---
title: "Secure Defence Network Path Control | Control"
url: https://fire-vault.com/control-for-defence
description: "Achieve total command over classified data paths in defence networks, enforcing physical separation between systems of different security levels. Discover."
lang: en-GB
---

Defence

# National Security-Grade Network Severance and Isolation

Defence networks carry the most sensitive information a nation possesses. The threat landscape includes the most capable adversaries on earth, operating with state-level resources and persistence.

- Nation-state APTs
- Cross-domain data leakage
- Insider threat
- Supply-chain implants

Back to Control: https://fire-vault.com/solutions/control

Image: Defence operations centre with situational awareness displays (https://fire-vault.com/assets/sector-square-defence-BuFAbR-h.jpg)

The exposure in numbers

01

Classification boundary enforcement

100% Classification boundary enforcement

02

Cross-domain network reachability

Zero Cross-domain network reachability

03

Cleared personnel at every facility

SC/DV Cleared personnel at every facility

04

JSP 440 and NATO security compliance

Full JSP 440 and NATO security compliance

The Challenge

## Defence networks face state-level adversaries.

01

### Nation-State Persistence

State-sponsored actors maintain persistent access campaigns against defence networks, investing years of effort to compromise a single classified system.

02

### Cross-Domain Risks

Information sharing between classification levels creates network paths that, if compromised, could allow classified data to traverse to lower classification domains.

03

### Legacy Military Systems

Decades-old military systems were designed for physical isolation but are increasingly connected to modern networks for interoperability.

Defence

> Defence information requires defence-grade protection. Logical separation managed by software is not sufficient when the adversary has the resources and patience to find and exploit every configuration error.

The Scenario

### Scenario: Cross-Domain Boundary Compromise

A state-sponsored group identifies a misconfiguration in a cross-domain solution connecting SECRET and OFFICIAL networks. The misconfiguration allows carefully crafted data packets to bypass content inspection, creating a covert channel for exfiltrating classified material. The channel operates for months at low bandwidth, evading detection systems tuned for bulk data movement. With Control, cross-domain boundaries are physically enforced. Data movement between classification levels requires multi-party authorisation with full content verification. The covert channel cannot exist because the physical path between domains does not exist outside authorised transfer windows.

"Our cross-domain solution had been certified and accredited. It passed every penetration test. But the misconfiguration that enabled the covert channel was in a feature that had been added after certification. The accreditation process had not caught up."

Module deployment · defence network

## Where each Control module is deployed across admin, mission and classified domains.

Defence estates separate admin networks from mission systems and classified enclaves. Control puts a boundary between each domain so the right things stay reachable and the wrong things do not. Sovereign data lives behind its own firebreak.

Grounded in MOD Secure by Design, NCSC for defence, NIST SP 800-171 and JSP guidance available in the public domain.

D0

Internet / Cloud

External

External services

Cloud

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

External traffic stops at the admin perimeter.

D1

Admin network

Admin

Office IT

Email

SOC

Day-to-day business systems.

Day-to-day business systems.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Admin cannot reach mission directly.

DMZ

Cross-domain DMZ

DMZ · trust boundary

Guard

Data diode

One-way and brokered exchange between domains.

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
Transfer

Cross-domain movement is checked and routed.

D2

Mission planning

Mission

Planning systems

Logistics

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Mission actions approved before they move.

D3

Mission execution

Mission

Command & control

ISR feeds

Operational tempo, not office hours.

Operational tempo, not office hours.

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Classified access is named with the right clearance.

D4

Classified enclave

Mission

Sovereign workloads

Sensitive data

Sovereign and sensitive systems.

Sovereign and sensitive systems.

OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Sovereign records, sensitive data, evidence and the recovery sets needed to survive a worst day.

Offline by design · secure by default

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
Transfer Controlled move

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

DMZ boundary Trust transition

OSS callout Off-network detail

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1. Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   On the D1 to DMZ link and the D3 to D4 link
   Admin, mission and classified each sit on their own physical fabrics. A compromise in admin cannot walk into mission or classified.
2. Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   On the D0 to D1 link and the D1 to DMZ link
   Real hardware off switches on the public and admin boundaries, cutting the live path into mission and classified estates.
3. Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   On the D0 to D1 link and inside the cross-domain DMZ
   Requests crossing into trusted estates are checked for origin, integrity and authority before they reach an operational system.
4. Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
   Transfer
   Inside the cross-domain DMZ
   Movement between domains is brokered, often one-way. Transfer governs the route and the landing point.
5. Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   On the D2 to D3 link
   Mission actions hold until the right approval is in place.
6. Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   On the D3 to D4 link
   Classified access ties to named individuals with the right clearance, device and authority.

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### UK Sovereign Facilities

All classified data remains within NATO-approved underground facilities in the United Kingdom, managed by SC/DV-cleared personnel under MOD oversight.

02

### Cleared Multi-Party Access

All access requires authorisation from multiple cleared individuals across different roles, preventing any single point of compromise.

03

### JSP 440 Compliance

Automated compliance logging maps directly to JSP 440, JSP 604, and NATO security requirements with continuous evidence generation.

04

### Independent Communications

Out-of-band management via dedicated, secured communications ensures control plane access independent of primary defence networks.

05

### Forensic-Grade Logging

Every access, transfer, and authorisation decision is recorded in tamper-proof, classification-appropriate logs on physically separate infrastructure.

06

### Cleared Recovery Capability

Verified control-plane baselines maintained within appropriately cleared facilities ensure classified system restoration during total compromise scenarios.

Demo to Live

## Adoption Guide

Step 1

#### Classification Boundary Assessment

Map all cross-domain connections and data flows between classification levels, identifying persistent paths and reachability gaps against JSP 440 requirements.

Step 2

#### Sovereign Architecture Design

Design physically separated classification zones with Control modules enforcing each boundary, aligned to MOD and NATO security requirements.

Step 3

#### Accredited Pilot

Deploy within a controlled environment with full classification boundary enforcement, multi-party authorisation, and forensic logging for accreditation evaluation.

Step 4

#### Operational Capability

Full deployment across defence infrastructure with cleared verified baselines, continuous compliance evidence, and independent communications.

Step 1

#### Classification Boundary Assessment

Step 2

#### Sovereign Architecture Design

Step 3

#### Accredited Pilot

Step 4

#### Operational Capability

Organise a Demo: https://fire-vault.com/contact

Relevant Control Blueprints

## Deployment patterns that apply here

CP-04 FIRE

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint
https://fire-vault.com/control-blueprints/cp-04

CP-01 FIRE

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View blueprint
https://fire-vault.com/control-blueprints/cp-01

CP-02 FIRE

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint
https://fire-vault.com/control-blueprints/cp-02

CP-05 FIRE+VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View blueprint
https://fire-vault.com/control-blueprints/cp-05

## Explore More

### Control for Critical Infrastructure

National-grade security for essential services.

Learn more about Control for Critical Infrastructure
https://fire-vault.com/control-for-critical-infrastructure

### Control for Public Sector

Government network isolation and classified data paths.

Learn more about Control for Public Sector
https://fire-vault.com/control-for-public-sector

Questions

## Frequently Asked

Defence blueprint - PoC

### Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-defence#webpage",
    "url": "https://fire-vault.com/control-for-defence",
    "name": "Secure Defence Network Path Control",
    "description": "Achieve total command over classified data paths in defence networks, enforcing physical separation between systems of different security levels. Discover.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-defence#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-defence#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Secure Defence Network Path Control",
        "item": "https://fire-vault.com/control-for-defence"
      }
    ]
  }
]
```