---
title: "Control by Firevault: Physical Path Control at… | Firevault"
url: https://fire-vault.com/control
description: "Control by Firevault governs the connection itself. Nine modules and eight Control Blueprints sever, validate and time-bound every path across IT, OT and AI…"
lang: en-GB
---

Image: Control - data path governance for enterprise (https://fire-vault.com/assets/control-icon-B9EWHzCT.png)
Control

# Control: network paths you can physically verify.

Nine purpose-built modules across two layers. The Fire layer decides which paths exist. The Vault layer decides what those paths are allowed to touch. Every decision is enforced in hardware you can see, hear and physically verify.

Explore Control Blueprints: https://fire-vault.com/control-blueprints

9

Modules

2

Layers

8

Blueprints

L1

Physical

FIRE, Control the path

VAULT, Protect the asset

Image: Control - data path governance for enterprise (https://fire-vault.com/assets/control-icon-B9EWHzCT.png)

Control

Image: Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)

Isolate

Image: Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)

Validate

Image: Archive module icon (https://fire-vault.com/assets/archive-icon-B3rc85NY.png)

Archive

Control Blueprint

OT Air-Gap

- Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
  Isolate Separates OT from everything else
- Image: FV-Archive module icon (https://fire-vault.com/assets/archive-icon-B3rc85NY.png)
  Archive Preserves operational records
- Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
  Validate Confirms the asset before recovery

Live path control across Purdue Levels 0 to 5

01 Why we built this

## Software alone was never going to be enough.

The same weaknesses recur in serious incidents. Control addresses them by moving the decision into hardware, away from the network it protects.

### Once inside, an attacker can move through the network

One compromised laptop is rarely the goal. It is the way in. Without a physical break in the path, the next system is only a hop away.

### The off switch relies on the network it is meant to cut

If the kill command travels the same network as the threat, the attacker is already standing next to the off switch. Control moves that switch off the network entirely.

### Pulling cables works, but it does not scale

Every team that has handled a real incident knows the feeling. Control gives you the same outcome on demand, from anywhere, with a clean audit trail.

02 Nine modules

## Four Fire modules decide the path. Five Vault modules decide the payload.

Every Control Blueprint is assembled from these nine modules. Nothing is bolted on afterwards.

### Firebreak

FIRE

Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.
https://fire-vault.com/control/modules/firebreak

### Isolate

FIRE

Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.
https://fire-vault.com/control/modules/isolate

### Relay

FIRE

Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.
https://fire-vault.com/control/modules/relay

### Execute

FIRE

Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.
https://fire-vault.com/control/modules/execute

### Validate

VAULT

Checks whether a request, command or approval should proceed before access, action or transfer is allowed.
https://fire-vault.com/control/modules/validate

### Archive

VAULT

Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.
https://fire-vault.com/control/modules/archive

### Unlink

VAULT

Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.
https://fire-vault.com/control/modules/unlink

### Lock

VAULT

Restricts access through identity, authority, policy, permission and operational controls.
https://fire-vault.com/control/modules/lock

### Transfer

VAULT

Controls how sensitive assets move into, out of or between protected environments through approved paths.
https://fire-vault.com/control/modules/transfer

03 Firebreak

## Firebreak is the physical control point.

Where a Blueprint calls for a Layer 1 cut, Firebreak delivers it. Per-zone, independently, in milliseconds, over a command path that never touches the production network.

See the Firebreak range (https://fire-vault.com/firebreak)

Compromised

Affected hosts

Image: FV-Is module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)

Image: FV-Ex module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)

Isolate · Execute

Internal Network

Workloads, directory

Image: FV-Lo module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)

Lock

Protected Zone

Records, secrets

Compromised

Affected hosts

Isolate · Execute

Internal Network

Workloads, directory

Lock

Protected Zone

Records, secrets

CP-02 · Separate compromised systems and restrict access immediately.

Module deck

Fb

Image: Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)

Firebreak

Re

Image: Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)

Relay

Un

Image: Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)

Unlink

Va

Validate

Ar

Archive

Tr

Image: Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)

Transfer

Fire, path control Protect, asset protection

04 What is included

## Three properties every deployment inherits.

What Every Blueprint Includes

## Four pillars under every Control Blueprint

Whatever the outcome, every Blueprint rests on the same physical foundation.

### Out-of-band command path

Commands arrive over dedicated management Ethernet, cellular SMS, or an authenticated API. They never traverse the production network they control.

Learn more (https://fire-vault.com/firebreak#range)

### Per-zone independence

Each zone is switched independently. Isolate one circuit, one tenant, one SCADA segment, without touching the rest.

Learn more

### Auditable, evidential log

Every action is logged locally and to SysLog. Verifiable records for NIS2, DORA, insurer scrutiny and internal audit.

Learn more (https://fire-vault.com/solutions/control/frameworks/nis2)

05 Against alternatives

## Detection tells you. Manual cabling costs you. Control does it.

## Control vs the alternatives

Detect-and-respond and manual shutdown are the two positions most teams pick between. Control is the third.

| Posture | Detect & respond | Manual shutdown | Control |
| --- | --- | --- | --- |
| Time to contain | Minutes to hours | Minutes, manual | Milliseconds, scheduled or on-demand |
| Reversible without site visit | Yes | No | Yes |
| Auditable physical action | No | Ad hoc | Yes |
| Depends on uncompromised software | Yes | No | No, hardware path |
| Scope of action | Alerts, blocks, isolates a host | Whole segment, all or nothing | Per-zone, per-module, per-blueprint |
| Out-of-band command path | No | No | Yes |
| Maps to NIS2 / DORA isolation | Indirect | Indirect | Yes |

06 UK governance

## Board-level evidence, not screenshots.

UK Board-Level Cyber Governance

## Hardware-enforced accountability the board can sign off

The NCSC Cyber Security Toolkit for Boards and the UK NIS2 regime both put personal, evidenced accountability on directors. Control turns that duty into a physical artefact: a switch position, an out-of-band command and a signed log, not a policy assertion.

### NCSC Cyber Security Toolkit for Boards, mapped to Control

NCSC Board Toolkit, Principle A

#### Embed cyber security into your governance

Control gives the board a single, physical control point over connectivity. Zone state is a governance artefact, not a screenshot. Board packs cite the actual switch position, not an intent.

NCSC Board Toolkit, Principle B

#### Build a positive cyber security culture

Out-of-band command paths remove the temptation to bypass. Operators cannot silently reconnect a segment: every action requires a named identity on a separate management plane.

NCSC Board Toolkit, Principle C

#### Establish baseline security controls

Physical segmentation between OT and IT, between crown-jewel data and the estate, and between third parties and production. Hardware-enforced, not policy-enforced.

NCSC Board Toolkit, Principle D

#### Manage cyber risk in the supply chain

Supplier and MSP access is scheduled, identity verified and time bound. When the window closes, the segment is physically disconnected. Third-party breach blast radius is bounded by hardware.

NCSC Board Toolkit, Principle E

#### Plan your response to cyber incidents

Firebreak provides a rehearsed, board-authorised kill switch. Isolation happens without walking to a rack, without touching the compromised network, and produces a signed, timestamped record for the post-incident review.

Reference: NCSC Cyber Security Toolkit for Boards (https://www.ncsc.gov.uk/collection/board-toolkit). Firevault maps controls to Toolkit principles; the Toolkit is guidance, not certification.

### UK NIS2 director duties, evidenced by hardware

#### Management body accountability, Article 20

NIS2 puts network security decisions on the board personally. Control makes those decisions evidenceable at the hardware layer, not just in policy documents, so directors can demonstrate they have discharged the duty.

See NIS2 mapping (https://fire-vault.com/solutions/control/frameworks/nis2)

#### Cybersecurity risk-management measures, Article 21

Article 21 requires network security, access control, supply-chain security and incident handling. Control's out-of-band command path, per-zone independence and signed logs map directly to Article 21(2)(a), (d), (e) and (i).

#### 24 and 72 hour incident notification, Article 23

The evidential log is generated at the moment of isolation, not reconstructed afterwards. Boards can meet the 24 hour early warning and 72 hour incident notification obligations with a defensible timeline.

07 Use cases

## Where Control can be put to work.

Use Cases

## Every sector reaches into the same eight Blueprints.

### Healthcare

Clinical data, medical devices and OT held behind physical isolation. Patient safety protected at Layer 1.

View use case
https://fire-vault.com/control-for-healthcare

### Finance

Hardware-enforced isolation for banking, investment and financial services. Regulatory and operational evidence by design.

View use case
https://fire-vault.com/control-for-banking

### Water Utilities

A new line of defence for the diverse OT and IT environments of the water sector. Assets protected from the physical layer up.

View use case
https://fire-vault.com/control-for-water

### Oil and Gas

Physical protection of OT and IT for upstream, midstream and downstream estates. Removes the remote path to critical kit.

View use case
https://fire-vault.com/control-for-oil-and-gas

### Telecoms

Physically isolating core telco infrastructure, satellite uplinks, OSS and BSS, and third-party access at the connection layer.

View use case
https://fire-vault.com/control-for-telecoms

### Utilities

Operational continuity for electricity, gas and broader utility estates. Layer 1 control where software defences end.

View use case
https://fire-vault.com/control-for-utilities

### Defence

Mission systems, classified enclaves and tactical kit held behind hardware-enforced disconnection.

View use case
https://fire-vault.com/control-for-defence

### Public Sector

Government estates, councils and arm's-length bodies. Auditable physical control over connectivity.

View use case
https://fire-vault.com/control-for-public-sector

### Education

Research networks, exam infrastructure and student data shielded from cyber attack at the physical layer.

View use case
https://fire-vault.com/control-for-education

### Critical Infrastructure

The last line of defence for CNI. Removes remote attack paths to the systems a country cannot afford to lose.

View use case
https://fire-vault.com/control-for-critical-infrastructure

08 Who it is for

## Built for the teams who own the consequences.

Who Control Is For

## From OT segments to national infrastructure

Control is built for operators who need physical certainty over what is reachable, when, and by whom.

### Critical national infrastructure

Energy, water, rail and telco operators who need verifiable physical isolation on the IT/OT boundary.
https://fire-vault.com/control-for-critical-infrastructure

### OT and SCADA environments

Sever legacy control networks on command for patching, incident response and routine isolation.
https://fire-vault.com/control-for-ot-environments

### Defence and national security

Air-gap-on-demand for classified enclaves, test ranges and partner-connected programmes.
https://fire-vault.com/control-for-critical-infrastructure

### Regulated finance

Demonstrable physical control for settlement enclaves, trading floors and audit-led isolation.
https://fire-vault.com/solutions/control/frameworks/nis2

### Enterprise IT under NIS2 / DORA

Map a logical containment story to an evidential physical control that regulators and insurers recognise.
https://fire-vault.com/solutions/control/frameworks/nis2

### Healthcare and research

Protect clinical systems, research data and connected medical equipment from lateral movement.
https://fire-vault.com/solutions/control

## Decide what stays connected.

We will review your architecture, map the modules you need and show you the evidence your board is likely to require.

Explore Blueprints: https://fire-vault.com/control-blueprints

Get started

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control#webpage",
    "url": "https://fire-vault.com/control",
    "name": "Control by Firevault: Physical Path Control at…",
    "description": "Control by Firevault governs the connection itself. Nine modules and eight Control Blueprints sever, validate and time-bound every path across IT, OT and AI…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control#breadcrumb"
    },
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".lead-paragraph"
      ]
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control by Firevault: Physical Path Control at…",
        "item": "https://fire-vault.com/control"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Product",
    "@id": "https://fire-vault.com/control#product",
    "name": "Control",
    "description": "Nine modules govern how data is accessed, moved, and disconnected across your environment. Hardware-encrypted, physically disconnected, offline by default.",
    "brand": {
      "@type": "Brand",
      "name": "Firevault"
    },
    "image": "https://fire-vault.com/images/og/og-platform.jpg",
    "url": "https://fire-vault.com/control",
    "category": "Data Path Governance",
    "manufacturer": {
      "@id": "https://fire-vault.com/#organization"
    },
    "offers": {
      "@type": "Offer",
      "price": "0",
      "priceCurrency": "GBP",
      "availability": "https://schema.org/InStock",
      "url": "https://fire-vault.com/control",
      "description": "Enterprise pricing. Contact for consultation.",
      "seller": {
        "@id": "https://fire-vault.com/#organization"
      }
    },
    "additionalProperty": [
      {
        "@type": "PropertyValue",
        "name": "Module Count",
        "value": "9"
      },
      {
        "@type": "PropertyValue",
        "name": "Modules",
        "value": "Firebreak, Transfer, Lock, Archive, Unlink, Vault, Execute, Relay, Isolate"
      },
      {
        "@type": "PropertyValue",
        "name": "Capability",
        "value": "Data path governance, access, movement, and disconnection orchestration"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "knowsAbout": [
      "Offline Secure Storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```