---
title: "Stop Ransomware Spreading Across Your Network |… | Firevault"
description: "Ransomware spreads along connections that already exist. See which paths need controlling, what physical Control changes, and the Blueprint that delivers it."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-lateral-movement#webpage",
      "url": "https://fire-vault.com/control-for-lateral-movement",
      "name": "Stop Ransomware Spreading Across Your Network |…",
      "description": "Ransomware spreads along connections that already exist. See which paths need controlling, what physical Control changes, and the Blueprint that delivers it.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-lateral-movement#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-lateral-movement#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Stop Ransomware Spreading Across Your Network |…",
          "item": "https://fire-vault.com/control-for-lateral-movement"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What is exposedWhy it existsThe path to controlWhat Control changesThe Control philosophyThe BlueprintQuestions

Control need · Ransomware containment 

# Ransomware does not break in everywhere. It travels. 

One compromised laptop rarely ends a business. What ends a business is the set of connections that let the compromise reach finance, backups, production and the recovery copies on the same night. Control governs those connections so that a single foothold stays a single foothold.

-   Board-level explanation
-   No architecture required to follow
-   Leads to Blueprint CP-01
-   Physical, not policy

[See what Control changes](#change) [What is Control](/control)

The connection state today

## Everything can reach everything, quietly

Office to server estate **Always live**

Server estate to backups **Always live**

Admin tooling **Reaches every zone**

Recovery copies **On the same network**

Need → Control → Blueprint → Modules

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-B6Y7Qt9r.jpg)

01 What is exposed 

## The damage is decided by what the first machine can reach.

Before any technology conversation, it is worth being honest about what is currently within reach of an ordinary compromised endpoint.

**01**

### The systems that run the day

Finance, case management, scheduling, production planning. Reachable from ordinary user devices because that is what makes them useful.

**Operational stoppage**

**02**

### The backups you would rely on

Backup servers usually sit on the same network as the systems they protect, with credentials that can reach both. Attackers target them first.

**Recovery removed**

**03**

### The administrative routes

Jump boxes, remote management tools and monitoring agents cross every boundary by design. A stolen credential inherits that reach.

**Privilege inheritance**

**04**

### The evidence you will need

Logs and audit records held on the same estate can be encrypted or altered along with everything else, which turns a recovery into an investigation.

**Evidence loss**

02 Why the exposure exists 

## Nobody designed this. It accumulated.

The paths that ransomware uses were almost always built for a good reason, then left open long after that reason ended. This is a governance problem before it is a security problem.

The honest position 

### Connectivity was the goal for twenty years. It was never revisited.

Every integration, every remote support arrangement and every convenience shortcut added a route. None of them came with an expiry date. The estate now carries more standing connectivity than any single person can describe, which is precisely what makes lateral movement fast.

**Control the path, protect the asset.**

Reason 01

### Convenience became permanent

A temporary connection opened for a project or a migration is almost never closed once the work finishes.

Reason 02

### Segmentation lives in software

Firewall rules and VLANs are configuration. Configuration can be changed, misapplied or bypassed with valid credentials.

Reason 03

### Backups sit inside the blast radius

If the recovery copy is reachable from the environment it protects, it shares that environment's fate.

Reason 04

### Nobody owns the map

Connections are added by different teams over years. There is rarely one person who can list every live path.

Reason 05

### Speed favours the attacker

Detection and response take minutes at best. Encryption across an open estate takes less.

Reason 06

### Trust is inherited

Systems trust each other because they always have, not because that trust was ever assessed against today's risk.

03 Which path needs controlling 

## Four connections decide how far an incident travels.

This is the part most organisations have never written down. Naming the paths is what turns an anxious conversation into a decision that can be made.

The path or relationship Who uses it How it behaves today What Control governs 

**User estate to core systems**Every employee device Standing connection, always available Reachable only through approved routes, closed by default outside them 

**Core systems to backup and recovery**Backup software and administrators Live path with credentials that reach both sides Recovery copies held with no live path from production 

**Administrative and remote management**Internal IT and outsourced support Persistent reach across every zone Opened for a named person and purpose, closed on schedule 

**Zone to zone inside the estate**Applications and integrations Governed by firewall configuration Enforced physically, so a rule change cannot re-open it 

This page deliberately stops at the level of paths and relationships. The zone architecture, module placement and deployment sequence sit in the Blueprint, where the technical detail belongs.

04 What physical Control changes 

## The change is in the connection state, not in your software.

Control does not add another agent to the estate or ask your teams to work differently. It changes whether a connection physically exists when nobody has asked for it.

Connection state today

### Standing connectivity

Paths exist continuously and are restrained by configuration. Containment depends on someone noticing an incident and acting correctly under pressure.

-   • Every route is available at all times, including out of hours
-   • Containment relies on detection speed and human response
-   • Backups and recovery copies share the estate they protect
-   • Segmentation can be undone by a credential or a rule change
-   • The board is asked to trust a diagram rather than a state

Connection state with Control

### Governed connectivity

The path is physically absent unless it has been opened for a stated purpose. Containment is a property of the architecture rather than a reaction to an alarm.

-   ✓ No standing path between the user estate and the crown jewels
-   ✓ Recovery copies with no live route from production
-   ✓ Support and administrative access opened on approval and closed on schedule
-   ✓ Boundaries that survive a misconfiguration or a stolen credential
-   ✓ A connection state that can be shown, not just described

**A foothold is survivable. A foothold with reach is what becomes an incident.**Connected when approved. Disconnected by default. 

05 The Control philosophy 

## Control the path, protect the asset.

Control is a way of thinking about connectivity before it is a set of products. These four principles apply to every Control need, and they are what the Blueprints put into practice.

**01**

### Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

**02**

### Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

**03**

### Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

**04**

### Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

### Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

Need Control Blueprint Modules and Firebreak 

06 Where this goes next 

## The Blueprint for this need is CP-01 Stop Kill-Chain Ransomware 

Once the paths are agreed, the Blueprint turns the decision into an architecture: where the boundaries sit, what governs each crossing and how the pattern is deployed without interrupting operations.

CP-01 · Lead layer FIRE

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

Modules the Blueprint leads with

[Firebreak](/control/modules/firebreak)[Isolate](/control/modules/isolate)[Execute](/control/modules/execute)

Applied to lateral movement prevention across it and ot. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

[Explore Blueprint CP-01](/control-blueprints/cp-01) [See Firebreak hardware](/firebreak)

Why it is worth exploring

### What you get from the Blueprint that this page does not cover

-   ✓ The zone architecture that separates the user estate, core systems and recovery copies
-   ✓ Where each module sits on the path and what it governs at that point
-   ✓ How approved crossings are opened and closed without manual work
-   ✓ A deployment sequence that can be phased alongside live operations
-   ✓ The evidence the pattern produces for auditors, insurers and the board

[Compare all Blueprints](/control-blueprints)

A different job

This page is about the paths ransomware travels along. Keeping a clean recovery copy is a different job: Offline Secure Storage holds selected copies physically outside the connected estate so recovery does not depend on the network under attack.

[Hold recovery copies beyond reach](/oss-for-ransomware-recovery)

Questions 

## What decision makers ask first.

Straight answers for the people who have to approve the work rather than run it.

Is this a replacement for our firewalls and endpoint tooling?

No. Those tools keep doing their job. Control sits underneath them and governs whether the physical path exists at all, so that a failure in software does not become unlimited reach.

Will this slow the business down?

How much of our estate has to change?

How is this different from reading the Blueprint directly?

Need → Control → Blueprint 

## You have the paths. The Blueprint has the architecture.

CP-01 Stop Kill-Chain Ransomware shows how these connections are governed in practice, module by module and boundary by boundary.

[Open Blueprint CP-01](/control-blueprints/cp-01) [Talk to a member of the team](/contact)