Protect Critical Infrastructure
Keep critical systems available, controlled and disconnected from unnecessary exposure.
Keep critical systems available, controlled and disconnected from unnecessary exposure.
OT and CNI connectivity with maintenance windows
Energy, Critical infrastructure, Defence, Manufacturing
How CP-05 protects critical infrastructure.
A FIRE+VAULT pattern for OT and CNI. Process zones run normally; maintenance and supervisory reach exist only through governed, time-bound conduits.
Grounded in IEC 62443-3-3 (FR 5, FR 7), NIS2 Annex I and the NCSC Cyber Assessment Framework B4.
Enterprise IT
Office, mail,
Office, mail, ERP, identity
IT-to-OT conduit is severed by default and opened as a named window.
Supervisory and engineering
SCADA, historian,
SCADA, historian, engineering workstations
Engineering reach is scoped, approved and verified.
Process control and field
PLCs, RTUs,
PLCs, RTUs, HMIs, sensors and actuators
Crown jewels · detail callout
Operational evidence and golden image vault
Operational records and golden PLC images sealed offline for safe recovery and audit.
Modules & symbols
Modules in this Blueprint
How the CP-05 pattern composes.
- 1
FirebreakFIREPhysically breaks the connection path so the attack cannot continue.
- 2
IsolateFIRESeparates the affected environment into a controlled zone.
- 3
RelayFIREOpens a temporary, time-bound window for an approved purpose.
- 4
ExecuteFIREFires the control action the moment a signal demands it.
Firebreak controls connectivity at the physical layer. Isolate separates operational systems. Relay opens approved maintenance, patching or supervisory windows. Execute can revoke access instantly. Transfer governs data movement, Archive preserves operational evidence and Lock holds access tight.
Related Blueprints
Compose alongside.
Control Third-Party Access
Give third parties access without giving them a permanent doorway.
View BlueprintStop Kill-Chain Ransomware
Stop ransomware moving, spreading or reaching the crown jewels.
View BlueprintContain Active Breaches
When prevention fails, containment must be physical, immediate and provable.
View Blueprint


Build control around your environment
Talk to our team about composing this Blueprint for your estate.
Takes about 2 minutes. No account needed.