---
title: "Protect Critical Infrastructure by Firevault - Control Blue…"
url: https://fire-vault.com/control-blueprints/cp-05
description: "Keep critical systems available, controlled and disconnected from unnecessary exposure."
lang: en-GB
---

FIRE + VAULT · CP-05

# Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

- CP-05
- Path and asset together

Read the guide: https://fire-vault.com/learn/guides/protecting-critical-infrastructure-control-blueprint

All Blueprints: https://fire-vault.com/control-blueprints

Image: Control Blueprint CP-05, Protect Critical Infrastructure: an isometric diagram of an industrial site with a single controlled entry gate (https://fire-vault.com/__l5e/assets-v1/504e7d61-228d-469e-aa2f-86ebe3981f88/blueprint-cp-05-hero.webp)

01 At a glance

## What this Blueprint does.

OT and CNI connectivity with maintenance windows

What it does

Where it fits

Who uses it

Energy, Critical infrastructure, Defence, Manufacturing

CP-05 topology

## How CP-05 protects critical infrastructure.

A FIRE+VAULT pattern for OT and CNI. Process zones run normally; maintenance and supervisory reach exist only through governed, time-bound conduits.

Grounded in IEC 62443-3-3 (FR 5, FR 7), NIS2 Annex I and the NCSC Cyber Assessment Framework B4.

Z0

Enterprise IT

Office, mail,

Enterprise IT zone

Office, mail, ERP, identity

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

IT-to-OT conduit is severed by default and opened as a named window.

Z1

Supervisory and engineering

SCADA, historian,

Supervisory and engineering zone

SCADA, historian, engineering workstations

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Engineering reach is scoped, approved and verified.

Z2

Process control and field

PLCs, RTUs,

Process control and field zone

PLCs, RTUs, HMIs, sensors and actuators

OSS

Crown jewels · detail callout

Operational evidence and golden image vault

Operational records and golden PLC images sealed offline for safe recovery and audit.

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Conduit Enforced module path

┄┄┄

Crown jewels Offline · detail callout

02 Modules in this Blueprint

## How the CP-05 pattern composes.

How the primary modules compose

1. 1
   Firebreak FIRE
   Physically breaks the connection path so the attack cannot continue.
   https://fire-vault.com/control/modules/firebreak
2. 2
   Isolate FIRE
   Separates the affected environment into a controlled zone.
   https://fire-vault.com/control/modules/isolate
3. 3
   Relay FIRE
   Opens a temporary, time-bound window for an approved purpose.
   https://fire-vault.com/control/modules/relay
4. 4
   Execute FIRE
   Fires the control action the moment a signal demands it.
   https://fire-vault.com/control/modules/execute

Supporting modules

- Transfer VAULT
  Governs what moves between protected environments.
  https://fire-vault.com/control/modules/transfer
- Archive VAULT
  Preserves the records, logs and evidence the control produced.
  https://fire-vault.com/control/modules/archive
- Lock VAULT
  Holds the asset behind identity, role and policy controls.
  https://fire-vault.com/control/modules/lock

03 How it reads end to end

## The Blueprint in full.

Firebreak controls connectivity at the physical layer. Isolate separates operational systems. Relay opens approved maintenance, patching or supervisory windows. Execute can revoke access instantly. Transfer governs data movement, Archive preserves operational evidence and Lock holds access tight.

04 Sector relevance

## Where CP-05 applies.

Energy Critical infrastructure Defence Manufacturing

05 Related Blueprints

## Compose alongside.

See all: https://fire-vault.com/control-blueprints

CP-03 FIRE + VAULT

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

View Blueprint
https://fire-vault.com/control-blueprints/cp-03

CP-08 FIRE + VAULT

### Control AI Systems

The AI Control Blueprint: bound what an AI system can reach, and keep a stop that the model cannot argue with.

View Blueprint
https://fire-vault.com/control-blueprints/cp-08

CP-01 FIRE-led

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View Blueprint
https://fire-vault.com/control-blueprints/cp-01

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Build control around your environment

Talk to our team about composing this Blueprint for your estate.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-blueprints/cp-05#webpage",
    "url": "https://fire-vault.com/control-blueprints/cp-05",
    "name": "Protect Critical Infrastructure by Firevault - Control Blue…",
    "description": "Keep critical systems available, controlled and disconnected from unnecessary exposure.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/43ece632-a099-4e7a-bc2d-64e687b31877/og-blueprint-cp-05.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-blueprints/cp-05#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-blueprints/cp-05#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control Blueprints",
        "item": "https://fire-vault.com/control-blueprints"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Protect Critical Infrastructure by Firevault - Control Blue…",
        "item": "https://fire-vault.com/control-blueprints/cp-05"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "TechArticle",
    "headline": "Protect Critical Infrastructure - Control Blueprint CP-05",
    "description": "Keep critical systems available, controlled and disconnected from unnecessary exposure.",
    "author": {
      "@type": "Organization",
      "name": "Firevault"
    },
    "publisher": {
      "@type": "Organization",
      "name": "Firevault",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png"
      }
    },
    "mainEntityOfPage": "https://fire-vault.com/control-blueprints/cp-05",
    "about": {
      "@type": "Thing",
      "name": "Control Blueprint CP-05"
    }
  }
]
```