Control Blueprints

FIRE controls the path. VAULT protects the asset.

A Control Blueprint is a deployment pattern. It names the route an attack would take, the lead layer that answers it, and the modules that deliver the control. Find the pattern closest to your estate and see how it composes.

Control Blueprints diagram showing all seven deployment patterns arranged around the central Firevault control model

7

Buyer-led Control Blueprints

9

FIRE and VAULT modules

3

Lead patterns: FIRE, VAULT, both

Zero

Standing path when the route is severed

The same method every time

Three steps behind every Blueprint

The Blueprints differ in what is at stake, not in how the control is built. Each one applies the same three steps to a different environment.

01

Name the path the attack would take

Every Blueprint starts from the route between a user, a system and the asset that would cause the most damage.

02

Choose the lead layer

FIRE controls the path. VAULT protects the asset. Some patterns need both working against the same route.

03

Compose the modules

Primary modules deliver the control. Supporting modules hold the evidence, the identity checks and the recovery copy.

FIRE-led

Controls the path. Disconnects, isolates and severs the route the attack would take.

VAULT-led

Protects the asset. Holds the data, identity and evidence behind verifiable controls.

FIRE + VAULT

Path and asset together, where access must be controlled and what it touches must be locked.

Blueprints in play

See the modules compose

The cards are modules. The line is the path between the user and the asset. Firebreak lands on the gate and the route severs. Select any card to pause.

Untrusted
Internet, email
FV-Fb module icon
FV-Is module icon
Firebreak · Isolate
Corporate IT
Endpoints, file shares
FV-Ex module icon
Execute
Clean Recovery
Backups, snapshots
Untrusted
Internet, email
FV-Fb module icon
FV-Is module icon
Firebreak · Isolate
Corporate IT
Endpoints, file shares
FV-Ex module icon
Execute
Clean Recovery
Backups, snapshots

RW·Break the attack path, contain systems, preserve clean recovery.

Module deck
Re
Relay module icon
Relay
Un
Unlink module icon
Unlink
Va
Validate module icon
Validate
Ar
Archive module icon
Archive
Lo
Lock module icon
Lock
Tr
Transfer module icon
Transfer
Fire, path controlProtect, asset protection
Seven Blueprints

The risk, and the pattern that answers it

Each Blueprint names the exposure, the lead layer and the modules that deliver the control. Filter by lead layer to narrow the patterns that fit your environment.

Showing 7 of 7

Blueprint Tool

Not sure which blueprint you need?

Answer a short series of questions on the problems, outcomes and assets that matter. We will recommend the right Control blueprint and the module mix that delivers it.

Start the Blueprint Tool
CP-01FIRE-led

Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

Primary modules
FirebreakIsolateExecute

Lateral movement prevention across IT and OT

Read the Blueprint
CP-02FIRE-led

Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

Primary modules
FirebreakIsolateExecute

Live incident containment and recovery

Read the Blueprint
CP-03FIRE + VAULT

Control Third-Party Access

Give third parties access without giving them a permanent doorway.

Primary modules
ValidateRelayLock

Time-bounded vendor and supplier access

Read the Blueprint
CP-04FIRE-led

Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

Primary modules
FirebreakIsolateUnlink

Trust boundary enforcement between zones

Read the Blueprint
CP-05FIRE + VAULT

Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

Primary modules
FirebreakIsolateRelayExecute

OT and CNI connectivity with maintenance windows

Read the Blueprint
CP-06VAULT-led

Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

Primary modules
ValidateLockArchive

Audit-grade governance of access and evidence

Read the Blueprint
CP-07FIRE-led

Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

Primary modules
FirebreakIsolateValidateRelay

Aerospace, aviation and MRO ground networks with air-lock ingress control

Read the Blueprint
Nine modules

Every Blueprint is built from these

Four FIRE modules control the path. Five VAULT modules protect the asset, the identity check and the evidence trail.

Firebreak module icon
FirebreakFIRE

Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.

Isolate module icon
IsolateFIRE

Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.

Relay module icon
RelayFIRE

Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.

Execute module icon
ExecuteFIRE

Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.

Validate module icon
ValidateVAULT

Checks whether a request, command or approval should proceed before access, action or transfer is allowed.

Archive module icon
ArchiveVAULT

Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.

Unlink module icon
UnlinkVAULT

Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.

Lock module icon
LockVAULT

Restricts access through identity, authority, policy, permission and operational controls.

Transfer module icon
TransferVAULT

Controls how sensitive assets move into, out of or between protected environments through approved paths.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Compose Control for your environment

Speak to a member of the team about combining these Blueprints around your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up