---
title: "Control for Critical Infrastructure (CNI) | Firevault"
url: https://fire-vault.com/control-for-critical-infrastructure
description: "Secure the UK's Critical National Infrastructure with Control, providing physical network path governance for OT and SCADA environments. Learn why."
lang: en-GB
---

Network Evolution & Rapid Protection (#NEARP)

# National-Grade Security for Essential Services

State-sponsored actors, hacktivists, and criminal organisations increasingly target essential services. Traditional cybersecurity cannot fully address these persistent, sophisticated threats.

Back to Control: https://fire-vault.com/solutions/control

Image: Industrial control environment with operational technology systems (https://fire-vault.com/assets/oss-industry-ot-CUdZsi1F.jpg)

The exposure in numbers

01

Sovereign control over critical data paths

100% Sovereign control over critical data paths

02

Network-reachable attack surfaces

Zero Network-reachable attack surfaces

03

Governance modules enforcing policy

9 Governance modules enforcing policy

04

NIS2 and CAF compliance evidence

Full NIS2 and CAF compliance evidence

The Challenge

## Critical infrastructure faces nation-state threats.

01

### Supply Chain Attacks

Nation-state actors exploit supply chain vulnerabilities to reach operational systems.

02

### IT/OT Convergence

Shared network paths between IT and OT create cascading vulnerabilities.

03

### Legacy Infrastructure

Legacy systems lack basic cybersecurity and cannot be easily patched.

> Sovereign infrastructure demands sovereign data control. If your most critical data can be reached from the internet, it can be compromised, regardless of how many software layers sit in front of it.

The Scenario

### Scenario: Nation-State Attack on Energy Grid

A state-sponsored group compromises a regional energy provider through a supply-chain update to SCADA management software. The attackers move laterally for 47 days, mapping grid topology and exfiltrating operational procedures. When they trigger the payload, substations across three counties lose supervisory control simultaneously. Recovery takes 11 days because backup configurations were stored on network-attached storage, also compromised. With Control, SCADA configurations and grid topology data reside in physically disconnected vaults requiring multi-party authorisation. The attack vector, network reachability, simply does not exist.

"We assumed our air-gap was real. It was not, it was a firewall rule. When it failed, everything behind it was exposed. We needed physical disconnection, not logical separation."

Module deployment · critical infrastructure network

## Where each Control module is deployed across IT, OT, vendors and field sites.

Critical infrastructure operators carry a corporate estate, an OT core that runs the mission, a vendor zone that supports the kit and remote field sites that report into it. Control puts a real boundary at every step of that picture.

Grounded in NCSC CAF, NIS2, CISA reference architectures and IEC 62443-3-2.

L5

Internet / Cloud

External

External services

Cloud APIs

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

External traffic terminates in the perimeter.

L4

Enterprise

IT

SOC

SIEM

Identity

Office estate and shared services.

Office estate and shared services.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
Unlink

Vendor paths exist on a schedule and not a minute more.

VND

Vendor zone

DMZ · trust boundary

MSP access

Vendor jump

Update broker

Third-party access opens on a schedule only.

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Vendor activity into OT is named, checked and approved.

L3

OT core

OT

Historian

Engineering

Asset mgmt

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate

Engineering and SCADA on separate fabrics.

L2

Supervisory control

OT

SCADA

HMI

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Control changes need approval before they move.

L1

Basic control

Field

PLCs

DCS

RTUs

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Field assets tie to named engineers.

L0

Field assets

Field

Sensors

Actuators

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Baselines, configurations, evidence and the recovery sets you need to restore from a known-good state.

Offline by design · secure by default

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
Unlink Remove trust

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

DMZ boundary Trust transition

OSS callout Off-network detail

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1. Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   At every zone boundary on the diagram
   Every zone sits on its own physical fabric. A compromise on the office or vendor side cannot walk into OT or out to the field.
2. Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   On the L5 to L4 link and the vendor link
   A real hardware off switch on the public and vendor boundaries, with vendor access opened only for the named window of work.
3. Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
   Relay
   On the vendor link
   Vendor connections exist for the window of work and not a minute more.
4. Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
   Unlink
   On the vendor link
   When a vendor relationship ends, Unlink removes the persistent connection and the inherited trust.
5. Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   On the L5 to L4 link, and inside the vendor link
   Requests crossing into trusted estates are checked for origin, integrity and authority.
6. Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   On the vendor link and the L1 to L0 link
   Access ties to named individuals with the right authority. Standing access is the exception.
7. Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   Inside the vendor link and on the L2 to L1 link
   Pushing a change holds until the right approval is in place.

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Sovereign Data Paths

All data remains within your chosen jurisdiction in NATO-approved Firevault Bunkers, never transiting public cloud or foreign infrastructure.

02

### Multi-Party Authorisation

Critical operations require sign-off from multiple authorised parties across different roles, preventing single points of compromise.

03

### NIS2 & CAF Evidence

Automated compliance logging maps directly to NIS2 Article 21 and NCSC CAF outcomes, audit-ready evidence generated continuously.

04

### Cellular Failover

Out-of-band management via dedicated cellular connectivity ensures control plane access even when primary networks are compromised.

05

### Immutable Logging

Every access, transfer, and policy decision is recorded in tamper-proof logs stored in physically separate infrastructure, forensic-grade accountability.

06

### Verified Safe-State Restoration

Verified control-plane baselines allow the network to be returned to a known-good operating state after a total compromise.

Demo to Live

## Adoption Guide

Step 1

#### Threat and Compliance Assessment

Map your infrastructure against NIS2 Article 21 and NCSC CAF outcomes to identify gaps in network segmentation, access control, and incident response.

Step 2

#### Sovereign Architecture Design

Select and configure Control modules for your specific sector, energy, water, transport, or defence, with sovereign data paths and multi-party authorisation models.

Step 3

#### Controlled Pilot

Deploy in an isolated CNI environment with full multi-party authorisation, immutable logging, and cellular failover, validating governance policies without operational risk.

Step 4

#### Operational Go-Live

Full deployment across critical infrastructure with verified safe-state restoration, continuous compliance evidence generation, and 24/7 out-of-band management.

Step 1

#### Threat and Compliance Assessment

Step 2

#### Sovereign Architecture Design

Step 3

#### Controlled Pilot

Step 4

#### Operational Go-Live

Organise a Demo: https://fire-vault.com/contact

Relevant Control Blueprints

## Deployment patterns that apply here

CP-05 FIRE+VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View blueprint
https://fire-vault.com/control-blueprints/cp-05

CP-04 FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint
https://fire-vault.com/control-blueprints/cp-04

CP-01 FIRE

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View blueprint
https://fire-vault.com/control-blueprints/cp-01

CP-02 FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint
https://fire-vault.com/control-blueprints/cp-02

CP-06 VAULT

### Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

View blueprint
https://fire-vault.com/control-blueprints/cp-06

CP-07 FIRE

### Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

View blueprint
https://fire-vault.com/control-blueprints/cp-07

## Explore More

### Control for OT Environments

Physical network governance for SCADA, ICS and industrial control.

Learn more about Control for OT Environments
https://fire-vault.com/control-for-ot-environments

### Control for IT Networks

Policy-enforced path control across IT infrastructure.

Learn more about Control for IT Networks
https://fire-vault.com/control-for-it-networks

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-critical-infrastructure#webpage",
    "url": "https://fire-vault.com/control-for-critical-infrastructure",
    "name": "Control for Critical Infrastructure (CNI)",
    "description": "Secure the UK's Critical National Infrastructure with Control, providing physical network path governance for OT and SCADA environments. Learn why.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-critical-infrastructure#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-critical-infrastructure#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control for Critical Infrastructure (CNI)",
        "item": "https://fire-vault.com/control-for-critical-infrastructure"
      }
    ]
  }
]
```