---
title: "Contain a Live Cyber Incident Physically | Cont… | Firevault"
description: "When an incident is live, containment has to be immediate and provable. See which paths need severing, what physical Control changes and the Blueprint behind…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-live-incidents#webpage",
      "url": "https://fire-vault.com/control-for-live-incidents",
      "name": "Contain a Live Cyber Incident Physically",
      "description": "When an incident is live, containment has to be immediate and provable. See which paths need severing, what physical Control changes and the Blueprint behind…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-live-incidents#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-live-incidents#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Contain a Live Cyber Incident Physically",
          "item": "https://fire-vault.com/control-for-live-incidents"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What is exposedWhy it existsThe path to controlWhat Control changesThe Control philosophyThe BlueprintQuestions

Control need · Live incident containment 

# In a live incident, the only question is how fast can you cut the path. 

Detection tells you something is wrong. Containment decides what it costs. If severing a connection means logging into a console, finding the right rule and hoping the change applies, containment is already competing with the attacker for time.

-   Written for executives
-   Incident response context
-   Leads to Blueprint CP-02
-   Provable severance

[See what Control changes](#change) [What is Control](/control)

The connection state today

## Containment depends on someone doing the right thing quickly

Severance method **Console and rule change**

Who can act **A small number of people**

Out of hours **Escalation and delay**

Proof of severance **Configuration screenshots**

Need → Control → Blueprint → Modules

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-B6Y7Qt9r.jpg)

01 What is exposed 

## During an incident, delay is the exposure.

The technical damage is usually decided in the first hour. These are the things that are exposed while the response is still being organised.

**01**

### The minutes before containment

Between detection and effective severance, the attacker keeps moving. Every additional route that stays live extends the eventual scope.

**Scope growth**

**02**

### The authority to act

Cutting a connection has business consequences, so people hesitate. Without a pre-agreed action, the decision escalates while the clock runs.

**Decision delay**

**03**

### The recovery position

If recovery copies are still reachable while the incident is live, the organisation can lose the thing it needs to restore from.

**Recovery at risk**

**04**

### The record of what happened

Regulators, insurers and boards ask what was severed and when. Configuration history is a weak answer to a question about physical state.

**Evidence gap**

02 Why the exposure exists 

## Containment was designed as a procedure, not as a capability.

Most incident response plans describe who should be called. Far fewer describe a mechanism that physically removes a connection in seconds and proves it afterwards.

The honest position 

### The plan assumes calm. Incidents are not calm.

Response documents are written in daylight by people with time. They are executed at night by people who are tired, incomplete in number and unsure how far the compromise has already reached. Anything that depends on flawless execution under those conditions will occasionally fail.

**Control the path, protect the asset.**

Reason 01

### Severance is a manual act

Pulling a path apart usually means editing configuration on the very estate that is under attack.

Reason 02

### Nobody wants to be wrong

Disconnecting a business system has a cost, so people wait for certainty that never arrives in time.

Reason 03

### Control planes share the estate

If the tools used to contain an incident sit inside the affected environment, they may already be compromised.

Reason 04

### Out of hours is the norm

Incidents are timed deliberately for weekends and holidays, when the fewest people are available to act.

Reason 05

### Evidence is an afterthought

Preserving logs competes with restoring service, and service usually wins.

Reason 06

### The plan is rarely rehearsed physically

Tabletop exercises test the conversation. They seldom test whether the path can actually be severed.

03 Which path needs controlling 

## Containment is a list of connections you have already agreed to cut.

Deciding this in advance is what removes hesitation on the night. Each of these is a business decision, taken once, in daylight.

The path or relationship Who uses it How it behaves today What Control governs 

**Internet and external boundary**Public services and remote users Severed by rule change under pressure Cut physically on signal, restored on approval 

**Affected zone to the rest of the estate**Applications and users in that zone Depends on segmentation holding Isolated at hardware level while the incident runs 

**Third-party and supplier links**Vendors and managed service providers Often forgotten during the first hours Closed automatically as part of the containment action 

**Recovery copies and evidence**Response and forensics teams Reachable from the affected environment Held with no live path, released under multi-party approval 

The Blueprint covers how these actions are triggered, sequenced and reversed, together with the evidence each step produces. This page is here to get the list agreed.

04 What physical Control changes 

## Containment becomes an action, not a project.

The point of physical Control during an incident is that severance is immediate, unambiguous and does not rely on the health of the systems under attack.

Connection state today

### Containment by configuration

The response team edits the environment while the attacker is inside it, then tries to confirm the change took effect.

-   • Severance takes as long as the console and the approval chain allow
-   • Actions are performed on infrastructure that may be compromised
-   • Supplier and remote paths are handled last, if at all
-   • Proof of containment is a configuration record
-   • Restoring service and preserving evidence pull in opposite directions

Connection state with Control

### Containment by physical severance

Pre-agreed paths are broken on signal from a control plane that sits outside the affected estate, and the state is visible rather than inferred.

-   ✓ Named paths severed immediately, including out of hours
-   ✓ A control plane that does not depend on the compromised environment
-   ✓ Supplier and remote links closed as part of the same action
-   ✓ A physical state that can be shown to insurers and regulators
-   ✓ Evidence and recovery copies preserved outside the blast radius

**Prevention fails occasionally. Containment has to work every time.**Connected when approved. Disconnected by default. 

05 The Control philosophy 

## Control the path, protect the asset.

Control treats connectivity as something to be governed deliberately. In an incident, that means the severance decision is made in advance and executed physically.

**01**

### Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

**02**

### Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

**03**

### Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

**04**

### Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

### Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

Need Control Blueprint Modules and Firebreak 

06 Where this goes next 

## The Blueprint for this need is CP-02 Contain Active Breaches 

With the containment list agreed, the Blueprint sets out how those actions are wired, triggered and reversed, and what each step leaves behind as evidence.

CP-02 · Lead layer FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

Modules the Blueprint leads with

[Firebreak](/control/modules/firebreak)[Isolate](/control/modules/isolate)[Execute](/control/modules/execute)

Applied to live incident containment and recovery. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

[Explore Blueprint CP-02](/control-blueprints/cp-02) [See Firebreak hardware](/firebreak)

Why it is worth exploring

### What you get from the Blueprint that this page does not cover

-   ✓ How severance is triggered, by whom and under what authority
-   ✓ The out-of-band control plane that stays reachable during an incident
-   ✓ Sequencing so containment does not destroy the evidence you need
-   ✓ How normal service is restored in a controlled, approved order
-   ✓ The audit record produced for regulators, insurers and the board

[Compare all Blueprints](/control-blueprints)

A different job

This page is about severing paths while an incident is running. Preserving the data and evidence you will rebuild from is a different job, and it belongs in Offline Secure Storage rather than in a containment plan.

[Protect the copies you rebuild from](/oss-for-ransomware-recovery)

Questions 

## What boards ask about containment.

The questions that come up when an incident response plan is reviewed rather than written.

Does this mean someone can shut down our business by mistake?

Severance actions are defined in advance, scoped to named paths and held under authority controls. The intention is to remove hesitation about agreed actions, not to give anyone a general off switch.

How quickly can a path be cut?

What if the attacker is already inside our management systems?

Is this only relevant to large organisations?

Need → Control → Blueprint 

## Agree the containment list. Then design how it fires.

CP-02 Contain Active Breaches sets out the architecture, the triggers and the evidence trail behind physical containment.

[Open Blueprint CP-02](/control-blueprints/cp-02) [Talk to a member of the team](/contact)