---
title: "Control Blueprints | Seven Deployment Patterns | Firevault"
description: "Seven buyer-led Control Blueprints from Firevault. Each names its lead layer, the primary FIRE and VAULT modules that deliver it, and the supporting modules…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-blueprints#webpage",
      "url": "https://fire-vault.com/control-blueprints",
      "name": "Control Blueprints",
      "description": "Seven buyer-led Control Blueprints from Firevault. Each names its lead layer, the primary FIRE and VAULT modules that deliver it, and the supporting modules…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/02151af9-f3f5-492a-b7fc-acb5592513e5/og-control-blueprints.png"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-blueprints#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-blueprints#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "/"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Control",
          "item": "/control"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Control Blueprints",
          "item": "/control-blueprints"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Control Blueprints 

# FIRE controls the path. VAULT protects the asset.

A Control Blueprint is a deployment pattern. It names the route an attack would take, the lead layer that answers it, and the modules that deliver the control. Find the pattern closest to your estate and see how it composes.

[See the seven Blueprints](#blueprints) [Watch modules compose](#compose)

![Control Blueprints diagram showing all seven deployment patterns arranged around the central Firevault control model](/__l5e/assets-v1/33bb3007-014e-4c21-bd86-6353dc1d781f/control-blueprints-hero.png)

7

Buyer-led Control Blueprints

9

FIRE and VAULT modules

3

Lead patterns: FIRE, VAULT, both

Zero

Standing path when the route is severed

The same method every time 

## Three steps behind every Blueprint

The Blueprints differ in what is at stake, not in how the control is built. Each one applies the same three steps to a different environment.

**01**

### Name the path the attack would take

Every Blueprint starts from the route between a user, a system and the asset that would cause the most damage.

**02**

### Choose the lead layer

FIRE controls the path. VAULT protects the asset. Some patterns need both working against the same route.

**03**

### Compose the modules

Primary modules deliver the control. Supporting modules hold the evidence, the identity checks and the recovery copy.

FIRE-led

Controls the path. Disconnects, isolates and severs the route the attack would take.

VAULT-led

Protects the asset. Holds the data, identity and evidence behind verifiable controls.

FIRE + VAULT

Path and asset together, where access must be controlled and what it touches must be locked.

Blueprints in play 

## See the modules compose

The cards are modules. The line is the path between the user and the asset. Firebreak lands on the gate and the route severs. Select any card to pause.

RW

Stop Kill-Chain Ransomware

CB

Contain Active Breaches

3P

Control Third-Party Access

SG

Enforce Physical Segmentation

CI

Protect Critical Infrastructure

AG

Prove Compliance Through Control

Untrusted

Internet, email

![FV-Fb module icon](/assets/firebreak-icon-7zSCkB1t.png)

![FV-Is module icon](/assets/isolate-icon-B9t8fl3o.png)

Firebreak · Isolate

Corporate IT

Endpoints, file shares

![FV-Ex module icon](/assets/execute-icon-kJl5Gtmk.png)

Execute

Clean Recovery

Backups, snapshots

Untrusted

Internet, email

![FV-Fb module icon](/assets/firebreak-icon-7zSCkB1t.png)

![FV-Is module icon](/assets/isolate-icon-B9t8fl3o.png)

Firebreak · Isolate

Corporate IT

Endpoints, file shares

![FV-Ex module icon](/assets/execute-icon-kJl5Gtmk.png)

Execute

Clean Recovery

Backups, snapshots

RW · Break the attack path, contain systems, preserve clean recovery. 

Module deck

Re

![Relay module icon](/assets/relay-icon-CVhJDRO7.png)

Relay

Un

![Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)

Unlink

Va

![Validate module icon](/assets/vault-icon-CD3Pv4ri.png)

Validate

Ar

![Archive module icon](/assets/archive-icon-B3rc85NY.png)

Archive

Lo

![Lock module icon](/assets/lock-icon-UU3vOaKE.png)

Lock

Tr

![Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)

Transfer

Fire, path control Protect, asset protection 

Seven Blueprints 

## The risk, and the pattern that answers it

Each Blueprint names the exposure, the lead layer and the modules that deliver the control. Filter by lead layer to narrow the patterns that fit your environment.

All BlueprintsFIREVAULTFIRE+VAULTShowing 7 of 7 

Blueprint Tool

## Not sure which blueprint you need?

Answer a short series of questions on the problems, outcomes and assets that matter. We will recommend the right Control blueprint and the module mix that delivers it.

[Start the Blueprint Tool](/blueprint-tool)

[

**CP-01**FIRE-led

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

Primary modules

Firebreak Isolate Execute 

Lateral movement prevention across IT and OT

Read the Blueprint ](/control-blueprints/cp-01)[

**CP-02**FIRE-led

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

Primary modules

Firebreak Isolate Execute 

Live incident containment and recovery

Read the Blueprint ](/control-blueprints/cp-02)[

**CP-03**FIRE + VAULT

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

Primary modules

Validate Relay Lock 

Time-bounded vendor and supplier access

Read the Blueprint ](/control-blueprints/cp-03)[

**CP-04**FIRE-led

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

Primary modules

Firebreak Isolate Unlink 

Trust boundary enforcement between zones

Read the Blueprint ](/control-blueprints/cp-04)[

**CP-05**FIRE + VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

Primary modules

Firebreak Isolate Relay Execute 

OT and CNI connectivity with maintenance windows

Read the Blueprint ](/control-blueprints/cp-05)[

**CP-06**VAULT-led

### Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

Primary modules

Validate Lock Archive 

Audit-grade governance of access and evidence

Read the Blueprint ](/control-blueprints/cp-06)[

**CP-07**FIRE-led

### Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

Primary modules

Firebreak Isolate Validate Relay 

Aerospace, aviation and MRO ground networks with air-lock ingress control

Read the Blueprint ](/control-blueprints/cp-07)

Nine modules 

## Every Blueprint is built from these

Four FIRE modules control the path. Five VAULT modules protect the asset, the identity check and the evidence trail.

[![Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)

Firebreak FIRE 

Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.



](/control/modules/firebreak)[![Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)

Isolate FIRE 

Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.



](/control/modules/isolate)[![Relay module icon](/assets/relay-icon-CVhJDRO7.png)

Relay FIRE 

Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.



](/control/modules/relay)[![Execute module icon](/assets/execute-icon-kJl5Gtmk.png)

Execute FIRE 

Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.



](/control/modules/execute)[![Validate module icon](/assets/vault-icon-CD3Pv4ri.png)

Validate VAULT 

Checks whether a request, command or approval should proceed before access, action or transfer is allowed.



](/control/modules/validate)[![Archive module icon](/assets/archive-icon-B3rc85NY.png)

Archive VAULT 

Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.



](/control/modules/archive)[![Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)

Unlink VAULT 

Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.



](/control/modules/unlink)[![Lock module icon](/assets/lock-icon-UU3vOaKE.png)

Lock VAULT 

Restricts access through identity, authority, policy, permission and operational controls.



](/control/modules/lock)[![Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)

Transfer VAULT 

Controls how sensitive assets move into, out of or between protected environments through approved paths.



](/control/modules/transfer)

[Solutions in Control](/solutions/control) [How Control works](/control) [Firebreak® product](/firebreak)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Compose Control for your environment

Speak to a member of the team about combining these Blueprints around your estate.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up