---
title: "Control Isolate Module: isolate network zones | Firevault"
description: "Isolate enforces physical separation between network zones so a compromised segment cannot reach critical systems while investigations run."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control/modules/isolate#webpage",
      "url": "https://fire-vault.com/control/modules/isolate",
      "name": "Control Isolate Module: isolate network zones",
      "description": "Isolate enforces physical separation between network zones so a compromised segment cannot reach critical systems while investigations run.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/792240c2-c981-405a-85ce-7bbb109b2b4d/og-control-isolate.webp"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control/modules/isolate#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control/modules/isolate#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control",
          "item": "https://fire-vault.com/control"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Modules",
          "item": "https://fire-vault.com/control/modules"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Control Isolate Module: isolate network zones",
          "item": "https://fire-vault.com/control/modules/isolate"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Control Module - FIRE 

# FV-Isolate. Separate, contain and limit reach. 

Isolate divides systems and networks into controlled zones so a problem in one place cannot freely become a problem everywhere. Trust does not extend across a boundary unless the boundary is intentionally opened for a defined purpose.

Schedule a Demo[Back to Control](/solutions/control)

Control at a glance 

![FV-Isolate module artwork: separate systems and networks into controlled zones](/__l5e/assets-v1/69b5a245-b93c-42fd-8d04-1e20fbb15cf5/control-module-isolate-hero.webp)

Control removes the physical path. Blueprints show where each module sits.

Exposure

How it worksExplore moreQuestions

The exposure in numbers 

01 

Boundaries are explicit, not implied by network topology

Designed Boundaries are explicit, not implied by network topology 

02 

Lateral movement is constrained by the zone it starts in

Bounded Lateral movement is constrained by the zone it starts in 

03 

Cross-zone access is requested, not assumed

No inherited trust Cross-zone access is requested, not assumed 

04 

Separation holds during normal operations and during response

Continuously enforced Separation holds during normal operations and during response 

The Problem 

## Flat networks reward whoever reaches them first.

01 

### Lateral movement

Once an attacker is inside a flat or weakly segmented environment, the next system, the next share and the next credential are all one step away.

02 

### Trust by topology

Permissions that exist only because two systems sit on the same subnet are permissions nobody chose to grant.

03 

### Drift over time

Logical segmentation drifts as services are added, integrations are wired in and exceptions accumulate, until the original boundary is no longer the real boundary.

Control Module - FIRE

> Separation is a design decision. Without it, every incident has the run of the building.

The Scenario

### Scenario: containing a compromise to its zone

A workstation in a corporate zone is compromised through a credential reuse attack. Because the corporate zone is isolated from the operations zone and from the records zone, the attacker's reach is limited to what is intentionally exposed to corporate, which is little. Investigation, eradication and recovery proceed in the affected zone while the other zones continue to operate. Cross-zone access for the responders is requested explicitly rather than already being available by default.

"Isolate is the difference between an incident in one room and an incident in the whole building."

FV-Isolate in placement 

## Where Isolate holds the zone boundary.

Isolate enforces the zone and conduit model. Each protected zone is reachable only through a named conduit, and only when the conduit is authorised to be open.

Grounded in IEC 62443-3-3 SR 5.1, SR 5.2 and SR 5.3, NIST SP 800-82 zone guidance and the Purdue Enterprise Reference Architecture.

Inputs ─┐ Telemetry ─┐ 

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)

FV-Isolate

Control layer

┌─ Outputs ┌─ Control 

01 SR 5.1 

Enterprise zone boundary

Defines the perimeter of the enterprise zone. Cross-zone traffic must use a declared conduit.

02 SR 5.2 

Control system zone (Purdue L3 to L2)

Holds the boundary between supervisory and process control. Engineering reach is named, not implicit.

03 IEC 61511 

Safety instrumented system zone

Keeps the SIS separated from basic process control. A compromise of BPCS does not reach the safety layer.

04 PR.IP-9 

Recovery and forensic zone

Recovery infrastructure sits in its own zone, reachable only when a restore operation is authorised.

Relies on · prerequisites

-   An explicit zone and conduit inventory that is maintained, not assumed 
-   Out-of-band approval to open a conduit 
-   Continuous evidence that each boundary is intact 

Pairs with · companion modules

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock ![FV-Validate module icon](/assets/vault-icon-CD3Pv4ri.png)Validate 

Featured In

[![TechRadar Pro logo](/press/techradar-pro-logo.svg) ](https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough "Read about Firevault on TechRadar Pro") [![Yahoo Finance logo](/assets/yahoo-finance-logo-white-aNkUpCH7.png) ](https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html "Read about Firevault on Yahoo Finance") [![Channel Insider logo](/assets/channel-insider-logo-white-CFFo4iu7.png) ](https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/ "Read about Firevault on Channel Insider") [![Security Buyer logo](/assets/security-buyer-logo-white-o6oIaBWz.png) ](https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/ "Read about Firevault on Security Buyer") [![SecurityBrief logo](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAT8AAAA1CAYAAAA3Sux5AAAL+0lEQVR4nO2dT4gdSRnAf++Ri5ODEcTJvoB0PIjgxdkFlejsTkBExFlhzWhEWPDkYWfXxZfoRSK73vKPJQrePHjamLhg5iAswrzNkFVyyBz04kqYJ2tmM6CQS2bxss9Dvcrr6emu+qq7ql/3e/WDZv50dVW9ftVff1Xfn+qMRiMiEY/cBpZTf78M/HpKfYlECukIhd8Z4IalzBbwIjCs2KdIO1kHfmU436mrI5FIih5wKvX3fWAb7MKvrFq4BTxb8tpI++gBDwTlogCM1IFEWVvr5vxzBSX0qsyHl8fX71SoI9IeXvVUz8hyLHlqJ1LMEmrpIn3fH6I0+6ZzGdVfm+ADOJ4Vfn1g02NnEqoJ0Ug7+Jyw3ELFdr5f8frQPMQuwCXHLdSzUzc94B4H12wBFlFLGpdr75Gc2yj5JSYt/NYJ9+GiAJxtficstx+0F9Nn0VM9q6hZ04jqLwwX3rScdxIuNZI1sonQwq+HebHaB1EAzi43BWWeDt6L2eQxShOsA2cB0gDWKdlvLfzu+euLkbhmM7t0gI2Cc+cYW9gipVgF7tTQzl4NbfimrNL2UAs/ibq+gRKWnczRRQ1uCW+59jDSKp5HjYkT40OPlyvT7NSMcIrwU2CbUWMrcPuhyMqtLnCzi+yGrqEGdt7UdYQa3BI3hkTS00jr2R0fcanDL48D138TOEq+BrhG89zXzljO76HkUnYcjgCOAL8UNCJZ0wH1ZmjjukEkEpot4CwHZ1kfB54BnkNNbZvAPnAcpRQdG/9vd2q9MfOK5fwl08kjwJf99YVrzLbwy9Nu50W7yX5235971u/jXSYacZoBk2WBW9iF4Mr4mtDs03zr/Gct539jOpnn5FyF+57rW8fNN6rnse2LOW18lHPoczYVPI12Yyg6XFwKbPclfU8WLGV3OCjkzlD82Ueoe6S549CPvPMSzlvaWBHeE+l31RPUJV2H+0hQ5nlBmWeE7c0DNluFUXh3gT/764s3a5EeWC6WnFVUiFVV3yj9wJ93vO4GcsGVWM67tm3ihdTvn7KUTYCnxr9LPOXT/TxVWEqhHZRDLtr/RFhOEgEgrc+3dnTdcv5/HtpIUC+KPmq81+FL2Bu3tUJD1v67wC8E5aRv5t1xnScMh4nXHNoy8Rjl+OiKNDTGhA6xaSsuhoqmWv+GnuqZhlPvPyzn/57526SVpp+BpdT/d1CRXJdR4/0xSnPvWOqT3o8eh2cCD8ZtbXJ45rMiqLPMbMF4X1ymvdIPP2KytpF3mK674NAfG8uocCMJWtvzSXaq1xZc7oPP78snPjVnE0V+jVX4keX8wKEuvf5+Gbsv71+YaP1FPGc5v4R65h5gnwmk2eTwMkpIloEF1zU/rdX4fiNKhZQri4K6V6iu7RUhyXTSZgbT7kABEu8EWyiXhKse6kjTwV+InOYKsuf1rxXbuYUSsFX6r9d0a0ELP9t0NIsWglpVrsIt/H/haRYxhwdtBmwb2j0FnmW+ZzkviUYaOLRnUzR62I0iZZ416Trofco/h7fx66ozoob0Z/oL2aWcF/4p8i1/UnrIb9qQw9Ela8Jri9qoSzDt1NTOvPN26nfXF3oW2zTR1bjXR72Es8dtJlNFEyGm2Glsa41FPCSMe5vEOl6J9NvoHHZLkwmtsro86NJp4QngZM7/b6KEoKTfWUHnEmd8lcOCtwOcFl6f0O5EnpdQ4+M0Ki09yEMas+yTfy8l9+eS4doOB9PlSxxzXxP3+jBlEjWs5hzL2DWuDWRuMFUoY7XuI9cWhygD2QZyQ1kZo6WUD49k/nEW+DfV1vQSlKDx9YVJHgppvxMmlkBpMocuxRriANW/O9gXeF+ifXtZHOXwQzGgPZ/jOubp7QXyvR0SQd11RT2Yxl9ZrjLp/2XKW8clKfBOUHyv+pY6llHGyJvjej7InLdph3nXPDX+3yhvHeIcfrSUVdSXVvThJALW5e0q0UT0+p708+XFBebxFUGZnwvbbAodmu/hb+NsyeuuWc77NnQUYQzPcmTIREPuo5a5dEx+3qzKhkRrPor5JXFlXMaENkZqFywXV5e8a564cpkWYV3W1EwUSXfJW2PbsS1bf5Pxz5cEdfke4CGNOr5p8xTdlbzlD9s6dF3+f+dR2k3VfH5blBNwJmxuTmvIXp772DXPIOMxO+3NotfUQBZ3WEQfFYfnOg0OZZD4uqCM6wDvYhbooResI/lsYB63P6D5uQb1LKqsEPCdjUXivypNhgLwQ8xeF0GWjGzCL40WXAnlrJerTObv02QB+GKAekP4P06Dl+1FWsVVzMKvz8ElkxVLfVWiWoqulVpLywjAEN/nC/Yi7AAfE9ZnmxV9lSkLP80Q9QUsAK/j9sDfGF+blGjXF8do1xS0brLhU21n4Fj+m5bztvXAIi4BPzWcXwL+hH1sXrTUk+W3DmWlSGZOicf2vuSxridUyeqyz8Q44mr2/0SFdqsSBZ+Z96bdgQAMHcraQuPKzlxsO9xto/Lo2TRL19C9EEarYwHqNJGEqFSb0U2HZLF1G7k6vkB5h0of7OEv8D3SDj5vOe+Sjiw0kvW5NsaMNw6J5udi5JB41f+M6bpQPALen2L7EqTaadwQSoZtvElju6VO7aGxJfEMzaMpt++FMmt+JiSOn19DlkYLwrlc/B77IvMSblbANzE71A7x725Q1657s8AadiFnW78e+OmKlSHmqd4n6+lGIW9jVoqu49ew+a7Hup7gW/hJ+O8U2swi2QbwHm7C1xYonzjUJWHFc32zju1h7NEcV6WkxrbK8BbmRMMrlHcwr40uMtO9z+nVO+OfEi1I4gidRidDNR0g1+h8ptpy9da3rUOFzkYzb9hSXIWOrXXhP1Nu3zbDW8R91rZQcCSunZPSBb4hKCedXkkCkXX2mKGgbB+5hrOAW3JNSRabRew+jXqfBxtvpH4fCsqbpmjzmibrxYrXm15ATdl4S/LdvmMvEhxbMhGXrCwXUdmk844dAhmkusiNDyOUJrSOeuB13v8llEV4hPsAkkwlNsftJgXnk/F5yZ6m6QVraVaShEmMsn6b6f0IdHpuCem3pcRJFCba6kMOpv6eVxY5vN+Ey/4Tb5Rsd1jyOgkJ6gWvnyEJTRgDkmmtpJ/r2N13gq75SffbXUTN9V02FkqTnWIXbYSe166PnHiDzN9PI9dq+5SP4MhawV3DqaJv4oS8l5x0ilU2E4uP6AIdolaVJkXgDLFPS0eo5/7HKBe3Y6jNrNYF14JyTQuSQUcLv2ep522S58PUpYbEheQ/INvIvsAqrNHcTZ/nEVusbx5lEv2GoknpxD6D7NldprxnwvGS11lJ+/mF9mEq8gEcYU9rE6pt8O9+kqXIylgmGeas4yOLkI0mGS5caVq2nRHVM2abCCoX0sJvQLgP0sWs/ewTbuCbkilqOoRZ1zENVq11hqq/jUw76UUedQhkCSGFTBV2CTMOTxM4GCIb4aE/yNBT/UPkCUF1+ixfG5/r1PPSKedJ/Gm/J5ENiJOUv9ezJvg0PsdAES7a/rQFsk442vSlkw5+lgc2xnUNPNRlpCi8TfrwmiibIfY41dTd15lkq3VlQLUkrlrgDh2uOYnqsxTXTNuuvorZtN+++JdD2eOEdSoeei7nmz0mY6nsXim6Hp/l/2k5r8dmmbRfG6jn3mVZYliinSd0RiORnaOH2gLvO+QbB/ZQ2UCu4f9N2Qe+zWFr9B7wISpO94/AH/A/WBPgW6gU9HkW1yHwN1S4j4+F6DPAKxz8rPreXiD/bWhzQM9alk3lq1jWOsAXHPohZR34Lvnf/11UqGSZuiUD31UB6GDf+NvEB7gbHk1tlqnPlDTBdWysoJ6fdP7MR+Of76H2Cn63RL2aSp9dKvwikVkjhPCLtIgq+fwikbYiiUSqkrE50gKi5heZNxJkDvOnqS+LS2QKRM0vMk/0kUcKDQL2I9IAppHSKhIJTQ+Vtux9VO7GT+OW/j2043ukAUThF5lFXkVNbxPck20MidsczAVx2huJHCRqfXNCFH6RyISmhpBFAhCnvZGIQu9kGJkTouYXmXeuI48/j8wQUfhFZpG7gjI6drbxG+1EwhCdnCPzQDpetenZUSI18X+Dj/KN9NJspQAAAABJRU5ErkJggg==) ](https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks "Read about Firevault on SecurityBrief") 

Capabilities

## What you get with every deployment

01 

### Explicit zoning

Zones are designed against operational reality, not inherited from the way switches happened to be wired.

02 

### Default-deny crossings

Cross-zone traffic is not allowed unless a specific path, purpose and approval exist.

03 

### Reduced blast radius

A compromise in one zone is contained to the surface that zone exposes, rather than the whole estate.

04 

### Independent recovery

Each zone can be investigated, recovered and brought back online without waiting on the others.

05 

### Identity-aware boundaries

Zone membership accounts for the identity making the request, not just the address it came from.

06 

### Evidential record

Boundary changes and cross-zone approvals are recorded through Archive on physically separate storage.

Demo to Live

## Adoption Guide

Step 1 

#### Map the estate

Identify the systems, services, identities and data flows that should sit together and those that should not.

Step 2 

#### Design the zones

Define zones around operational reality, with explicit ownership and explicit cross-zone rules.

Step 3 

#### Validate the boundary

Test the boundary with realistic scenarios, including credential abuse and inherited trust paths.

Step 4 

#### Operate and review

Run Isolate as part of normal change control and review crossings through Archive on a regular cadence.

Step 1 

#### Map the estate

Identify the systems, services, identities and data flows that should sit together and those that should not.

Step 2 

#### Design the zones

Define zones around operational reality, with explicit ownership and explicit cross-zone rules.

Step 3 

#### Validate the boundary

Test the boundary with realistic scenarios, including credential abuse and inherited trust paths.

Step 4 

#### Operate and review

Run Isolate as part of normal change control and review crossings through Archive on a regular cadence.

[Organise a Demo](/contact)

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

[

Control for Water Playbook 

### Control for Water: Deployment Playbook

Defines the zone model that path control operates between, from telemetry through to enterprise systems.

Read the playbook: Control for Water: Deployment Playbook ](/playbook/firebreak-water)[

Firevault Aerospace Playbook 

### A Control Blueprint for Aerospace & Aviation

Shows how zones are drawn between engineering, production and airside environments without disrupting flight operations.

Read the playbook: A Control Blueprint for Aerospace & Aviation ](/playbook/aerospace)[

A Control Blueprint for AI 

### A Control Blueprint for AI: 2026 Playbook

Separates model development, weights custody and production inference into controlled zones.

Read the playbook: A Control Blueprint for AI: 2026 Playbook ](/playbook/ai-control-blueprints)

## Explore More

[

### FV-Firebreak

Physically open or close a zone boundary when required.

Learn more about FV-Firebreak ](/control/modules/firebreak)[

### FV-Relay

Purpose-led, time-bound cross-zone connectivity.

Learn more about FV-Relay ](/control/modules/relay)[

### Lateral movement

Why a flat network turns one foothold into an estate-wide incident.

Learn more about Lateral movement ](/solutions/control)

Questions

## Frequently Asked

Is Isolate the same as network segmentation? 

How do zones work with existing networks? 

What happens when work genuinely needs to cross a zone? 

How is drift prevented?