Start from the need

What systems do you need to control?

These five needs are about systems, networks and access rather than files. Each one hands off to the Control Blueprint that governs it physically. If your need is about data and digital assets instead, that journey belongs to Offline Secure Storage®.

  • Critical systems
  • Lateral movement
  • Third-party access
  • AI systems
  • Data centres
Security analyst reviewing an isolated workstation with disconnected cables

5

Systems and access needs covered on this page

7

Control Blueprints behind them

CP-01 to CP-07

Physical

Separation enforced in hardware, not configuration

Zero

Standing paths left open between separated zones

01The same control every time

Three steps, whatever you are controlling.

The needs below differ in which path is at risk, not in how the control works. Each page applies the same three steps to the systems in that setting.

01

Name the path, not just the perimeter

Every incident travels a route between systems, sites or suppliers. The route is what needs governing.

02

Break the path in hardware

Control removes the standing connection so the route does not exist until someone opens it.

03

Open it for a witnessed window

Work happens inside a defined window, the session is evidenced, and the path closes again afterwards.

02Systems and access

What you need to control, not just store.

Each need names the path most organisations live with, then the practical difference once that path is governed physically by a Control Blueprint.

06Blueprint CP-04 and CP-05

Control critical systems and network exposure

A boundary enforced only by configuration can be undone by a rule change or a stolen credential.

What changes

IT and OT are separated physically, so the path only exists when it is opened deliberately.

Read the detail
07Blueprint CP-01 and CP-02

Contain ransomware and lateral movement

A compromise in one environment should not automatically provide a path to the next.

What changes

Movement stops at a physical break rather than at a firewall rule.

Read the detail
08Blueprint CP-03

Control third-party and remote access

Vendor, maintenance and support connections outlive the projects that created them.

What changes

Access exists for a defined window, is witnessed, and closes physically afterwards.

Read the detail
09Blueprint AI Control patterns

Control AI systems and infrastructure

Agents inherit standing credentials and act at machine speed, so their reach is rarely the reach intended.

What changes

The reach of an agent is bounded by hardware, not by prompt or policy alone.

Read the detail
10Blueprint CP-04 and CP-05

Control data centre and colocation infrastructure

The building can be physically secure while the paths inside it remain continuously exposed.

What changes

Cross-connects and management planes are opened on demand and closed by default.

Read the detail
03Data and digital assets

If the need is a file, not a system, start with #OSS.

Personal records, intellectual property, ransomware recovery copies, customer data and long-term digital assets are held on physically disconnected hardware by Offline Secure Storage®.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy