Your estate is different. The path discipline is not.
Each sector answers to a different regulator and runs a different estate. Pick yours to see the blueprint: the zones, the modules deployed, the frameworks they answer to and the evidence produced.
- Thirteen sectors
- Nine modules
- Policy-enforced paths

- Regulated sectors mapped to Control blueprints
- 13Regulated sectors mapped to Control blueprints
- Modules deployed per estate, under one policy fabric
- 09Modules deployed per estate, under one policy fabric
- Session ceiling on every privileged path
- 120minSession ceiling on every privileged path
- Commitment behind every deployment
- 36moCommitment behind every deployment
Thirteen estates, thirteen blueprints.
Every card opens a full blueprint: the estate, the modules, the regulatory anchors and how operators work once paths are enforced.
Critical infrastructure
Utilities
Policy-enforced paths across generation, distribution and metering estates.
NCSC CAF and NIS2
See blueprintCritical infrastructure
Water
OT segmentation and evidence trails for treatment and distribution networks.
NCSC CAF and DWI
See blueprintCritical infrastructure
Energy
Grid, generation and market-facing systems separated by governed paths.
NIS2 and IEC 62443
See blueprintCritical infrastructure
Oil and gas
Upstream, midstream and downstream operations held under module policy.
IEC 62443
See blueprintCritical infrastructure
Telecoms
Signalling, subscriber and support estates protected at the management plane.
TSA and NIS2
See blueprintCritical infrastructure
Colocations and data centres
Tenant isolation, cross-connect governance and shared-fabric protection.
ISO 27001 and NIS2
See blueprintPublic sector
Defence
Programme data and mission systems governed by physical path control.
DEFSTAN and JSP 440
See blueprintPublic sector
Public sector
Central and local government estates segmented for resilience and audit.
NCSC CAF and GovAssure
See blueprintRegulated industry
Banking
Payments, ledgers and admin planes governed by policy rather than trust.
DORA and FCA
See blueprintRegulated industry
Healthcare
Clinical, imaging and admin estates held apart by enforced paths.
DSPT and NIS2
See blueprintRegulated industry
Retail
Point of sale, loyalty and supplier estates separated to contain lateral movement.
PCI DSS
See blueprintIndustrial
Construction
Project data, design files and site systems governed across joint ventures.
ISO 27001
See blueprintIndustrial
Education
Research data, safeguarding evidence and admin estates on separate paths.
DfE and Cyber Essentials
See blueprintFour disciplines, applied to different estates.
The systems change from one sector to the next. The way paths are governed does not.
Segment
Estates are split into zones so one compromised system cannot reach the next.
Enforce
Every privileged path is opened by policy, time-bound and closed automatically.
Verify
Identity is checked at the path, not assumed from a network position.
Evidence
Every session produces an audit trail your regulator and insurer can read.
Prefer to start somewhere else?
Industry is one way in. You can also start from the need you have, the modules themselves, or the hardware that enforces them.



Which offline secure storage solution is right for you?
Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.
Takes about 2 minutes. No account needed.