Name the path the attack would take
Every Blueprint starts from the route between a user, a system and the asset that would cause the most damage.
A Control Blueprint is a deployment pattern. It names the route an attack would take, the lead layer that answers it, and the modules that deliver the control. Find the pattern closest to your estate and see how it composes.

7
Buyer-led Control Blueprints
9
FIRE and VAULT modules
3
Lead patterns: FIRE, VAULT, both
Zero
Standing path when the route is severed
The Blueprints differ in what is at stake, not in how the control is built. Each one applies the same three steps to a different environment.
Every Blueprint starts from the route between a user, a system and the asset that would cause the most damage.
FIRE controls the path. VAULT protects the asset. Some patterns need both working against the same route.
Primary modules deliver the control. Supporting modules hold the evidence, the identity checks and the recovery copy.
Controls the path. Disconnects, isolates and severs the route the attack would take.
Protects the asset. Holds the data, identity and evidence behind verifiable controls.
Path and asset together, where access must be controlled and what it touches must be locked.
The cards are modules. The line is the path between the user and the asset. Firebreak lands on the gate and the route severs. Select any card to pause.
RW·Break the attack path, contain systems, preserve clean recovery.
Each Blueprint names the exposure, the lead layer and the modules that deliver the control. Filter by lead layer to narrow the patterns that fit your environment.
Blueprint Tool
Answer a short series of questions on the problems, outcomes and assets that matter. We will recommend the right Control blueprint and the module mix that delivers it.
Stop ransomware moving, spreading or reaching the crown jewels.
Lateral movement prevention across IT and OT
When prevention fails, containment must be physical, immediate and provable.
Live incident containment and recovery
Give third parties access without giving them a permanent doorway.
Time-bounded vendor and supplier access
Segmentation should not just be logical. It should be physically enforceable.
Trust boundary enforcement between zones
Keep critical systems available, controlled and disconnected from unnecessary exposure.
OT and CNI connectivity with maintenance windows
Compliance becomes stronger when control can be demonstrated, not just documented.
Audit-grade governance of access and evidence
Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.
Aerospace, aviation and MRO ground networks with air-lock ingress control
Four FIRE modules control the path. Five VAULT modules protect the asset, the identity check and the evidence trail.
Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.
Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.
Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.
Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.
Checks whether a request, command or approval should proceed before access, action or transfer is allowed.
Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.
Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.
Restricts access through identity, authority, policy, permission and operational controls.
Controls how sensitive assets move into, out of or between protected environments through approved paths.



Speak to a member of the team about combining these Blueprints around your estate.
Takes about 2 minutes. No account needed.