Recent Breaches
Breaches
View All →
All Control Blueprints
FIRE-ledCP-01Controls the path

Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

All Blueprints
What it does

Stop ransomware moving, spreading or reaching the crown jewels.

Where it fits

Lateral movement prevention across IT and OT

Who uses it

Financial services, Healthcare, Public sector, Defence

CP-01 topology

How CP-01 stops the kill chain.

A FIRE-led pattern. The path between any compromised zone and the crown jewels is severed by default, opened only as a named event, and severed again on alert.

Grounded in MITRE ATT&CK TA0008, IEC 62443-3-3 SR 5.1 and NCSC ransomware guidance.

Z0

User and endpoint zone

Where the

User and endpoint zone zone

Where the foothold typically lands

IsolateLock

Named, scoped reach into core services

Z1

Core IT services

Identity, file,

Core IT services zone

Identity, file, mail, collaboration

FirebreakExecuteUnlink

Severed by default. Restored only as an approved Execute event.

Z2

Crown-jewel systems

Database, ERP,

Crown-jewel systems zone

Database, ERP, core record systems

OSS

Crown jewels · detail callout

Offline recovery vault

Tamper-evident copies, not reachable on the live network. The ransomware cannot touch them.

Modules & symbols

IsolateZone boundary
LockNamed access
FirebreakPhysical sever
ExecuteApproved action
UnlinkRemove trust
ConduitEnforced module path
┄┄┄
Crown jewelsOffline · detail callout
How it reads end to end

Firebreak physically breaks the connection path. Isolate separates the affected environment. Execute triggers the control action the moment risk is detected. Unlink removes the persistent dependencies and Lock holds the crown jewels behind identity controls that ransomware cannot reach.

Sector relevance
Financial servicesHealthcarePublic sectorDefence
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Build control around your environment

Talk to our team about composing this Blueprint for your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®