Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026Lidl GBCustomer contact data (subset via supplier) records stolen2026Asahi GroupProduction systems disrupted records stolen2026Kido InternationalPhotos and personal data of ~8,000 children records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Lidl GBCustomer contact data (subset via supplier) records stolen2026Asahi GroupProduction systems disrupted records stolen2026Kido InternationalPhotos and personal data of ~8,000 children records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Adidas UKCustomer contact details (subset) records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →
All Control Blueprints
FIRE-ledCP-01Controls the path

Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

All Blueprints
What it does

Stop ransomware moving, spreading or reaching the crown jewels.

Where it fits

Lateral movement prevention across IT and OT

Who uses it

Financial services, Healthcare, Public sector, Defence

CP-01 topology

How CP-01 stops the kill chain.

A FIRE-led pattern. The path between any compromised zone and the crown jewels is severed by default, opened only as a named event, and severed again on alert.

Grounded in MITRE ATT&CK TA0008, IEC 62443-3-3 SR 5.1 and NCSC ransomware guidance.

Z0

User and endpoint zone

Where the

User and endpoint zone zone

Where the foothold typically lands

FV-Isolate module iconIsolateFV-Lock module iconLock

Named, scoped reach into core services

Z1

Core IT services

Identity, file,

Core IT services zone

Identity, file, mail, collaboration

FV-Firebreak module iconFirebreakFV-Execute module iconExecuteFV-Unlink module iconUnlink

Severed by default. Restored only as an approved Execute event.

Z2

Crown-jewel systems

Database, ERP,

Crown-jewel systems zone

Database, ERP, core record systems

OSS

Crown jewels · detail callout

Offline recovery vault

Tamper-evident copies, not reachable on the live network. The ransomware cannot touch them.

Modules & symbols

FV-Isolate module iconIsolateZone boundary
FV-Lock module iconLockNamed access
FV-Firebreak module iconFirebreakPhysical sever
FV-Execute module iconExecuteApproved action
FV-Unlink module iconUnlinkRemove trust
ConduitEnforced module path
┄┄┄
Crown jewelsOffline · detail callout
How it reads end to end

Firebreak physically breaks the connection path. Isolate separates the affected environment. Execute triggers the control action the moment risk is detected. Unlink removes the persistent dependencies and Lock holds the crown jewels behind identity controls that ransomware cannot reach.

Sector relevance
Financial servicesHealthcarePublic sectorDefence
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Build control around your environment

Talk to our team about composing this Blueprint for your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy