Control blueprints by industry

Your estate is different. The path discipline is not.

Each sector answers to a different regulator and runs a different estate. Pick yours to see the blueprint: the zones, the modules deployed, the frameworks they answer to and the evidence produced.

  • Thirteen sectors
  • Nine modules
  • Policy-enforced paths
Why Control
Corridor of offline storage racks inside a Firevault bunker
Blueprint coverage
01
Regulated sectors mapped to Control blueprints
13Regulated sectors mapped to Control blueprints
02
Modules deployed per estate, under one policy fabric
09Modules deployed per estate, under one policy fabric
03
Session ceiling on every privileged path
120minSession ceiling on every privileged path
04
Commitment behind every deployment
36moCommitment behind every deployment
01Choose your industry

Thirteen estates, thirteen blueprints.

Every card opens a full blueprint: the estate, the modules, the regulatory anchors and how operators work once paths are enforced.

01

Critical infrastructure

Utilities

Policy-enforced paths across generation, distribution and metering estates.

NCSC CAF and NIS2

See blueprint
02

Critical infrastructure

Water

OT segmentation and evidence trails for treatment and distribution networks.

NCSC CAF and DWI

See blueprint
03

Critical infrastructure

Energy

Grid, generation and market-facing systems separated by governed paths.

NIS2 and IEC 62443

See blueprint
04

Critical infrastructure

Oil and gas

Upstream, midstream and downstream operations held under module policy.

IEC 62443

See blueprint
05

Critical infrastructure

Telecoms

Signalling, subscriber and support estates protected at the management plane.

TSA and NIS2

See blueprint
06

Critical infrastructure

Colocations and data centres

Tenant isolation, cross-connect governance and shared-fabric protection.

ISO 27001 and NIS2

See blueprint
07

Public sector

Defence

Programme data and mission systems governed by physical path control.

DEFSTAN and JSP 440

See blueprint
08

Public sector

Public sector

Central and local government estates segmented for resilience and audit.

NCSC CAF and GovAssure

See blueprint
09

Regulated industry

Banking

Payments, ledgers and admin planes governed by policy rather than trust.

DORA and FCA

See blueprint
10

Regulated industry

Healthcare

Clinical, imaging and admin estates held apart by enforced paths.

DSPT and NIS2

See blueprint
11

Regulated industry

Retail

Point of sale, loyalty and supplier estates separated to contain lateral movement.

PCI DSS

See blueprint
12

Industrial

Construction

Project data, design files and site systems governed across joint ventures.

ISO 27001

See blueprint
13

Industrial

Education

Research data, safeguarding evidence and admin estates on separate paths.

DfE and Cyber Essentials

See blueprint
02What every blueprint shares

Four disciplines, applied to different estates.

The systems change from one sector to the next. The way paths are governed does not.

Segment

Estates are split into zones so one compromised system cannot reach the next.

Enforce

Every privileged path is opened by policy, time-bound and closed automatically.

Verify

Identity is checked at the path, not assumed from a network position.

Evidence

Every session produces an audit trail your regulator and insurer can read.

03Other routes in

Prefer to start somewhere else?

Industry is one way in. You can also start from the need you have, the modules themselves, or the hardware that enforces them.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy