---
title: "Separate IT and OT Networks Physically | Control | Firevault"
description: "Segmentation that lives in configuration can be undone. See which paths between IT and OT need controlling, what physical Control changes and the Blueprint…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-critical-systems#webpage",
      "url": "https://fire-vault.com/control-for-critical-systems",
      "name": "Separate IT and OT Networks Physically",
      "description": "Segmentation that lives in configuration can be undone. See which paths between IT and OT need controlling, what physical Control changes and the Blueprint…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-critical-systems#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-critical-systems#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Separate IT and OT Networks Physically",
          "item": "https://fire-vault.com/control-for-critical-systems"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What is exposedWhy it existsThe path to controlWhat Control changesThe Control philosophyThe BlueprintQuestions

Control need · Segmentation that holds 

# Your network diagram shows a boundary. Your cabling may not. 

Segmentation is usually described as a set of zones and enforced as a set of rules. The two are not the same thing. If a credential, a misconfiguration or a forgotten route can carry traffic across a boundary, that boundary exists on the diagram rather than in the estate.

-   For operations and engineering leaders
-   IT and OT context
-   Leads to Blueprint CP-04
-   Enforced in hardware

[See what Control changes](#change) [What is Control](/control)

The connection state today

## Zones defined in configuration, tested rarely

Boundary enforcement **Firewall rules**

Rule review **Periodic at best**

Engineering access **Persistent**

Proof the zone holds **A diagram**

Need → Control → Blueprint → Modules

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-B6Y7Qt9r.jpg)

01 What is exposed 

## A boundary you cannot demonstrate is a boundary you cannot rely on.

Where operational systems sit behind logical separation only, the exposure is easy to describe and uncomfortable to look at.

**01**

### Systems that cannot defend themselves

Controllers and instruments running unpatchable software were designed for isolation, then connected for visibility and reporting.

**Legacy exposure**

**02**

### Shared administrative tooling

When identity, monitoring or jump servers span both sides of the boundary, a compromise on one side inherits the other.

**Shared control plane**

**03**

### Routes nobody documented

Engineering laptops, temporary links and supplier connections create crossings that never appear in the architecture record.

**Undocumented paths**

**04**

### Consequences measured physically

In operational environments, the outcome of a crossing is not data loss. It is production stoppage, safety risk and service failure.

**Physical consequence**

02 Why the exposure exists 

## Convergence delivered real benefits and quietly removed the gap.

Operational networks were connected for good commercial reasons. The problem is that the protection they previously relied on was physical, and what replaced it was configuration.

The honest position 

### You cannot configure your way back to an air gap.

Firewalls, VLANs and rule sets are valuable, and they are still configuration. Configuration is changed by people, inherited from previous teams and occasionally wrong. A boundary that matters to safety and continuity deserves an enforcement mechanism that does not depend on a rule being correct on the day.

**Control the path, protect the asset.**

Reason 01

### Reporting needed a route

Production data had to reach the business, and the simplest way to deliver it was a permanent connection.

Reason 02

### Remote support became standard

Equipment vendors expect to reach their kit, and that expectation was met with standing access.

Reason 03

### Rule sets accumulate

Firewall policies grow over years until no one is confident about what any individual rule still permits.

Reason 04

### Operational systems cannot be patched freely

Availability requirements mean known vulnerabilities remain in place far longer than in corporate IT.

Reason 05

### Two teams, two languages

IT and operations measure risk differently, so boundary decisions fall between the two.

Reason 06

### The gap was never replaced

When the air gap was removed, nothing physical was put in its place. Only policy was.

03 Which path needs controlling 

## Segmentation becomes real when each crossing has an owner.

Rather than debating zone models, start by naming the crossings that exist today and deciding how each one should behave.

The path or relationship Who uses it How it behaves today What Control governs 

**Corporate IT to operational network**Reporting, planning and business systems Permanent route governed by rules Physically closed by default, opened only for defined exchange 

**Engineering and maintenance access**Internal engineers and equipment vendors Standing access through shared jump hosts Scheduled window, named person, closed automatically 

**Operational data to the business**Historians, dashboards and analytics Continuous two-way connectivity One directional, defined route for the data that must flow 

**Shared identity and management tooling**IT administration and monitoring Spans both environments Separated, so a compromise on one side does not inherit the other 

Zone models, level mapping and conduit design belong in the Blueprint. This page is about agreeing which crossings exist and which of them should stop being permanent.

04 What physical Control changes 

## The boundary stops being a rule and starts being a fact.

Control puts a physical enforcement point on the crossings you have named, so the boundary holds regardless of what happens in configuration.

Connection state today

### Logical segmentation

Zones exist in policy and are enforced by devices that can be reconfigured, misconfigured or traversed with valid credentials.

-   • The boundary depends on rules being correct today and tomorrow
-   • Valid credentials can cross a boundary that policy says is closed
-   • Undocumented routes accumulate without being noticed
-   • Assurance is an architecture document rather than a state
-   • Operational risk is carried by a configuration change process

Connection state with Control

### Physically enforced segmentation

Crossings exist only when they have been opened for a purpose, and the closed state is a property of the hardware rather than of a rule.

-   ✓ No permanent path between corporate IT and operational systems
-   ✓ Data flows on a defined route, in the direction it is meant to travel
-   ✓ Engineering and vendor access opened on schedule and closed automatically
-   ✓ A boundary that survives a misconfiguration or a stolen credential
-   ✓ Segmentation you can demonstrate to a regulator or an auditor

**In operational environments, the consequence of a crossing is measured in downtime and safety, not in records.**Connected when approved. Disconnected by default. 

05 The Control philosophy 

## Control the path, protect the asset.

Control restores the discipline that operational environments used to get from physical separation, without giving up the visibility that convergence delivered.

**01**

### Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

**02**

### Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

**03**

### Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

**04**

### Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

### Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

Need Control Blueprint Modules and Firebreak 

06 Where this goes next 

## The Blueprint for this need is CP-04 Enforce Physical Segmentation 

With the crossings agreed, the Blueprint sets out the zone architecture, the enforcement points and the phased deployment that gets there without interrupting production.

CP-04 · Lead layer FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

Modules the Blueprint leads with

[Firebreak](/control/modules/firebreak)[Isolate](/control/modules/isolate)[Unlink](/control/modules/unlink)

Applied to trust boundary enforcement between zones. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

[Explore Blueprint CP-04](/control-blueprints/cp-04) [See Firebreak hardware](/firebreak)

Why it is worth exploring

### What you get from the Blueprint that this page does not cover

-   ✓ The zone and conduit architecture behind physically enforced segmentation
-   ✓ Where enforcement sits on each crossing and what it governs
-   ✓ How scheduled maintenance and vendor windows are handled
-   ✓ A phased deployment designed around production constraints
-   ✓ Evidence aligned to sector expectations and recognised frameworks

[Compare all Blueprints](/control-blueprints)

A different job

This page is about the crossings between IT and OT. Protecting the engineering records, configurations and gold copies behind that boundary is a different job: Offline Secure Storage keeps them physically disconnected.

[Hold engineering records offline](/oss-for-ransomware-recovery)

Questions 

## What operations leaders ask.

The questions that decide whether physical segmentation is practical in a live environment.

Will this interrupt production?

Deployment is phased and designed around operational constraints. Control sits at boundaries rather than inside control systems, so programs, logic and protocols are not modified.

We still need data out of the plant. Does that stop?

How do engineers and vendors work?

Is this the same as the Blueprint?

Need → Control → Blueprint 

## Name the crossings. Then design the boundary.

CP-04 Enforce Physical Segmentation shows how zones are separated in hardware and how approved crossings are governed.

[Open Blueprint CP-04](/control-blueprints/cp-04) [Talk to a member of the team](/contact)