---
title: "Control for Water: Deployment Playbook | Firevault"
description: "A 28-page deployment playbook for water boards, CISOs, OT leaders and network architects. Firebreak® Layer 1 path control, the wider Control by Firevault…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/playbook/firebreak-water#webpage",
      "url": "https://fire-vault.com/playbook/firebreak-water",
      "name": "Control for Water: Deployment Playbook",
      "description": "A 28-page deployment playbook for water boards, CISOs, OT leaders and network architects. Firebreak® Layer 1 path control, the wider Control by Firevault…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/87198e25-711c-49ab-95d1-5f7cc99553cb/firebreak-water-cover.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/playbook/firebreak-water#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/playbook/firebreak-water#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Playbooks",
          "item": "https://fire-vault.com/playbooks"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Control for Water: Deployment Playbook",
          "item": "https://fire-vault.com/playbook/firebreak-water"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Control for Water: Deployment Playbook",
      "description": "A 28-page deployment playbook for water boards, CISOs, OT leaders and network architects. Firebreak® Layer 1 path control, the wider Control by Firevault modules and Offline Secure Storage® recovery copies, mapped against the Purdue model.",
      "inLanguage": "en-GB",
      "author": [
        {
          "@type": "Person",
          "name": "Mark Fermor"
        },
        {
          "@type": "Person",
          "name": "David Bailey"
        }
      ],
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "url": "https://fire-vault.com"
      },
      "image": "/__l5e/assets-v1/87198e25-711c-49ab-95d1-5f7cc99553cb/firebreak-water-cover.jpg",
      "keywords": "water sector cyber security, OT cyber security playbook, Purdue model physical segmentation, SCADA path control, IT OT boundary, Layer 1 physical isolation, Offline Secure Storage for utilities, Control by Firevault water blueprint",
      "mainEntityOfPage": "https://fire-vault.com/playbook/firebreak-water"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is Control for Water?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Control for Water is the Firevault control model for water and wastewater operations. It governs which connectivity paths may exist, for what purpose, for how long and under whose authority, across the treatment works, pumping stations, remote telemetry sites and the IT/OT boundary that link them."
          }
        },
        {
          "@type": "Question",
          "name": "Where does Firebreak fit in Control for Water?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Firebreak® is the Layer 1 path control module within Control by Firevault. It sits below the firewall and decides whether a physical route exists at all, so a compromised rule, credential or supplier session has no standing path to use. Firewalls, segmentation and monitoring continue to do what they do best above it."
          }
        },
        {
          "@type": "Question",
          "name": "Which control modules does a water operator normally deploy?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Isolate, Validate, Relay and Archive govern what happens while a path is open: who authorised it, what may cross it, what is inspected and what is written to an unreachable copy. Firebreak decides whether the path exists in the first place. Most operators start with the IT/OT boundary and remote sites, then extend to supplier access and legacy systems."
          }
        },
        {
          "@type": "Question",
          "name": "How does Control for Water map onto the Purdue model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The Control modules map against Purdue levels 0 to 3.5 and the IT/OT boundary, so architects can see exactly where physical path control belongs alongside existing zones and conduits rather than replacing them."
          }
        },
        {
          "@type": "Question",
          "name": "Where does Offline Secure Storage® fit?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Control governs the path; Offline Secure Storage® holds the recovery copy that an incident on that path cannot reach. For water operators that means configuration baselines, control-system backups, historian extracts and engineering records kept physically beyond the reach of the connected estate."
          }
        },
        {
          "@type": "Question",
          "name": "Does Control for Water support NIS2, the Security and Emergency Measures Direction and DORA-style evidence?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Every path decision becomes an auditable event with a named authoriser, a purpose and a duration, which is the evidence regulators and boards ask for when they question whether connectivity is intentional rather than inherited."
          }
        },
        {
          "@type": "Question",
          "name": "How does an operator pilot this without disrupting supply?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pilots are scoped by consequence, not by geography: one boundary or one remote site, judged on reach, authority, evidence and recovery. Nothing is removed from the existing architecture during a pilot, so a rollback is a physical decision rather than a change programme."
          }
        },
        {
          "@type": "Question",
          "name": "Can you brief my board or OT team?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Reply to the delivery email and we will arrange a working session with Mark or David for your board, OT team or architecture group."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Playbooks",
          "item": "https://fire-vault.com/playbooks"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Control for Water: Deployment Playbook",
          "item": "https://fire-vault.com/playbook/firebreak-water"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

1.  [Home](/)
2.  [Playbooks](/playbooks)
3.  Control for Water Playbook

Control for Water Playbook 

# Control for Water  
Deployment Playbook 

Control the path. Protect the supply. Keep a clean copy.

A 28-page deployment playbook for water boards, CISOs, OT leaders and network architects. Firebreak® Layer 1 path control, the wider Control by Firevault modules and Offline Secure Storage® recovery copies, mapped against the Purdue model.

28 pages

22 min read

Water boards and executive teams

![Control for Water: Deployment Playbook cover](/__l5e/assets-v1/87198e25-711c-49ab-95d1-5f7cc99553cb/firebreak-water-cover.jpg)

## Get the playbook

Emailed to you within a minute

First name \*

Last name \*

Work email \*

Personal email addresses such as Gmail or Yahoo are not accepted.

Company \*

Sector \*Select one, ... 

Job title \*

I agree to receive the playbook and occasional Firevault briefings. See our [privacy policy](/privacy-charter). 

Email me and open the playbook

Email-gated  GDPR compliant 

01 Foreword 

## Written by the people who build the controls.

The water sector's connectivity story has been written by convenience, not by design. Remote sites, third-party support, engineering tools and telemetry now share paths that were never intended to carry them.

**Mark Fermor** · Co-Founder, Firevault 

**David Bailey** · Co-Founder, Firevault 

> The doctrine
> 
> Control the path. Govern the agent. Protect the asset.
> 
> Every Firevault playbook is grounded in the same doctrine behind our Offline Secure Storage® platform, so a decision taken in one chapter still holds in the next.

The Control for Water Playbook is a practical response. It explains, in plain language, how Firebreak Layer 1 physical path control complements existing firewalls and segmentation, where the wider Control by Firevault modules and Offline Secure Storage® recovery copies belong on the Purdue model, and how a water operator can pilot and scale the whole pattern without ripping up what already works.

It is written for the boards, CISOs, OT leaders and architects who now have to prove, to regulators and to themselves, that every connectivity choice is intentional and evidenced.

02 What's inside 

## 6 parts. Written for the people who own the decision.

Each chapter opens with the decision it exists to help you make, and closes with the evidence you should expect back.

01

### The water-sector control problem

Why standing connectivity, third-party access and operational consequence sit at the heart of water cyber resilience.

-   Convenience connectivity is now a systemic risk 
-   Physical path control is missing from most reference architectures 

02

### The control layers, Firebreak included

A plain-English explanation of Firebreak Layer 1 path control, the Control modules that sit around it and the offline recovery copy behind them, and how all three complement, never replace, firewalls, segmentation and monitoring.

-   Firebreak sits below the firewall, not beside it 
-   Isolate, Validate, Relay and Archive govern what happens when a path is open 
-   Offline Secure Storage® holds the copy the incident cannot reach 

03

### Control blueprint for water

From bridge to controlled exchange. Where the Control by Firevault modules and offline recovery copies sit across Purdue levels 0–3.5 and the IT/OT boundary.

-   A defensible reference architecture for OT engineering 
-   Clear ownership boundaries between IT and OT 

04

### Deployment use cases

IT/OT boundary, SCADA protection, supplier access, remote sites, legacy systems, isolation and recovery, aviation air-lock, seven patterns end-to-end.

-   Each use case maps to a named Control module 
-   Every pattern includes an evidence trail for regulators 

05

### Adoption model

Ownership, selection and command design: who decides the path, who opens it, and how the evidence is captured.

-   Path decisions become auditable events 
-   Ownership sits with operations, not the supplier 

06

### Pilot to rollout

Four steps from assessment to company-wide deployment, with a pilot acceptance pack the board can sign off.

-   A pilot is judged on reach, authority, evidence and recovery 
-   Rollout is staged by consequence, not geography 

03 Who it's for 

## Read it if you're accountable for the decision.

-   Water boards and executive teams 
-   CISOs and heads of OT security 
-   Network and control-system architects 
-   Regulators and CNI programme leads 

Sectors we hear from

Water & wastewater Energy & utilities Critical national infrastructure Government & defence 

04 A look inside 

## Real pages from the playbook.

A short preview of what lands in your inbox.

![Control for Water: Deployment Playbook preview, Standing connectivity](/__l5e/assets-v1/2232048b-606b-4dd7-aaa5-b63acb05cf37/firebreak-water-spread1.jpg)

Standing connectivity  Full page in playbook 

![Control for Water: Deployment Playbook preview, Physical vs logical control](/__l5e/assets-v1/e0bae3d3-9ab8-4f81-ac15-1af9ef30c255/firebreak-water-spread2.jpg)

Physical vs logical control  Full page in playbook 

![Control for Water: Deployment Playbook preview, IT / OT boundary](/__l5e/assets-v1/bcd32d35-47c9-4d9f-95ca-f39b0e85c687/firebreak-water-spread3.jpg)

IT / OT boundary  Full page in playbook 

![Control for Water: Deployment Playbook preview, Isolation and recovery](/__l5e/assets-v1/3afb37a0-50fc-49a3-a55e-2b99cfd8cd57/firebreak-water-spread4.jpg)

Isolation and recovery  Full page in playbook 

05 Frequently asked 

## Questions leaders ask before requesting.

Something else on your mind? Reply to any Firevault email or write to [founders@fire-vault.com](mailto:founders@fire-vault.com).

### What is Control for Water? 

### Where does Firebreak fit in Control for Water? 

### Which control modules does a water operator normally deploy? 

### How does Control for Water map onto the Purdue model? 

### Where does Offline Secure Storage® fit? 

### Does Control for Water support NIS2, the Security and Emergency Measures Direction and DORA-style evidence? 

### How does an operator pilot this without disrupting supply? 

### Can you brief my board or OT team? 

06 More Firevault playbooks 

## Board-level control blueprints.

Each playbook is written for the people who own the decision, practical, UK-grounded and free to request.

[

![The Leaders' Playbook cover](/__l5e/assets-v1/e8c2b388-0083-4aa9-a143-f8c4b11d2db3/leaders-cover.jpg)Read The Leaders' Playbook ](/playbook/leaders)

Related playbook

### The Leaders' Playbook

A board-level briefing on sovereign data, succession resilience and physical protection.

28 pages  18 min read  Email-gated 

[Get the playbook](/playbook/leaders)

[

![A Control Blueprint for AI: 2026 Playbook cover](/__l5e/assets-v1/d10e0e16-e107-4d93-b690-87f7b33bea9b/ai-control-cover.jpg)Read A Control Blueprint for AI: 2026 Playbook ](/playbook/ai-control-blueprints)

Related playbook

### A Control Blueprint for AI: 2026 Playbook

40-page blueprint on AI infrastructure, open weights, agents and kill-switch design.

40 pages  28 min read  Email-gated 

[Get the playbook](/playbook/ai-control-blueprints)

[

![Close the File. Protect the Record. cover](/__l5e/assets-v1/a563c7e7-cdd3-47c3-8557-57a4d04b97b7/legal-cover.jpg)Read Close the File. Protect the Record. ](/playbook/legal)

Related playbook

### Close the File. Protect the Record.

File closure, retained records and offline custody for UK law firms.

28 pages  20 min read  Email-gated 

[Get the playbook](/playbook/legal)

[

![A Control Blueprint for Aerospace & Aviation cover](/__l5e/assets-v1/bb5110b1-edcd-4a3a-93fc-af134ae6e4b7/aerospace-cover.jpg)Read A Control Blueprint for Aerospace & Aviation ](/playbook/aerospace)

Related playbook

### A Control Blueprint for Aerospace & Aviation

Communication registers, operational states and rapid isolation for aerospace and aviation.

28 pages  22 min read  Email-gated 

[Get the playbook](/playbook/aerospace)

## Ready to read it?

Request Control for Water. Access opens on this page straight away, so you can read it here and download the PDF. We email a secure link to the same address as a backup.

[Get the playbook](#get-the-playbook)[Talk to Mark](mailto:founders@fire-vault.com)