---
title: "What Systems Do You Need to Control? | Firevault Control"
description: "Five systems and access needs answered by Firevault Control: critical system exposure, lateral movement, third-party access, AI systems and data centre…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for#webpage",
      "url": "https://fire-vault.com/control-for",
      "name": "What Systems Do You Need to Control?",
      "description": "Five systems and access needs answered by Firevault Control: critical system exposure, lateral movement, third-party access, AI systems and data centre…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "/"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Solutions",
          "item": "/solutions"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Control",
          "item": "/solutions/control"
        },
        {
          "@type": "ListItem",
          "position": 5,
          "name": "By need",
          "item": "/control-for"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Start from the need 

# What systems do you need to control ?

These five needs are about systems, networks and access rather than files. Each one hands off to the Control Blueprint that governs it physically. If your need is about data and digital assets instead, that journey belongs to Offline Secure Storage®.

-   Critical systems
-   Lateral movement
-   Third-party access
-   AI systems
-   Data centres

[See the five control needs](#needs) [I need to protect data instead](/oss-for)

![Security analyst reviewing an isolated workstation with disconnected cables](/assets/hero-square-analyst-DI5B7V_E.jpg)

5

Systems and access needs covered on this page

7

Control Blueprints behind them

CP-01 to CP-07

Physical

Separation enforced in hardware, not configuration

Zero

Standing paths left open between separated zones

01 The same control every time 

## Three steps, whatever you are controlling.

The needs below differ in which path is at risk, not in how the control works. Each page applies the same three steps to the systems in that setting.

**01**

### Name the path, not just the perimeter

Every incident travels a route between systems, sites or suppliers. The route is what needs governing.

**02**

### Break the path in hardware

Control removes the standing connection so the route does not exist until someone opens it.

**03**

### Open it for a witnessed window

Work happens inside a defined window, the session is evidenced, and the path closes again afterwards.

02 Systems and access 

## What you need to control, not just store.

Each need names the path most organisations live with, then the practical difference once that path is governed physically by a Control Blueprint.

[

**06**Blueprint CP-04 and CP-05

### Control critical systems and network exposure

A boundary enforced only by configuration can be undone by a rule change or a stolen credential.

What changes

IT and OT are separated physically, so the path only exists when it is opened deliberately.

Read the detail ](/control-for-critical-systems)[

**07**Blueprint CP-01 and CP-02

### Contain ransomware and lateral movement

A compromise in one environment should not automatically provide a path to the next.

What changes

Movement stops at a physical break rather than at a firewall rule.

Read the detail ](/control-for-lateral-movement)[

**08**Blueprint CP-03

### Control third-party and remote access

Vendor, maintenance and support connections outlive the projects that created them.

What changes

Access exists for a defined window, is witnessed, and closes physically afterwards.

Read the detail ](/control-for-third-party-access)[

**09**Blueprint AI Control patterns

### Control AI systems and infrastructure

Agents inherit standing credentials and act at machine speed, so their reach is rarely the reach intended.

What changes

The reach of an agent is bounded by hardware, not by prompt or policy alone.

Read the detail ](/control-for-ai-systems)[

**10**Blueprint CP-04 and CP-05

### Control data centre and colocation infrastructure

The building can be physically secure while the paths inside it remain continuously exposed.

What changes

Cross-connects and management planes are opened on demand and closed by default.

Read the detail ](/control-for-data-centre-exposure)

03 Data and digital assets 

## If the need is a file, not a system, start with #OSS.

Personal records, intellectual property, ransomware recovery copies, customer data and long-term digital assets are held on physically disconnected hardware by Offline Secure Storage®.

[Data needs 01 to 05](/oss-for) [Control Blueprints](/control-blueprints)

Full index 

## Every Control by Firevault page

Every need, industry, utilities and blueprint page for Control by Firevault, in one place. Each page sets out the data paths it governs and the evidence it produces.

### By need

-   [Separate critical systems](/control-for-critical-systems)
-   [IT and OT convergence](/control-for-it-ot-convergence)
-   [IT networks](/control-for-it-networks)
-   [OT environments](/control-for-ot-environments)
-   [Stop lateral movement](/control-for-lateral-movement)
-   [Ransomware containment](/control-for-ransomware-containment)
-   [Contain a live incident](/control-for-live-incidents)
-   [Insider threat](/control-for-insider-threat)
-   [Third-party access](/control-for-third-party-access)
-   [Supply chain risk](/control-for-supply-chain-risk)
-   [Management plane](/control-for-management-plane)
-   [AI systems](/control-for-ai-systems)
-   [Data centre exposure](/control-for-data-centre-exposure)

### By industry

-   [All industries](/control-for-industry)
-   [Critical infrastructure](/control-for-critical-infrastructure)
-   [Banking](/control-for-banking)
-   [Colocations and data centres](/control-for-colocations)
-   [Construction](/control-for-construction)
-   [Defence](/control-for-defence)
-   [Education](/control-for-education)
-   [Energy](/control-for-energy)
-   [Healthcare](/control-for-healthcare)
-   [Oil and gas](/control-for-oil-and-gas)
-   [Public sector](/control-for-public-sector)
-   [Retail](/control-for-retail)
-   [Telecoms](/control-for-telecoms)
-   [Telecommunications compliance](/control-for-telecommunications)
-   [Water](/control-for-water)

### Utilities

-   [Utilities overview](/control-for-utilities)
-   [Utilities: water](/control-for-utilities-water)
-   [Utilities: gas](/control-for-utilities-gas)
-   [Utilities: renewables](/control-for-utilities-renewables)

### Blueprints and modules

-   [All Control Blueprints](/control-blueprints)
-   [CP-01](/control-blueprints/cp-01)
-   [CP-02](/control-blueprints/cp-02)
-   [CP-03](/control-blueprints/cp-03)
-   [CP-04](/control-blueprints/cp-04)
-   [CP-05](/control-blueprints/cp-05)
-   [CP-06](/control-blueprints/cp-06)
-   [CP-07](/control-blueprints/cp-07)
-   [The nine Control modules](/control/nine-modules)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up