV-Is module icon
FV-Ex module icon
Isolate · Execute
Internal Network
Workloads, directory
FV-Lo module icon
Lock
Protected Zone
Records, secrets
Compromised
Affected hosts
FV-Is module icon
FV-Ex module icon
Isolate · Execute
Internal Network
Workloads, directory
FV-Lo module icon
Lock
Protected Zone
Records, secrets

CP-02·Separate compromised systems and restrict access immediately.

Module deck
Fb
Firebreak module icon
Firebreak
Re
Relay module icon
Relay
Un
Unlink module icon
Unlink
Va
Validate module icon
Validate
Ar
Archive module icon
Archive
Tr
Transfer module icon
Transfer
Fire, path controlProtect, asset protection
04What is included

Three properties every deployment inherits.

What Every Blueprint Includes

Four pillars under every Control Blueprint

Whatever the outcome, every Blueprint rests on the same physical foundation.

Out-of-band command path

Commands arrive over dedicated management Ethernet, cellular SMS, or an authenticated API. They never traverse the production network they control.

Learn more

Per-zone independence

Each zone is switched independently. Isolate one circuit, one tenant, one SCADA segment, without touching the rest.

Learn more

Auditable, evidential log

Every action is logged locally and to SysLog. Verifiable records for NIS2, DORA, insurer scrutiny and internal audit.

Learn more
05Against alternatives

Detection tells you. Manual cabling costs you. Control does it.

Control vs the alternatives

Detect-and-respond and manual shutdown are the two positions most teams pick between. Control is the third.

Posture Detect & respond Manual shutdown Control
Time to contain Minutes to hours Minutes, manual Milliseconds, scheduled or on-demand
Reversible without site visit Yes No Yes
Auditable physical action No Ad hoc Yes
Depends on uncompromised software Yes No No, hardware path
Scope of action Alerts, blocks, isolates a host Whole segment, all or nothing Per-zone, per-module, per-blueprint
Out-of-band command path No No Yes
Maps to NIS2 / DORA isolation Indirect Indirect Yes
06UK governance

Board-level evidence, not screenshots.

UK Board-Level Cyber Governance

Hardware-enforced accountability the board can sign off

The NCSC Cyber Security Toolkit for Boards and the UK NIS2 regime both put personal, evidenced accountability on directors. Control turns that duty into a physical artefact: a switch position, an out-of-band command and a signed log, not a policy assertion.

NCSC Cyber Security Toolkit for Boards, mapped to Control

NCSC Board Toolkit, Principle A

Embed cyber security into your governance

Control gives the board a single, physical control point over connectivity. Zone state is a governance artefact, not a screenshot. Board packs cite the actual switch position, not an intent.

NCSC Board Toolkit, Principle B

Build a positive cyber security culture

Out-of-band command paths remove the temptation to bypass. Operators cannot silently reconnect a segment: every action requires a named identity on a separate management plane.

NCSC Board Toolkit, Principle C

Establish baseline security controls

Physical segmentation between OT and IT, between crown-jewel data and the estate, and between third parties and production. Hardware-enforced, not policy-enforced.

NCSC Board Toolkit, Principle D

Manage cyber risk in the supply chain

Supplier and MSP access is scheduled, identity verified and time bound. When the window closes, the segment is physically disconnected. Third-party breach blast radius is bounded by hardware.

NCSC Board Toolkit, Principle E

Plan your response to cyber incidents

Firebreak provides a rehearsed, board-authorised kill switch. Isolation happens without walking to a rack, without touching the compromised network, and produces a signed, timestamped record for the post-incident review.

Reference: NCSC Cyber Security Toolkit for Boards. Firevault maps controls to Toolkit principles; the Toolkit is guidance, not certification.

UK NIS2 director duties, evidenced by hardware

Management body accountability, Article 20

NIS2 puts network security decisions on the board personally. Control makes those decisions evidenceable at the hardware layer, not just in policy documents, so directors can demonstrate they have discharged the duty.

See NIS2 mapping

Cybersecurity risk-management measures, Article 21

Article 21 requires network security, access control, supply-chain security and incident handling. Control's out-of-band command path, per-zone independence and signed logs map directly to Article 21(2)(a), (d), (e) and (i).

See NIS2 mapping

24 and 72 hour incident notification, Article 23

The evidential log is generated at the moment of isolation, not reconstructed afterwards. Boards can meet the 24 hour early warning and 72 hour incident notification obligations with a defensible timeline.

See NIS2 mapping
07Use cases

Where Control can be put to work.

Use Cases

Every sector reaches into the same eight Blueprints.

08Who it is for

Built for the teams who own the consequences.

Who Control Is For

From OT segments to national infrastructure

Control is built for operators who need physical certainty over what is reachable, when, and by whom.

Decide what stays connected.

We will review your architecture, map the modules you need and show you the evidence your board is likely to require.

Explore Blueprints
    Get started