---
title: "Control Firebreak Module: cut network paths | Firevault"
description: "Firebreak severs network paths at Layer 1 in seconds, containing lateral movement before a breach can spread across IT or OT estates."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control/modules/firebreak#webpage",
      "url": "https://fire-vault.com/control/modules/firebreak",
      "name": "Control Firebreak Module: cut network paths",
      "description": "Firebreak severs network paths at Layer 1 in seconds, containing lateral movement before a breach can spread across IT or OT estates.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/2a9868c7-789c-40f7-bb9f-e70f75005876/og-control-firebreak.png"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control/modules/firebreak#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control/modules/firebreak#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control",
          "item": "https://fire-vault.com/control"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Modules",
          "item": "https://fire-vault.com/control/modules"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Control Firebreak Module: cut network paths",
          "item": "https://fire-vault.com/control/modules/firebreak"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Control Module - FIRE 

# FV-Firebreak. Physically open or close the path. 

Firebreak governs whether a connection path exists at all. When the path is severed, the attack has no route to progress. Containment is delivered by removing the physical connection, not by inspecting traffic or trusting a configuration to hold.

Schedule a Demo[Back to Control](/solutions/control)

Control at a glance 

![FV-Firebreak module artwork: physically open or close the connection path](/__l5e/assets-v1/37647b48-3ccb-4b8a-8244-16e01f003108/control-module-firebreak-hero.png)

Control removes the physical path. Blueprints show where each module sits.

Exposure

How it worksExplore moreQuestions

The exposure in numbers 

01 

Severance happens at the connection itself, not in a rule set

Physical Severance happens at the connection itself, not in a rule set 

02 

Network paths remaining once Firebreak is engaged

Zero Network paths remaining once Firebreak is engaged 

03 

Every open and close requires explicit approval

Authorised Every open and close requires explicit approval 

04 

Each state change is recorded for evidential review

Auditable Each state change is recorded for evidential review 

The Problem 

## Filtering a path is not the same as removing it.

01 

### Filtering trusts the filter

Firewall rules, ACLs and segmentation policies assume the enforcement plane is intact. A compromised management plane can quietly relax the same rules that are supposed to contain the attack.

02 

### Logical boundaries leak

VLANs, overlays and software-defined boundaries can be bypassed through misconfiguration, trunk abuse or trust inheritance. The separation only exists while every layer behaves as intended.

03 

### Reaction is too slow

Emergency rule changes need authoring, testing and propagation. An attacker moving laterally does not wait for the change window to complete.

Control Module - FIRE

> If the path can be filtered, it can be unfiltered. If the path is physically removed, there is nothing left to negotiate with.

The Scenario

### Scenario: cutting the route during a live incident

Detection confirms unauthorised activity reaching from a corporate segment into an operations environment. Rather than authoring emergency firewall rules and waiting for them to propagate, the duty engineer requests a Firebreak action on the inter-segment path. With co-approval, the path is physically opened. Traffic stops because the connection no longer exists. Investigation continues on each side without further risk of progression, and the path remains severed until the environment is verified clean and a controlled restoration is approved.

"Firebreak is the moment you stop debating containment and you simply remove the road."

FV-Firebreak in placement 

## Where Firebreak physically severs the path.

Firebreak is engaged at every conduit where a severed path is the only acceptable default. It removes the connection itself, not the rule about the connection.

Grounded in IEC 62443-3-3 SR 5.1 Network Segmentation, NIST CSF PR.AC-5 and NCSC Cyber Assessment Framework B4.

Inputs ─┐ Telemetry ─┐ 

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)

FV-Firebreak

FIRE layer

┌─ Outputs ┌─ Control 

01 SR 5.1 

Internet to enterprise conduit

Severs the inbound path when no legitimate traffic is expected. The path comes up only for an authorised window.

02 SR 5.1 / SR 5.2 

IT to OT boundary

Removes the standing route between corporate IT and operational technology. An IT compromise has nowhere to go.

03 PR.PT-5 

Production to recovery vault

Holds the path to offline recovery copies severed at rest. Ransomware cannot encrypt what it cannot reach.

04 SR 1.13 

Vendor maintenance conduit

Default-severed third-party reach. Opens only as a named, time-bound session and closes on schedule.

Relies on · prerequisites

-   Physical interruption hardware in the conduit, not just a routing change 
-   Out-of-band authorisation channel that survives an IT compromise 
-   Tamper-evident audit of every open and close event 

Pairs with · companion modules

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay ![FV-Execute module icon](/assets/execute-icon-kJl5Gtmk.png)Execute ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 

Featured In

[![TechRadar Pro logo](/press/techradar-pro-logo.svg) ](https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough "Read about Firevault on TechRadar Pro") [![Yahoo Finance logo](/assets/yahoo-finance-logo-white-aNkUpCH7.png) ](https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html "Read about Firevault on Yahoo Finance") [![Channel Insider logo](/assets/channel-insider-logo-white-CFFo4iu7.png) ](https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/ "Read about Firevault on Channel Insider") [![Security Buyer logo](/assets/security-buyer-logo-white-o6oIaBWz.png) ](https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/ "Read about Firevault on Security Buyer") [![SecurityBrief logo](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAT8AAAA1CAYAAAA3Sux5AAAL+0lEQVR4nO2dT4gdSRnAf++Ri5ODEcTJvoB0PIjgxdkFlejsTkBExFlhzWhEWPDkYWfXxZfoRSK73vKPJQrePHjamLhg5iAswrzNkFVyyBz04kqYJ2tmM6CQS2bxss9Dvcrr6emu+qq7ql/3e/WDZv50dVW9ftVff1Xfn+qMRiMiEY/cBpZTf78M/HpKfYlECukIhd8Z4IalzBbwIjCs2KdIO1kHfmU436mrI5FIih5wKvX3fWAb7MKvrFq4BTxb8tpI++gBDwTlogCM1IFEWVvr5vxzBSX0qsyHl8fX71SoI9IeXvVUz8hyLHlqJ1LMEmrpIn3fH6I0+6ZzGdVfm+ADOJ4Vfn1g02NnEqoJ0Ug7+Jyw3ELFdr5f8frQPMQuwCXHLdSzUzc94B4H12wBFlFLGpdr75Gc2yj5JSYt/NYJ9+GiAJxtficstx+0F9Nn0VM9q6hZ04jqLwwX3rScdxIuNZI1sonQwq+HebHaB1EAzi43BWWeDt6L2eQxShOsA2cB0gDWKdlvLfzu+euLkbhmM7t0gI2Cc+cYW9gipVgF7tTQzl4NbfimrNL2UAs/ibq+gRKWnczRRQ1uCW+59jDSKp5HjYkT40OPlyvT7NSMcIrwU2CbUWMrcPuhyMqtLnCzi+yGrqEGdt7UdYQa3BI3hkTS00jr2R0fcanDL48D138TOEq+BrhG89zXzljO76HkUnYcjgCOAL8UNCJZ0wH1ZmjjukEkEpot4CwHZ1kfB54BnkNNbZvAPnAcpRQdG/9vd2q9MfOK5fwl08kjwJf99YVrzLbwy9Nu50W7yX5235971u/jXSYacZoBk2WBW9iF4Mr4mtDs03zr/Gct539jOpnn5FyF+57rW8fNN6rnse2LOW18lHPoczYVPI12Yyg6XFwKbPclfU8WLGV3OCjkzlD82Ueoe6S549CPvPMSzlvaWBHeE+l31RPUJV2H+0hQ5nlBmWeE7c0DNluFUXh3gT/764s3a5EeWC6WnFVUiFVV3yj9wJ93vO4GcsGVWM67tm3ihdTvn7KUTYCnxr9LPOXT/TxVWEqhHZRDLtr/RFhOEgEgrc+3dnTdcv5/HtpIUC+KPmq81+FL2Bu3tUJD1v67wC8E5aRv5t1xnScMh4nXHNoy8Rjl+OiKNDTGhA6xaSsuhoqmWv+GnuqZhlPvPyzn/57526SVpp+BpdT/d1CRXJdR4/0xSnPvWOqT3o8eh2cCD8ZtbXJ45rMiqLPMbMF4X1ymvdIPP2KytpF3mK674NAfG8uocCMJWtvzSXaq1xZc7oPP78snPjVnE0V+jVX4keX8wKEuvf5+Gbsv71+YaP1FPGc5v4R65h5gnwmk2eTwMkpIloEF1zU/rdX4fiNKhZQri4K6V6iu7RUhyXTSZgbT7kABEu8EWyiXhKse6kjTwV+InOYKsuf1rxXbuYUSsFX6r9d0a0ELP9t0NIsWglpVrsIt/H/haRYxhwdtBmwb2j0FnmW+ZzkviUYaOLRnUzR62I0iZZ416Trofco/h7fx66ozoob0Z/oL2aWcF/4p8i1/UnrIb9qQw9Ela8Jri9qoSzDt1NTOvPN26nfXF3oW2zTR1bjXR72Es8dtJlNFEyGm2Glsa41FPCSMe5vEOl6J9NvoHHZLkwmtsro86NJp4QngZM7/b6KEoKTfWUHnEmd8lcOCtwOcFl6f0O5EnpdQ4+M0Ki09yEMas+yTfy8l9+eS4doOB9PlSxxzXxP3+jBlEjWs5hzL2DWuDWRuMFUoY7XuI9cWhygD2QZyQ1kZo6WUD49k/nEW+DfV1vQSlKDx9YVJHgppvxMmlkBpMocuxRriANW/O9gXeF+ifXtZHOXwQzGgPZ/jOubp7QXyvR0SQd11RT2Yxl9ZrjLp/2XKW8clKfBOUHyv+pY6llHGyJvjej7InLdph3nXPDX+3yhvHeIcfrSUVdSXVvThJALW5e0q0UT0+p708+XFBebxFUGZnwvbbAodmu/hb+NsyeuuWc77NnQUYQzPcmTIREPuo5a5dEx+3qzKhkRrPor5JXFlXMaENkZqFywXV5e8a564cpkWYV3W1EwUSXfJW2PbsS1bf5Pxz5cEdfke4CGNOr5p8xTdlbzlD9s6dF3+f+dR2k3VfH5blBNwJmxuTmvIXp772DXPIOMxO+3NotfUQBZ3WEQfFYfnOg0OZZD4uqCM6wDvYhbooResI/lsYB63P6D5uQb1LKqsEPCdjUXivypNhgLwQ8xeF0GWjGzCL40WXAnlrJerTObv02QB+GKAekP4P06Dl+1FWsVVzMKvz8ElkxVLfVWiWoqulVpLywjAEN/nC/Yi7AAfE9ZnmxV9lSkLP80Q9QUsAK/j9sDfGF+blGjXF8do1xS0brLhU21n4Fj+m5bztvXAIi4BPzWcXwL+hH1sXrTUk+W3DmWlSGZOicf2vuSxridUyeqyz8Q44mr2/0SFdqsSBZ+Z96bdgQAMHcraQuPKzlxsO9xto/Lo2TRL19C9EEarYwHqNJGEqFSb0U2HZLF1G7k6vkB5h0of7OEv8D3SDj5vOe+Sjiw0kvW5NsaMNw6J5udi5JB41f+M6bpQPALen2L7EqTaadwQSoZtvElju6VO7aGxJfEMzaMpt++FMmt+JiSOn19DlkYLwrlc/B77IvMSblbANzE71A7x725Q1657s8AadiFnW78e+OmKlSHmqd4n6+lGIW9jVoqu49ew+a7Hup7gW/hJ+O8U2swi2QbwHm7C1xYonzjUJWHFc32zju1h7NEcV6WkxrbK8BbmRMMrlHcwr40uMtO9z+nVO+OfEi1I4gidRidDNR0g1+h8ptpy9da3rUOFzkYzb9hSXIWOrXXhP1Nu3zbDW8R91rZQcCSunZPSBb4hKCedXkkCkXX2mKGgbB+5hrOAW3JNSRabRew+jXqfBxtvpH4fCsqbpmjzmibrxYrXm15ATdl4S/LdvmMvEhxbMhGXrCwXUdmk844dAhmkusiNDyOUJrSOeuB13v8llEV4hPsAkkwlNsftJgXnk/F5yZ6m6QVraVaShEmMsn6b6f0IdHpuCem3pcRJFCba6kMOpv6eVxY5vN+Ey/4Tb5Rsd1jyOgkJ6gWvnyEJTRgDkmmtpJ/r2N13gq75SffbXUTN9V02FkqTnWIXbYSe166PnHiDzN9PI9dq+5SP4MhawV3DqaJv4oS8l5x0ilU2E4uP6AIdolaVJkXgDLFPS0eo5/7HKBe3Y6jNrNYF14JyTQuSQUcLv2ep522S58PUpYbEheQ/INvIvsAqrNHcTZ/nEVusbx5lEv2GoknpxD6D7NldprxnwvGS11lJ+/mF9mEq8gEcYU9rE6pt8O9+kqXIylgmGeas4yOLkI0mGS5caVq2nRHVM2abCCoX0sJvQLgP0sWs/ewTbuCbkilqOoRZ1zENVq11hqq/jUw76UUedQhkCSGFTBV2CTMOTxM4GCIb4aE/yNBT/UPkCUF1+ixfG5/r1PPSKedJ/Gm/J5ENiJOUv9ezJvg0PsdAES7a/rQFsk442vSlkw5+lgc2xnUNPNRlpCi8TfrwmiibIfY41dTd15lkq3VlQLUkrlrgDh2uOYnqsxTXTNuuvorZtN+++JdD2eOEdSoeei7nmz0mY6nsXim6Hp/l/2k5r8dmmbRfG6jn3mVZYliinSd0RiORnaOH2gLvO+QbB/ZQ2UCu4f9N2Qe+zWFr9B7wISpO94/AH/A/WBPgW6gU9HkW1yHwN1S4j4+F6DPAKxz8rPreXiD/bWhzQM9alk3lq1jWOsAXHPohZR34Lvnf/11UqGSZuiUD31UB6GDf+NvEB7gbHk1tlqnPlDTBdWysoJ6fdP7MR+Of76H2Cn63RL2aSp9dKvwikVkjhPCLtIgq+fwikbYiiUSqkrE50gKi5heZNxJkDvOnqS+LS2QKRM0vMk/0kUcKDQL2I9IAppHSKhIJTQ+Vtux9VO7GT+OW/j2043ukAUThF5lFXkVNbxPck20MidsczAVx2huJHCRqfXNCFH6RyISmhpBFAhCnvZGIQu9kGJkTouYXmXeuI48/j8wQUfhFZpG7gjI6drbxG+1EwhCdnCPzQDpetenZUSI18X+Dj/KN9NJspQAAAABJRU5ErkJggg==) ](https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks "Read about Firevault on SecurityBrief") 

Capabilities

## What you get with every deployment

01 

### Path-level severance

Firebreak operates on the connection path itself, so a closed path cannot be reached, scanned or negotiated with from either side.

02 

### No logical bypass

There is no rule plane to subvert and no configuration to mis-set. The contained state is the absence of the connection.

03 

### Multi-party authorisation

Open and close actions require explicit approval from designated parties so no single account, compromised or otherwise, can change the boundary alone.

04 

### Triggered or commanded

Actions can be initiated by an operator, by a scheduled task, or by an upstream detection in line with pre-approved conditions.

05 

### Evidential record

Each state change, the requesting party and the approving party are recorded on physically separate storage through Archive.

06 

### Controlled restoration

Paths are reopened deliberately and individually, through Relay where a defined purpose and window applies.

Demo to Live

## Adoption Guide

Step 1 

#### Map the paths

Identify the connection paths where severance is a meaningful response, including inter-zone, inter-site and third-party links.

Step 2 

#### Define the authority

Agree the approval pattern for open and close, the pre-approved automation conditions and the escalation route.

Step 3 

#### Rehearse and validate

Walk the playbook with the responders, then exercise live severance and restoration on a non-production path.

Step 4 

#### Operate and review

Run Firebreak as part of regular response, review state changes through Archive and tune the trigger conditions over time.

Step 1 

#### Map the paths

Identify the connection paths where severance is a meaningful response, including inter-zone, inter-site and third-party links.

Step 2 

#### Define the authority

Agree the approval pattern for open and close, the pre-approved automation conditions and the escalation route.

Step 3 

#### Rehearse and validate

Walk the playbook with the responders, then exercise live severance and restoration on a non-production path.

Step 4 

#### Operate and review

Run Firebreak as part of regular response, review state changes through Archive and tune the trigger conditions over time.

[Organise a Demo](/contact)

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

[

Control for Water Playbook 

### Control for Water: Deployment Playbook

Chapter three places Firebreak on the Purdue model for a water operator and walks the pilot through to rollout.

Read the playbook: Control for Water: Deployment Playbook ](/playbook/firebreak-water)[

A Control Blueprint for AI 

### A Control Blueprint for AI: 2026 Playbook

Sets out where physical path severance belongs around training clusters, inference estates and agent action authority.

Read the playbook: A Control Blueprint for AI: 2026 Playbook ](/playbook/ai-control-blueprints)[

Firevault Aerospace Playbook 

### A Control Blueprint for Aerospace & Aviation

Applies path control to design authority networks, maintenance systems and airside operational technology.

Read the playbook: A Control Blueprint for Aerospace & Aviation ](/playbook/aerospace)

## Explore More

[

### FV-Isolate

Zones and trust boundaries that Firebreak operates between.

Learn more about FV-Isolate ](/control/modules/isolate)[

### FV-Relay

Purposeful, time-bound restoration of severed paths.

Learn more about FV-Relay ](/control/modules/relay)[

### Ransomware containment

Cut the route before the encryption finishes spreading.

Learn more about Ransomware containment ](/control-for-ransomware-containment)

Questions

## Frequently Asked

Is Firebreak the same as a firewall block? 

Can Firebreak be triggered automatically? 

How are paths reopened? 

Does Firebreak affect management access?