Recent Breaches
Breaches
View All →
All Control Blueprints
FIRE-ledCP-04Controls the path

Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

All Blueprints
What it does

Segmentation should not just be logical. It should be physically enforceable.

Where it fits

Trust boundary enforcement between zones

Who uses it

Defence, Critical infrastructure, Public sector, Manufacturing

CP-04 topology

How CP-04 enforces physical segmentation.

A FIRE-led pattern. Zones are physically separated; always-on dependencies between them are removed; any temporary crossing is a named, time-bound event.

Grounded in IEC 62443-3-3 SR 5.1 to SR 5.3 and the Purdue Enterprise Reference Architecture.

Z0

Zone A

First trust

Zone A zone

First trust domain (for example, IT enterprise)

FirebreakIsolateUnlink

Default-severed boundary with no inherited trust.

Z1

Zone B

Second trust

Zone B zone

Second trust domain (for example, OT supervisory)

FirebreakLockRelay

Crossing exists only as a named, time-bound Relay session.

Z2

Zone C

Third trust

Zone C zone

Third trust domain (for example, field or process)

OSS

Crown jewels · detail callout

Authoritative configuration vault

Zone and conduit definitions held offline so they cannot be silently re-drawn from a compromised admin tier.

Modules & symbols

FirebreakPhysical sever
IsolateZone boundary
UnlinkRemove trust
LockNamed access
RelayTime-bound path
ConduitEnforced module path
┄┄┄
Crown jewelsOffline · detail callout
How it reads end to end

Firebreak controls the physical path between zones. Isolate separates environments at hardware level. Unlink removes always-on dependencies that quietly tunnel between them. Lock and Relay govern when and how a temporary crossing is ever allowed.

Sector relevance
DefenceCritical infrastructurePublic sectorManufacturing
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Build control around your environment

Talk to our team about composing this Blueprint for your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®