Control for Water Playbook

Control for Water
Deployment Playbook

Control the path. Protect the supply. Keep a clean copy.

A 28-page deployment playbook for water boards, CISOs, OT leaders and network architects. Firebreak® Layer 1 path control, the wider Control by Firevault modules and Offline Secure Storage® recovery copies, mapped against the Purdue model.

28 pages
22 min read
Water boards and executive teams
Control for Water: Deployment Playbook cover

Get the playbook

Emailed to you within a minute

Personal email addresses such as Gmail or Yahoo are not accepted.

Email-gated GDPR compliant
01Foreword

Written by the people who build the controls.

The water sector's connectivity story has been written by convenience, not by design. Remote sites, third-party support, engineering tools and telemetry now share paths that were never intended to carry them.

Mark Fermor · Co-Founder, Firevault
David Bailey · Co-Founder, Firevault

The doctrine

Control the path. Govern the agent. Protect the asset.

Every Firevault playbook is grounded in the same doctrine behind our Offline Secure Storage® platform, so a decision taken in one chapter still holds in the next.

The Control for Water Playbook is a practical response. It explains, in plain language, how Firebreak Layer 1 physical path control complements existing firewalls and segmentation, where the wider Control by Firevault modules and Offline Secure Storage® recovery copies belong on the Purdue model, and how a water operator can pilot and scale the whole pattern without ripping up what already works.

It is written for the boards, CISOs, OT leaders and architects who now have to prove, to regulators and to themselves, that every connectivity choice is intentional and evidenced.

02What's inside

6 parts. Written for the people who own the decision.

Each chapter opens with the decision it exists to help you make, and closes with the evidence you should expect back.

01

The water-sector control problem

Why standing connectivity, third-party access and operational consequence sit at the heart of water cyber resilience.

  • Convenience connectivity is now a systemic risk
  • Physical path control is missing from most reference architectures
02

The control layers, Firebreak included

A plain-English explanation of Firebreak Layer 1 path control, the Control modules that sit around it and the offline recovery copy behind them, and how all three complement, never replace, firewalls, segmentation and monitoring.

  • Firebreak sits below the firewall, not beside it
  • Isolate, Validate, Relay and Archive govern what happens when a path is open
  • Offline Secure Storage® holds the copy the incident cannot reach
03

Control blueprint for water

From bridge to controlled exchange. Where the Control by Firevault modules and offline recovery copies sit across Purdue levels 0–3.5 and the IT/OT boundary.

  • A defensible reference architecture for OT engineering
  • Clear ownership boundaries between IT and OT
04

Deployment use cases

IT/OT boundary, SCADA protection, supplier access, remote sites, legacy systems, isolation and recovery, aviation air-lock, seven patterns end-to-end.

  • Each use case maps to a named Control module
  • Every pattern includes an evidence trail for regulators
05

Adoption model

Ownership, selection and command design: who decides the path, who opens it, and how the evidence is captured.

  • Path decisions become auditable events
  • Ownership sits with operations, not the supplier
06

Pilot to rollout

Four steps from assessment to company-wide deployment, with a pilot acceptance pack the board can sign off.

  • A pilot is judged on reach, authority, evidence and recovery
  • Rollout is staged by consequence, not geography
03Who it's for

Read it if you're accountable for the decision.

  • Water boards and executive teams
  • CISOs and heads of OT security
  • Network and control-system architects
  • Regulators and CNI programme leads

Sectors we hear from

Water & wastewaterEnergy & utilitiesCritical national infrastructureGovernment & defence
04A look inside

Real pages from the playbook.

A short preview of what lands in your inbox.

Control for Water: Deployment Playbook preview, Standing connectivity
Standing connectivity Full page in playbook
Control for Water: Deployment Playbook preview, Physical vs logical control
Physical vs logical control Full page in playbook
Control for Water: Deployment Playbook preview, IT / OT boundary
IT / OT boundary Full page in playbook
Control for Water: Deployment Playbook preview, Isolation and recovery
Isolation and recovery Full page in playbook
05Frequently asked

Questions leaders ask before requesting.

Something else on your mind? Reply to any Firevault email or write to founders@fire-vault.com.

Ready to read it?

Request Control for Water. Access opens on this page straight away, so you can read it here and download the PDF. We email a secure link to the same address as a backup.