The systems that run the day
Finance, case management, scheduling, production planning. Reachable from ordinary user devices because that is what makes them useful.
Operational stoppageOne compromised laptop rarely ends a business. What ends a business is the set of connections that let the compromise reach finance, backups, production and the recovery copies on the same night. Control governs those connections so that a single foothold stays a single foothold.
Need → Control → Blueprint → Modules

Before any technology conversation, it is worth being honest about what is currently within reach of an ordinary compromised endpoint.
Finance, case management, scheduling, production planning. Reachable from ordinary user devices because that is what makes them useful.
Operational stoppageBackup servers usually sit on the same network as the systems they protect, with credentials that can reach both. Attackers target them first.
Recovery removedJump boxes, remote management tools and monitoring agents cross every boundary by design. A stolen credential inherits that reach.
Privilege inheritanceLogs and audit records held on the same estate can be encrypted or altered along with everything else, which turns a recovery into an investigation.
Evidence lossThe paths that ransomware uses were almost always built for a good reason, then left open long after that reason ended. This is a governance problem before it is a security problem.
Every integration, every remote support arrangement and every convenience shortcut added a route. None of them came with an expiry date. The estate now carries more standing connectivity than any single person can describe, which is precisely what makes lateral movement fast.
Control the path, protect the asset.A temporary connection opened for a project or a migration is almost never closed once the work finishes.
Firewall rules and VLANs are configuration. Configuration can be changed, misapplied or bypassed with valid credentials.
If the recovery copy is reachable from the environment it protects, it shares that environment's fate.
Connections are added by different teams over years. There is rarely one person who can list every live path.
Detection and response take minutes at best. Encryption across an open estate takes less.
Systems trust each other because they always have, not because that trust was ever assessed against today's risk.
This is the part most organisations have never written down. Naming the paths is what turns an anxious conversation into a decision that can be made.
Control does not add another agent to the estate or ask your teams to work differently. It changes whether a connection physically exists when nobody has asked for it.
Paths exist continuously and are restrained by configuration. Containment depends on someone noticing an incident and acting correctly under pressure.
The path is physically absent unless it has been opened for a stated purpose. Containment is a property of the architecture rather than a reaction to an alarm.
Control is a way of thinking about connectivity before it is a set of products. These four principles apply to every Control need, and they are what the Blueprints put into practice.
Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.
A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.
When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.
A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.
Once the paths are agreed, the Blueprint turns the decision into an architecture: where the boundaries sit, what governs each crossing and how the pattern is deployed without interrupting operations.
Stop ransomware moving, spreading or reaching the crown jewels.
Applied to lateral movement prevention across it and ot. The Blueprint page carries the architecture, the zone detail and the deployment sequence.
This page is about the paths ransomware travels along. Keeping a clean recovery copy is a different job: Offline Secure Storage holds selected copies physically outside the connected estate so recovery does not depend on the network under attack.
Hold recovery copies beyond reachStraight answers for the people who have to approve the work rather than run it.
CP-01 Stop Kill-Chain Ransomware shows how these connections are governed in practice, module by module and boundary by boundary.
We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy