---
title: "Physical Layer Security Guide: the Layer 1 | Firevault"
description: "Firewalls, endpoint detection, identity management, and immutable backups are all software layers. Every software layer depends on the integrity of the layer…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/physical-layer-security-architecture#webpage",
      "url": "https://fire-vault.com/learn/guides/physical-layer-security-architecture",
      "name": "Physical Layer Security Guide: the Layer 1",
      "description": "Firewalls, endpoint detection, identity management, and immutable backups are all software layers. Every software layer depends on the integrity of the layer…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fphysical-layer-security-architecture.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/physical-layer-security-architecture#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/physical-layer-security-architecture#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Physical Layer Security Architecture",
          "item": "https://fire-vault.com/learn/guides/physical-layer-security-architecture"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Physical Layer Security Architecture",
      "description": "Firewalls, endpoint detection, identity management, and immutable backups are all software layers. Every software layer depends on the integrity of the layer beneath it. The physical layer is the foundation that no software attack can compromise.",
      "url": "https://fire-vault.com/learn/guides/physical-layer-security-architecture",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fphysical-layer-security-architecture.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:16:21.25498+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/physical-layer-security-architecture"
      },
      "inLanguage": "en-GB",
      "articleSection": "Architecture",
      "wordCount": 602,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Security Is Built in LayersThe Software CeilingThe Physical Layer: Where Probab…Where the Physical Layer FitsWhat Lives at the Physical LayerThe Architecture of CertaintyConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Architecture 

Architecture · 19 February 2026 

# Physical Layer Security Architecture

Firewalls, endpoint detection, identity management, and immutable backups are all software layers. Every software layer depends on the integrity of the layer beneath it. The physical layer is the foundation that no software attack can compromise.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fphysical-layer-security-architecture)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fphysical-layer-security-architecture&text=Physical%20Layer%20Security%20Architecture%0A%0AFirewalls%2C%20endpoint%20detection%2C%20identity%20management%2C%20and%20immutable%20backups%20are%20all%20software%20layers.%20Every%20software%20layer%20depends%20on%20the%20integrity%20of%20the%20layer%20beneath%20it.%20The%20physical%20layer%20is%20the%20foundation%20that%20no%20software%20attack%20can%20compromise.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fphysical-layer-security-architecture)[](mailto:?subject=Physical%20Layer%20Security%20Architecture&body=Firewalls%2C%20endpoint%20detection%2C%20identity%20management%2C%20and%20immutable%20backups%20are%20all%20software%20layers.%20Every%20software%20layer%20depends%20on%20the%20integrity%20of%20the%20layer%20beneath%20it.%20The%20physical%20layer%20is%20the%20foundation%20that%20no%20software%20attack%20can%20compromise.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fphysical-layer-security-architecture)

![Physical Layer Security Architecture](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fphysical-layer-security-architecture.jpg)

Architecture 

Why it matters

## What this means for organisations holding critical data

Firewalls, endpoint detection, identity management, and immutable backups are all software layers. Every software layer depends on the integrity of the layer beneath it. The physical layer is the foundation that no software attack can compromise.

**On this page**[Security Is Built in Layers](#section-0)[The Software Ceiling](#section-1)[The Physical Layer: Where Probab…](#section-2)[Where the Physical Layer Fits](#section-3)[What Lives at the Physical Layer](#section-4)[The Architecture of Certainty](#section-5)[Conclusion](#section-6)

On this page

1.  [Security Is Built in Layers](#section-0)
2.  [The Software Ceiling](#section-1)
3.  [The Physical Layer: Where Probability Becomes Zero](#section-2)
4.  [Where the Physical Layer Fits](#section-3)
5.  [What Lives at the Physical Layer](#section-4)
6.  [The Architecture of Certainty](#section-5)
7.  [Conclusion](#section-6)

## Security Is Built in Layers

Defence in depth is the foundational principle of modern security architecture. Organisations deploy multiple layers of controls: network security, endpoint protection, identity management, application security, and data protection. Each layer reduces the probability of a successful attack.

But every layer in a typical security architecture shares a common characteristic: it is software. Firewalls run on firmware. Endpoint detection runs on operating systems. Identity management runs on cloud platforms. Even "immutable" backup runs on storage software. Each software layer depends on the integrity of the software beneath it.

## The Software Ceiling

Software-based security has a ceiling. No matter how many layers of software you deploy, every layer is vulnerable to:

-   **Zero-day vulnerabilities:** Undiscovered flaws in any layer can be exploited before patches exist
-   **Configuration errors:** A single misconfiguration in any layer can create an exploitable gap
-   **Credential compromise:** Administrative credentials for any layer can be phished, purchased, or brute-forced
-   **Supply chain attacks:** Compromised updates to any layer can bypass all controls in that layer
-   **Insider threats:** Personnel with administrative access can bypass controls in any layer they manage

This is not a criticism of software security. These layers are essential. But they represent probability reduction, not elimination. There is always a non-zero probability that a sufficiently sophisticated attacker can traverse all software layers.

## The Physical Layer: Where Probability Becomes Zero

The physical layer operates on a different principle entirely. Rather than reducing the probability of successful attack, it eliminates the possibility of remote attack by removing the attack surface.

Data stored in physically disconnected hardware has no IP address, no network interface, no API endpoint, and no remote management console. There is no software to exploit, no credentials to compromise, and no configuration to misconfigure. The only attack vector is physical access, which is governed through identity verification and access controls that create accountability.

## Where the Physical Layer Fits

The physical layer does not replace software security layers. It provides the foundation beneath them:

### The Security Architecture Stack

-   **Layer 5 (Application):** Application-level security controls, input validation, authentication
-   **Layer 4 (Identity):** Identity management, multi-factor authentication, least privilege
-   **Layer 3 (Network):** Firewalls, segmentation, intrusion detection
-   **Layer 2 (Endpoint):** Endpoint detection and response, device management
-   **Layer 1 (Physical):** [Offline Secure Storage](/offline-secure-storage)® for recovery credentials, certificates, and critical assets

When Layers 2 through 5 are all compromised simultaneously (as happens in sophisticated ransomware attacks), Layer 1 remains intact because it operates on different physics. This is the foundation from which all other layers can be rebuilt.

## What Lives at the Physical Layer

The physical layer governs the assets that every other layer depends on:

-   **The credentials that configure Layer 3:** Firewall admin passwords and network device credentials
-   **The certificates that underpin Layer 4:** Root CA keys and identity system configuration
-   **The procedures that rebuild Layers 2 through 5:** System rebuild documentation and configuration baselines
-   **The evidence that validates all layers:** Audit logs, compliance documentation, and governance records

## The Architecture of Certainty

Software layers provide confidence. The physical layer provides certainty. Confidence says "we believe our controls will hold." Certainty says "regardless of what happens to our software controls, we can recover."

This distinction matters most in board rooms, regulatory conversations, and insurance negotiations. Confidence requires explanation. Certainty requires only demonstration.

## Conclusion

Every security architecture that consists exclusively of software layers has a ceiling. The physical layer breaks through that ceiling by providing a foundation that no software attack can reach. For the assets that matter most, the credentials and procedures that enable recovery from total compromise, the physical layer is not optional. It is the foundation that makes every other layer rebuildable.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Zero Trust Architecture Guide: What NIST SP 800-207 Actually Requires
    
    A technical guide to Zero Trust architecture based on NIST SP 800-207: the tenets, the policy engine and policy enforcement point, deployment models, and the limits of Zero Trust in OT and recovery.
    
    Read guide ](/learn/guides/zero-trust-architecture-guide)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up