---
title: "Protect Maritime and Commercial Shipping by Firevault - Con…"
url: https://fire-vault.com/control-blueprints/cp-09
description: "Keep vessel, port and terminal operations separated, with remote access that exists only for an approved voyage or maintenance window."
lang: en-GB
---

FIRE-led · CP-09

# Protect Maritime and Commercial Shipping

Keep vessel, port and terminal operations separated, with remote access that exists only for an approved voyage or maintenance window.

- CP-09
- Controls the path

All Blueprints: https://fire-vault.com/control-blueprints

Image: Control Blueprint CP-09, Protect Maritime and Commercial Shipping: a commercial vessel and port terminal separated by a physically controlled operational boundary (https://fire-vault.com/assets/blueprint-cp-09-hero-DrzOLqys.webp)

01 At a glance

## What this Blueprint does.

Commercial vessels, ports and terminals with local control of operational and supplier paths

What it does

Where it fits

Who uses it

Maritime, Commercial shipping, Ports and terminals, Logistics, Offshore operations

CP-09 topology

## How CP-09 protects maritime and commercial shipping.

A FIRE-led pattern for vessels, ports and terminals. Shore, supplier and satellite paths stay closed by default. Vessel and terminal operations remain separated, and approved access exists only as a validated, time-bound window.

Z0

Shore and remote services

Suppliers, fleet

Shore and remote services zone

Suppliers, fleet management, satellite, private 5G and port services

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay

Closed by default. Opens only for an approved, time-bound request.

Z1

Controlled exchange

The only

Controlled exchange zone

The only place approved maintenance, updates or cargo data cross

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Operational reach is separated and can be severed locally on signal.

Z2

Vessel and terminal operations

Bridge support,

Vessel and terminal operations zone

Bridge support, vessel OT, cargo handling, cranes, gates and terminal systems

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Conduit Enforced module path

┄┄┄

Crown jewels Offline · detail callout

02 Modules in this Blueprint

## How the CP-09 pattern composes.

How the primary modules compose

1. 1
   Firebreak FIRE
   Physically breaks the connection path so the attack cannot continue.
   https://fire-vault.com/control/modules/firebreak
2. 2
   Isolate FIRE
   Separates the affected environment into a controlled zone.
   https://fire-vault.com/control/modules/isolate
3. 3
   Validate VAULT
   Checks the request, command or approval before anything proceeds.
   https://fire-vault.com/control/modules/validate
4. 4
   Relay FIRE
   Opens a temporary, time-bound window for an approved purpose.
   https://fire-vault.com/control/modules/relay
5. 5
   Execute FIRE
   Fires the control action the moment a signal demands it.
   https://fire-vault.com/control/modules/execute

Supporting modules

- Lock VAULT
  Holds the asset behind identity, role and policy controls.
  https://fire-vault.com/control/modules/lock
- Archive VAULT
  Preserves the records, logs and evidence the control produced.
  https://fire-vault.com/control/modules/archive
- Transfer VAULT
  Governs what moves between protected environments.
  https://fire-vault.com/control/modules/transfer

03 How it reads end to end

## The Blueprint in full.

Firebreak holds the routes between shore, vessel and terminal operations closed by default. Isolate separates bridge and navigation-support systems, vessel operational technology, cargo handling, port equipment and corporate IT. Validate checks remote supplier, update and data-exchange requests before Relay opens a time-bound path. Execute can close that path locally, while Lock, Archive and Transfer control authority, preserve the record and govern what crosses the boundary.

04 In a control-layer architecture

## A local action, agreed before it is needed.

Ships and ports cannot assume continuous access to a central security platform. CP-09 places the defensive action locally, so a vessel or terminal can sever a suspect supplier, satellite, private 5G or shore link without waiting for remote orchestration. The action is agreed in advance, logged and subject to human authority.

05 Sector relevance

## Where CP-09 applies.

Maritime Commercial shipping Ports and terminals Logistics Offshore operations

06 Related Blueprints

## Compose alongside.

See all: https://fire-vault.com/control-blueprints

CP-01 FIRE-led

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View Blueprint
https://fire-vault.com/control-blueprints/cp-01

CP-02 FIRE-led

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View Blueprint
https://fire-vault.com/control-blueprints/cp-02

CP-04 FIRE-led

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View Blueprint
https://fire-vault.com/control-blueprints/cp-04

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Build control around your environment

Talk to our team about composing this Blueprint for your estate.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-blueprints/cp-09#webpage",
    "url": "https://fire-vault.com/control-blueprints/cp-09",
    "name": "Protect Maritime and Commercial Shipping by Firevault - Con…",
    "description": "Keep vessel, port and terminal operations separated, with remote access that exists only for an approved voyage or maintenance window.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/assets/og-blueprint-cp-09-Y5UAUzk1.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-blueprints/cp-09#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-blueprints/cp-09#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control Blueprints",
        "item": "https://fire-vault.com/control-blueprints"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Protect Maritime and Commercial Shipping by Firevault - Con…",
        "item": "https://fire-vault.com/control-blueprints/cp-09"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "TechArticle",
    "headline": "Protect Maritime and Commercial Shipping - Control Blueprint CP-09",
    "description": "Keep vessel, port and terminal operations separated, with remote access that exists only for an approved voyage or maintenance window.",
    "author": {
      "@type": "Organization",
      "name": "Firevault"
    },
    "publisher": {
      "@type": "Organization",
      "name": "Firevault",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png"
      }
    },
    "mainEntityOfPage": "https://fire-vault.com/control-blueprints/cp-09",
    "about": {
      "@type": "Thing",
      "name": "Control Blueprint CP-09"
    }
  }
]
```