---
title: "Enforce Physical Segmentation by Firevault - Control Bluepr…"
url: https://fire-vault.com/control-blueprints/cp-04
description: "Segmentation should not just be logical. It should be physically enforceable."
lang: en-GB
---

FIRE-led · CP-04

# Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

- CP-04
- Controls the path

Read the guide: https://fire-vault.com/learn/guides/enforcing-physical-segmentation-control-blueprint

All Blueprints: https://fire-vault.com/control-blueprints

Image: Control Blueprint CP-04, Enforce Physical Segmentation: an isometric diagram of two environments divided by a physically enforced wall (https://fire-vault.com/__l5e/assets-v1/4b36508e-42df-4d29-8d03-a62998e43604/blueprint-cp-04-hero.webp)

01 At a glance

## What this Blueprint does.

Trust boundary enforcement between zones

What it does

Where it fits

Who uses it

Defence, Critical infrastructure, Public sector, Manufacturing

CP-04 topology

## How CP-04 enforces physical segmentation.

A FIRE-led pattern. Zones are physically separated; always-on dependencies between them are removed; any temporary crossing is a named, time-bound event.

Grounded in IEC 62443-3-3 SR 5.1 to SR 5.3 and the Purdue Enterprise Reference Architecture.

Z0

Zone A

First trust

Zone A zone

First trust domain (for example, IT enterprise)

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
Unlink

Default-severed boundary with no inherited trust.

Z1

Zone B

Second trust

Zone B zone

Second trust domain (for example, OT supervisory)

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay

Crossing exists only as a named, time-bound Relay session.

Z2

Zone C

Third trust

Zone C zone

Third trust domain (for example, field or process)

OSS

Crown jewels · detail callout

Authoritative configuration vault

Zone and conduit definitions held offline so they cannot be silently re-drawn from a compromised admin tier.

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
Unlink Remove trust

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Conduit Enforced module path

┄┄┄

Crown jewels Offline · detail callout

02 Modules in this Blueprint

## How the CP-04 pattern composes.

How the primary modules compose

1. 1
   Firebreak FIRE
   Physically breaks the connection path so the attack cannot continue.
   https://fire-vault.com/control/modules/firebreak
2. 2
   Isolate FIRE
   Separates the affected environment into a controlled zone.
   https://fire-vault.com/control/modules/isolate
3. 3
   Unlink VAULT
   Removes the persistent dependencies that quietly bypass the control.
   https://fire-vault.com/control/modules/unlink

Supporting modules

- Lock VAULT
  Holds the asset behind identity, role and policy controls.
  https://fire-vault.com/control/modules/lock
- Relay FIRE
  Opens a temporary, time-bound window for an approved purpose.
  https://fire-vault.com/control/modules/relay

03 How it reads end to end

## The Blueprint in full.

Firebreak controls the physical path between zones. Isolate separates environments at hardware level. Unlink removes always-on dependencies that quietly tunnel between them. Lock and Relay govern when and how a temporary crossing is ever allowed.

04 Sector relevance

## Where CP-04 applies.

Defence Critical infrastructure Public sector Manufacturing

05 Related Blueprints

## Compose alongside.

See all: https://fire-vault.com/control-blueprints

CP-01 FIRE-led

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View Blueprint
https://fire-vault.com/control-blueprints/cp-01

CP-02 FIRE-led

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View Blueprint
https://fire-vault.com/control-blueprints/cp-02

CP-07 FIRE-led

### Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

View Blueprint
https://fire-vault.com/control-blueprints/cp-07

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Build control around your environment

Talk to our team about composing this Blueprint for your estate.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-blueprints/cp-04#webpage",
    "url": "https://fire-vault.com/control-blueprints/cp-04",
    "name": "Enforce Physical Segmentation by Firevault - Control Bluepr…",
    "description": "Segmentation should not just be logical. It should be physically enforceable.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/e7bae73d-cf05-42fe-8b6d-f2a095e51d38/og-blueprint-cp-04.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-blueprints/cp-04#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-blueprints/cp-04#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control Blueprints",
        "item": "https://fire-vault.com/control-blueprints"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Enforce Physical Segmentation by Firevault - Control Bluepr…",
        "item": "https://fire-vault.com/control-blueprints/cp-04"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "TechArticle",
    "headline": "Enforce Physical Segmentation - Control Blueprint CP-04",
    "description": "Segmentation should not just be logical. It should be physically enforceable.",
    "author": {
      "@type": "Organization",
      "name": "Firevault"
    },
    "publisher": {
      "@type": "Organization",
      "name": "Firevault",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png"
      }
    },
    "mainEntityOfPage": "https://fire-vault.com/control-blueprints/cp-04",
    "about": {
      "@type": "Thing",
      "name": "Control Blueprint CP-04"
    }
  }
]
```