Recent Breaches
Breaches
View All →
All Control Blueprints
FIRE-ledCP-02Controls the path

Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

All Blueprints
What it does

When prevention fails, containment must be physical, immediate and provable.

Where it fits

Live incident containment and recovery

Who uses it

Financial services, Energy, Public sector, Defence

CP-02 topology

How CP-02 contains a live incident.

A FIRE-led pattern for live containment. Affected zones are severed at the conduit, recovery zones are reached only through an authorised Execute event.

Grounded in NIST CSF RS.MI-1, IEC 62443-3-3 FR 6 and the CISA Incident Response Playbook.

Z0

Affected zone

Where the

Affected zone zone

Where the live incident is unfolding

FirebreakIsolate

Severed on alert. Blast radius bounded.

Z1

Unaffected production

Operational zones

Unaffected production zone

Operational zones still running

ExecuteLockArchive

Reach into forensic and recovery only as an approved event.

Z2

Forensic and recovery zone

Where evidence

Forensic and recovery zone zone

Where evidence is held and recovery is staged

OSS

Crown jewels · detail callout

Sealed evidence and recovery vault

Logs, snapshots and golden images sealed offline for the incident response and any later investigation.

Modules & symbols

FirebreakPhysical sever
IsolateZone boundary
ExecuteApproved action
LockNamed access
ArchiveDisconnected copy
ConduitEnforced module path
┄┄┄
Crown jewelsOffline · detail callout
How it reads end to end

Firebreak disconnects the exposed path. Isolate contains the breach area. Execute allows immediate action during a live incident. Archive preserves logs, evidence and recovery points while Lock protects what remains as recovery begins.

Sector relevance
Financial servicesEnergyPublic sectorDefence
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Build control around your environment

Talk to our team about composing this Blueprint for your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®