---
title: "Control Data Centre and Colocation Exposure | Firevault"
description: "Shared racks, remote hands and management networks widen exposure inside a data centre. See the paths that need governing, what physical Control changes and…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-data-centre-exposure#webpage",
      "url": "https://fire-vault.com/control-for-data-centre-exposure",
      "name": "Control Data Centre and Colocation Exposure",
      "description": "Shared racks, remote hands and management networks widen exposure inside a data centre. See the paths that need governing, what physical Control changes and…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-data-centre-exposure#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-data-centre-exposure#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control Data Centre and Colocation Exposure",
          "item": "https://fire-vault.com/control-for-data-centre-exposure"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What is exposedWhy it existsThe path to controlWhat Control changesThe Control philosophyThe BlueprintQuestions

Systems and access 

# You own the racks. You rarely own every route into them. 

Colocation gives you space, power and connectivity. It also brings shared fabric, provider engineers, remote hands and out-of-band management planes. Physical Control governs which of those routes exists, and when.

-   Colocation and shared racks
-   Out-of-band management
-   Remote hands
-   Cross-connects

[See what Control changes](#change) [What is Control](/control)

The connection state today

## Managed remotely, all of the time

Management plane **Always reachable**

Provider access **Contractual, not physical**

Cross-connects **Persistent**

Evidence **Provider tickets**

Need → Control → Blueprint → Modules

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-B6Y7Qt9r.jpg)

01 What is exposed 

## The estate is defended. The routes into it are assumed

Most data centre risk is not about the building. It is about the standing paths that make remote operation convenient.

**01**

### Out-of-band management

IPMI, BMC and console access are permanently reachable and often the least monitored plane in the estate.

**Management**

**02**

### Remote hands

Provider staff can physically touch equipment on request, with the record held by the provider.

**People**

**03**

### Shared fabric

Cross-connects, shared switching and provider services create routes you did not design.

**Network**

**04**

### Backup and replication links

Replication paths between sites stay open continuously, so an attack propagates with the data.

**Backups**

**05**

### Hardware lifecycle

Decommissioned disks and appliances leave the floor holding data that was never accounted for.

**Assets**

**06**

### Multi-tenant assumptions

Controls that hold in a private facility do not always hold where other tenants share the same space.

**Tenancy**

02 Why the exposure exists 

## Remote operation was the requirement

Colocation exists so that people do not have to travel. Every convenience that supports that becomes a standing route.

The pattern 

### Contracts govern behaviour, not connectivity

A colocation contract describes what the provider will and will not do. It does not remove the physical routes that make those actions possible.

**Control the path, protect the asset.**

01

### Management planes are built for access

Out-of-band exists so equipment can be reached when everything else has failed, which is exactly why it is valuable to an attacker.

02

### Provider boundaries are unclear

Responsibility is split, so neither party holds a complete list of the routes into the racks.

03

### Replication is always-on by design

Continuous replication is treated as resilience, even though it copies the incident as faithfully as the data.

04

### Audits look at the facility

Certifications cover the building and process, not the specific connections your estate depends on.

03 Which paths need controlling 

## Write down every route into the racks

Data centre exposure becomes manageable the moment the routes are named rather than assumed.

The path or relationship Who uses it How it behaves today What Control governs 

**Out-of-band management**Infrastructure team Always reachable Window opened for named maintenance, then closed 

**Provider remote hands**Facility staff On request, provider-logged Approved, time-bound and evidenced on your side too 

**Cross-connects and shared fabric**Provider and partners Persistent Documented crossings with physical enforcement 

**Replication to second site**Platform team Continuous Scheduled transfer with a disconnected gold copy 

**Vendor maintenance**Hardware suppliers Standing accounts Validated request, opened window, automatic close 

This is a list a provider cannot write for you. It describes your estate, not their facility.

04 What physical Control changes 

## Routes into the floor exist only when they are needed

Physical Control sits in the path itself, so a management plane or cross-connect is not simply firewalled, it is absent between windows.

Connection state today

### Before

Every convenience route is available at all times.

-   • Out-of-band reachable continuously
-   • Provider access governed by contract only
-   • Replication open around the clock
-   • Evidence held mainly by the provider

Connection state with Control

### After

Routes are opened deliberately and close on their own.

-   ✓ Management access exists only inside a maintenance window
-   ✓ Every crossing named, approved and recorded
-   ✓ A gold copy held physically disconnected
-   ✓ Your own evidence trail, independent of the provider

**If the route is not there, neither the provider nor an attacker can use it.**Connected when approved. Disconnected by default. 

05 The Firevault principle 

## Control is physical, or it is only a policy

Software can be told to deny a connection. Physical Control removes the connection itself, so the denial does not depend on the system behaving as configured.

**01**

### Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

**02**

### Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

**03**

### Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

**04**

### Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

### Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

Need Control Blueprint Modules and Firebreak 

06 Where this is designed 

## The Blueprint for this need is CP-04 Enforce Physical Segmentation 

Data centre and colocation exposure spans two patterns: enforcing the boundary between zones and keeping critical systems available while disconnected from unnecessary routes.

CP-04 · Lead layer FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

Modules the Blueprint leads with

[Firebreak](/control/modules/firebreak)[Isolate](/control/modules/isolate)[Unlink](/control/modules/unlink)

Applied to trust boundary enforcement between zones. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

[Open Blueprint CP-04](/control-blueprints/cp-04) [See Firebreak hardware](/firebreak)

Why it is worth exploring

### What you get from the Blueprint that this page does not cover

-   ✓ It shows how zones are separated in hardware rather than in configuration
-   ✓ It sets out maintenance and vendor windows that open and close on purpose
-   ✓ It defines the evidence you hold yourself, independent of the facility provider

[Compare all Blueprints](/control-blueprints)

[Also relevant · CP-05

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

Open CP-05 ](/control-blueprints/cp-05)

A different job

This page is about the routes into your racks. Holding a recovery copy that no route can reach is a different job, and that belongs in Offline Secure Storage rather than in replication.

[Hold a disconnected gold copy](/oss-for-ransomware-recovery)

Questions 

## What infrastructure teams ask

The questions that come up when colocation exposure is reviewed properly.

Does this mean travelling to site?

No. Access is still remote. It exists inside a window opened for a named person and purpose, rather than continuously.

Is our provider certification not enough?

What happens in an emergency?

Can we keep replication?

Need → Control → Blueprint 

## List the routes into the floor. Then govern them.

CP-04 Enforce Physical Segmentation and CP-05 Protect Critical Infrastructure set out how those routes are separated, opened and evidenced.

[Open Blueprint CP-04](/control-blueprints/cp-04) [Talk to a member of the team](/contact)