---
title: "Control Supply Chain & Vendor Access | Control"
url: https://fire-vault.com/control-for-supply-chain-risk
description: "Govern all third-party and vendor access paths into your network. Grant time-bound, physically-enforced access to prevent supply chain attacks. Learn why."
lang: en-GB
---

Threat Response

# Eliminate Supply Chain Risk Through Physical Path Governance

Supply chain attacks exploit the persistent connections that organisations maintain with vendors, managed service providers, and software suppliers. When these paths are physically severed between active sessions, the attack vector ceases to exist.

Back to Control: https://fire-vault.com/solutions/control

Image: Corridor of offline storage racks inside a Firevault bunker (https://fire-vault.com/assets/hero-square-bunker-B6Y7Qt9r.jpg)

The exposure in numbers

01

Of breaches originate through third-party access

62% Of breaches originate through third-party access

02

Persistent vendor paths outside maintenance windows

Zero Persistent vendor paths outside maintenance windows

03

Third-party sessions recorded on tamper-proof storage

100% Third-party sessions recorded on tamper-proof storage

04

Faster containment when vendor paths are physically severed

4.5x Faster containment when vendor paths are physically severed

The Threat

## Third-party connections are the most exploited entry point.

01

### Persistent Vendor Access

Managed service providers and equipment vendors maintain always-on VPN connections and remote access tools. These paths remain active 24/7, regardless of whether maintenance is being performed.

02

### Trust Chain Exploitation

Attackers compromise a vendor with weaker security and use their legitimate access to pivot into the target organisation. The connection is trusted, the credentials are valid, and the activity appears routine.

03

### Software Supply Chain

Compromised software updates delivered through trusted channels bypass perimeter security entirely. The malicious payload arrives through the same path as legitimate updates.

Threat Response

> Every vendor connection is a doorway into your organisation. If that doorway remains open when no one is walking through it, you are inviting risk without gaining value.

The Scenario

### Scenario: Managed Service Provider Compromise

A mid-size manufacturer uses a managed IT service provider for patch management and monitoring. The MSP maintains a persistent VPN connection to the manufacturer's network for 24/7 support. Attackers compromise the MSP's RMM platform and use the existing VPN connection to deploy ransomware across all of the MSP's clients simultaneously. With Control, the MSP's access path is physically severed outside scheduled maintenance windows. The Relay module activates the connection for a four-hour patch window each Tuesday, with all activity recorded. When the MSP is compromised on a Thursday evening, there is no path for the attackers to traverse.

"Our MSP had a VPN into our network that was active 168 hours a week. They used it for about 6 hours. That left 162 hours where an attacker had a trusted path into our core infrastructure."

Supply chain attack

## How Control contains a trusted-vendor compromise.

Supply chain attacks turn a trusted maintenance route into a breach path. Control treats vendor access as a temporary, governed event rather than a standing trust, so a compromised supplier cannot ride straight into production.

Mapped to MITRE ATT&CK T1195 Supply Chain Compromise, ENISA Threat Landscape for Supply Chain Attacks and NCSC supply chain guidance.

1. ST 01
   Vendor Compromise
   T1195
   ◤ Attacker
   Attackers breach a software vendor, MSP or update server that customers already trust.
   ◢ Control breaks it
   Vendor reach into the protected zone is severed by default. There is no permanent trust to ride.
   Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak
   Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
   Unlink
   ✕ Break here
2. ST 02
   Trusted Delivery
   T1078.004
   ◤ Attacker
   Pushes a tainted update or piggy-backs on a legitimate support session into customer environments.
   ◢ Control breaks it
   Maintenance windows open only as time-bound Relay sessions. The connection closes on schedule, every time.
   Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
   Relay
   Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
   Lock
   ✕ Break here
3. ST 03
   Execution in Production
   TA0002
   ◤ Attacker
   Runs the malicious payload against production assets, often with privileges granted to the vendor.
   ◢ Control breaks it
   Vendor-initiated changes are routed through Execute with multi-party approval and Validate before they reach the asset.
   Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
   Execute
   Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
   Validate
   ✕ Break here
4. ST 04
   Onward Movement
   TA0008
   ◤ Attacker
   Pivots from the vendor-managed system into the wider estate.
   ◢ Control breaks it
   Isolate enforces the zone boundary. The compromised system cannot reach into adjacent zones without a fresh, approved path.
   Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
   Isolate
   Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
   Firebreak

Outcome · outcome block

A compromised vendor reaches only what the time-bound session allowed, for only as long as it was open. The wider estate stays out of reach.

Modules & symbols

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
Unlink Remove trust

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate Zone boundary

✕

Break here Chain severed by Firevault

◤

Attacker step MITRE ATT&CK tactic

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Scheduled Access Windows

Vendor connections activate only during defined maintenance windows. Between windows, the physical path does not exist and cannot be established remotely.

02

### Multi-Party Session Approval

Every vendor session requires approval from both the vendor team and internal security before the physical path is activated.

03

### Complete Session Recording

All vendor activity during active windows is captured on physically disconnected storage that neither the vendor nor an attacker can access or modify.

04

### Instant Vendor Disconnection

When a supply chain compromise is detected, all vendor paths are physically severed within seconds, regardless of which vendor is affected.

05

### Vendor Zone Isolation

Third-party access is confined to a physically separated zone with no path to production systems, backup infrastructure, or management planes.

06

### Vendor Compliance Evidence

Automated logging provides the evidence required for ISO 27001 supplier assessments, NIS2 supply chain requirements, and contractual SLA compliance.

Demo to Live

## Adoption Guide

Step 1

#### Third-Party Path Audit

Map every vendor, MSP, and software supplier connection into your infrastructure, documenting active hours, data flows, and the systems each path can reach.

Step 2

#### Window and Zone Design

Define maintenance windows, vendor zones, and multi-party authorisation requirements for each third-party relationship based on operational need and risk profile.

Step 3

#### Pilot with Primary MSP

Deploy Relay-governed access for your primary managed service provider, testing scheduled windows, emergency access procedures, and session recording.

Step 4

#### Full Vendor Governance

Extend to all third-party connections with automated window management, vendor zone isolation, and continuous compliance evidence generation.

Step 1

#### Third-Party Path Audit

Step 2

#### Window and Zone Design

Step 3

#### Pilot with Primary MSP

Step 4

#### Full Vendor Governance

Organise a Demo: https://fire-vault.com/contact

## Explore More

### Ransomware Containment

Sever the path before ransomware spreads.

Learn more about Ransomware Containment
https://fire-vault.com/control-for-ransomware-containment

### IT/OT Convergence

Physically separate IT from operational technology.

Learn more about IT/OT Convergence
https://fire-vault.com/control-for-it-ot-convergence

### FV-Relay

Time-bound, policy-controlled connection windows.

Learn more about FV-Relay
https://fire-vault.com/control/modules/relay

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for-supply-chain-risk#webpage",
    "url": "https://fire-vault.com/control-for-supply-chain-risk",
    "name": "Control Supply Chain & Vendor Access",
    "description": "Govern all third-party and vendor access paths into your network. Grant time-bound, physically-enforced access to prevent supply chain attacks. Learn why.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for-supply-chain-risk#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for-supply-chain-risk#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control Supply Chain & Vendor Access",
        "item": "https://fire-vault.com/control-for-supply-chain-risk"
      }
    ]
  }
]
```