Control Module - FIRE

FV-Execute. Actions that happen when they should.

Execute initiates control actions in response to policy, approval, schedule, incident state or supervisory override. The decision to act is recorded with the action, so there is no ambiguity about why the environment changed.

Back to Control
Control at a glance
FV-Execute module artwork: initiate control actions on policy, approval or schedule

Control removes the physical path. Blueprints show where each module sits.

The exposure in numbers
01
Actions follow defined conditions, not informal practice
TriggeredActions follow defined conditions, not informal practice
02
Sensitive actions require the right approval pattern
ApprovedSensitive actions require the right approval pattern
03
Every action is paired with its reason and approver
RecordedEvery action is paired with its reason and approver
04
Where appropriate, actions have a defined undo path
ReversibleWhere appropriate, actions have a defined undo path
The Problem

Critical actions decided in the moment, by whoever is closest.

01

Ad-hoc response

When a control action is taken by the person who happens to be on shift, the rationale lives only in their memory and the outcome is harder to reason about later.

02

Missed conditions

Actions that should follow a schedule, a state change or an upstream signal often do not, because nothing systematic connects the signal to the action.

03

No supervisory layer

Without an explicit supervisory override, a runaway automation or a faulty trigger has no clean way to be paused, redirected or stopped.

Control Module - FIRE

An action without a reason is a fact you will struggle to defend. Execute records both, together, every time.

The Scenario

Scenario: a scheduled lockdown that does not depend on memory

A weekly maintenance pattern requires several systems to be placed into a restricted state outside business hours. Rather than relying on individuals to remember and act, Execute initiates the lockdown on schedule, with the policy that authorises it and the supervisor who can override it both recorded against the action. The same pattern applies in reverse when the window ends, and the evidential record shows what happened and why.

"Execute is the discipline of treating an action as a decision, not as a habit."

FV-Execute in placement

Where Execute requires an approved action.

Execute is the gate around any change that matters. Nothing destructive, privileged or boundary-altering happens without a named approver and a recorded decision.

Grounded in IEC 62443-3-3 SR 1.5 Authenticator Management, NIST CSF PR.AC-4 and ISO 27001 A.5.18, A.8.18.

Inputs ─┐Telemetry ─┐
FV-Execute module icon

FV-Execute

Control layer

┌─ Outputs┌─ Control
01SR 5.1

Firebreak open and close events

Every change to the physical conduit state is an approved Execute event, not a console click.

02PR.AC-4

Privileged change to OT assets

Engineering changes against PLCs, RTUs and HMIs require multi-party approval before the path is opened.

03PR.IP-9

Restore from offline vault

Restoration from the offline vault is an explicit, recorded Execute decision with quorum approval.

04A.5.18

Boundary policy changes

Changes to the zone and conduit definitions themselves are governed actions, not silent edits.

Relies on · prerequisites

  • Independent approver identities that cannot be impersonated from the system being changed
  • Recorded intent for every action, not just an audit log of the action
  • Quorum policy that survives a single compromised admin

Pairs with · companion modules

FV-Firebreak module iconFirebreakFV-Relay module iconRelayFV-Lock module iconLockFV-Validate module iconValidate

Featured In

TechRadar Pro logoYahoo Finance logoChannel Insider logoSecurity Buyer logoSecurityBrief logo

Capabilities

What you get with every deployment

01

Condition-led initiation

Actions begin because a defined condition was met, not because somebody remembered.

02

Approval where it matters

Sensitive actions require the right approval before execution rather than after the fact.

03

Incident-aware

Execute responds to incident state so containment, isolation and lockdown actions can be carried out at machine speed within agreed bounds.

04

Supervisory override

An explicit supervisory layer can pause, redirect or stop an action when human judgement needs to take over.

05

Scoped authority

Each action is constrained to the systems and operations the policy permits.

06

Decision and execution paired

The reason for the action and the action itself are recorded together through Archive.

Demo to Live

Adoption Guide

Step 1

Catalogue the actions

List the control actions that matter, including their owners, scopes and current triggers.

Step 2

Define conditions and approvals

For each action, agree the policy, schedule, incident state and approval pattern that should govern it.

Step 3

Pilot with one workflow

Move one action onto Execute end-to-end, including the supervisory override and the evidential record.

Step 4

Operate and review

Run Execute as the initiation layer for control actions and review patterns through Archive on a regular cadence.

Step 1

Catalogue the actions

List the control actions that matter, including their owners, scopes and current triggers.

Step 2

Define conditions and approvals

For each action, agree the policy, schedule, incident state and approval pattern that should govern it.

Step 3

Pilot with one workflow

Move one action onto Execute end-to-end, including the supervisory override and the evidential record.

Step 4

Operate and review

Run Execute as the initiation layer for control actions and review patterns through Archive on a regular cadence.

Questions

Frequently Asked