Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
All Control Blueprints
FIRE-ledCP-07Controls the path

Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

All Blueprints
What it does

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

Where it fits

Aerospace, aviation and MRO ground networks with air-lock ingress control

Who uses it

Aerospace, Aviation, Defence, MRO and ground operations, Airport IT

CP-07 topology

How CP-07 protects aviation and aerospace networks.

A FIRE-led pattern for aerospace and aviation. Incoming traffic to ground IT, MRO benches and airport operational networks is blocked at Layer 1 by default. Reach exists only as an air-lock cycle: validated request, outer door opens, inner door opens, session runs, both doors close.

Grounded in EASA Part-IS, FAA InfoSec Handbook 1370.121, ICAO Doc 8973 and IEC 62443-3-3 SR 5.1.

Z0

External and vendor

Airlines, MRO

External and vendor zone

Airlines, MRO suppliers, OEM update services and remote engineers

FV-Firebreak module iconFirebreakFV-Validate module iconValidateFV-Relay module iconRelay

Outer door. Closed by default. Opens only on a validated, time-bound request.

Z1

Aviation air-lock

The only

Aviation air-lock zone

The only place an incoming session ever lands, held between two hardware doors

FV-Isolate module iconIsolateFV-Execute module iconExecuteFV-Lock module iconLock

Inner door. Opens only after the outer door is proved closed, and severs on signal.

Z2

Ground and MRO operations

Airline IT,

Ground and MRO operations zone

Airline IT, dispatch, load control, MRO test benches and airport operational systems

OSS

Crown jewels · detail callout

Airworthiness evidence vault

Signed logs of every air-lock cycle, software load and configuration change held offline for the airworthiness and regulator record.

Modules & symbols

FV-Firebreak module iconFirebreakPhysical sever
FV-Validate module iconValidateIntegrity check
FV-Relay module iconRelayTime-bound path
FV-Isolate module iconIsolateZone boundary
FV-Execute module iconExecuteApproved action
FV-Lock module iconLockNamed access
ConduitEnforced module path
┄┄┄
Crown jewelsOffline · detail callout
How it reads end to end

Firebreak holds the boundary closed by default, so no incoming session, sync or update reaches airline IT, MRO, avionics test benches or airport operational networks unless explicitly opened. Isolate keeps flight-critical, ground handling and corporate zones physically apart. Validate checks every ingress request against identity, authority and airworthiness policy before the air-lock cycles. Relay opens the inner door only after the outer one is proved closed, then closes it again on schedule. Lock, Archive and Execute preserve who did what, and revoke the window on signal.

Sector relevance
AerospaceAviationDefenceMRO and ground operationsAirport IT
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Build control around your environment

Talk to our team about composing this Blueprint for your estate.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up