Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →

Control Blueprints

FIRE controls the path. VAULT protects the asset.

Seven buyer-led Blueprints. Each one names its lead layer, the primary modules that deliver it, and the supporting modules that round it out.

7
Blueprints
9
Modules
3
Lead types

What a Blueprint is

A pattern. A lead layer. A defined set of modules.

FIRE-led

Controls the path. Disconnects, isolates and severs the route the attack would take.

VAULT-led

Protects the asset. Holds the data, identity and evidence behind verifiable controls.

FIRE + VAULT

Path and asset together. Used where access must be controlled and what it touches must be locked.

Blueprints in play

See the modules compose a Blueprint.

Deal nine modules into a path. Firebreak lands on the gate and the route severs. Click any card to pause.

How to read this
The cards are modules. The line is the path between the user and the asset. Each Blueprint chooses which modules sit on the path and which support it.
Zone A
Segment A hosts
Zone B
Segment B hosts
High-Trust Enclave
Classified, secrets
Zone A
Segment A hosts
Open
Zone B
Segment B hosts
Open
High-Trust Enclave
Classified, secrets

3P·Open access only when required, close on completion.

Module deck
Fb
Firebreak module icon
Firebreak
Is
Isolate module icon
Isolate
Re
Relay module icon
Relay
Ex
Execute module icon
Execute
Un
Unlink module icon
Unlink
Va
Validate module icon
Validate
Ar
Archive module icon
Archive
Lo
Lock module icon
Lock
Tr
Transfer module icon
Transfer
Fire, path controlProtect, asset protection

The seven Blueprints

Pick a Blueprint to see the modules in detail.

Filter by lead layer, module or sector to narrow the patterns that fit your environment.

Showing 7 of 7 Blueprints
CP-01FIRE-led

Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

Primary modules
FirebreakIsolateExecute
Supporting
UnlinkLock
Financial servicesHealthcarePublic sectorDefence
View Blueprint
CP-02FIRE-led

Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

Primary modules
FirebreakIsolateExecute
Supporting
ArchiveLock
Financial servicesEnergyPublic sectorDefence
View Blueprint
CP-03FIRE + VAULT

Control Third-Party Access

Give third parties access without giving them a permanent doorway.

Primary modules
ValidateRelayLock
Supporting
TransferArchiveExecute
Financial servicesHealthcareEnergyPublic sector
View Blueprint
CP-04FIRE-led

Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

Primary modules
FirebreakIsolateUnlink
Supporting
LockRelay
DefenceCritical infrastructurePublic sectorManufacturing
View Blueprint
CP-05FIRE + VAULT

Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

Primary modules
FirebreakIsolateRelayExecute
Supporting
TransferArchiveLock
EnergyCritical infrastructureDefenceManufacturing
View Blueprint
CP-06VAULT-led

Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

Primary modules
ValidateLockArchive
Supporting
TransferRelayExecuteFirebreak
Financial servicesHealthcarePublic sectorCritical infrastructure
View Blueprint
CP-07FIRE-led

Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

Primary modules
FirebreakIsolateValidateRelay
Supporting
LockArchiveExecute
AerospaceAviationDefenceMRO and ground operations
View Blueprint

The nine modules

Every Blueprint is built from these.

Firebreak module icon
FirebreakFIRE

Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.

Isolate module icon
IsolateFIRE

Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.

Relay module icon
RelayFIRE

Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.

Execute module icon
ExecuteFIRE

Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.

Validate module icon
ValidateVAULT

Checks whether a request, command or approval should proceed before access, action or transfer is allowed.

Archive module icon
ArchiveVAULT

Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.

Unlink module icon
UnlinkVAULT

Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.

Lock module icon
LockVAULT

Restricts access through identity, authority, policy, permission and operational controls.

Transfer module icon
TransferVAULT

Controls how sensitive assets move into, out of or between protected environments through approved paths.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Compose Control for your environment

Talk to our team about combining these Blueprints around your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy