---
title: "What Systems Do You Need to Control? | Firevault Control"
url: https://fire-vault.com/control-for
description: "Five systems and access needs answered by Firevault Control: critical system exposure, lateral movement, third-party access, AI systems and data centre…"
lang: en-GB
---

Start from the need

# What systems do you need to control?

These five needs are about systems, networks and access rather than files. Each one hands off to the Control Blueprint that governs it physically. If your need is about data and digital assets instead, that journey belongs to Offline Secure Storage®.

- Critical systems
- Lateral movement
- Third-party access
- AI systems
- Data centres

See the five control needs
I need to protect data instead: https://fire-vault.com/oss-for

Image: Security analyst reviewing an isolated workstation with disconnected cables (https://fire-vault.com/assets/hero-square-analyst-DI5B7V_E.jpg)

5

Systems and access needs covered on this page

8

Control Blueprints behind them

CP-01 to CP-08

Physical

Separation enforced in hardware, not configuration

Zero

Standing paths left open between separated zones

01 The same control every time

## Three steps, whatever you are controlling.

The needs below differ in which path is at risk, not in how the control works. Each page applies the same three steps to the systems in that setting.

**01**

### Name the path, not just the perimeter

Every incident travels a route between systems, sites or suppliers. The route is what needs governing.

**02**

### Break the path in hardware

Control removes the standing connection so the route does not exist until someone opens it.

**03**

### Open it for a witnessed window

Work happens inside a defined window, the session is evidenced, and the path closes again afterwards.

02 Systems and access

## What you need to control, not just store.

Each need names the path most organisations live with, then the practical difference once that path is governed physically by a Control Blueprint.

**06**Blueprint CP-04 and CP-05

### Control critical systems and network exposure

A boundary enforced only by configuration can be undone by a rule change or a stolen credential.

What changes

IT and OT are separated physically, so the path only exists when it is opened deliberately.

Read the detail
https://fire-vault.com/control-for-critical-systems

**07**Blueprint CP-01 and CP-02

### Contain ransomware and lateral movement

A compromise in one environment should not automatically provide a path to the next.

What changes

Movement stops at a physical break rather than at a firewall rule.

Read the detail
https://fire-vault.com/control-for-lateral-movement

**08**Blueprint CP-03

### Control third-party and remote access

Vendor, maintenance and support connections outlive the projects that created them.

What changes

Access exists for a defined window, is witnessed, and closes physically afterwards.

Read the detail
https://fire-vault.com/control-for-third-party-access

**09**Blueprint AI Control patterns

### Control AI systems and infrastructure

Agents inherit standing credentials and act at machine speed, so their reach is rarely the reach intended.

What changes

The reach of an agent is bounded by hardware, not by prompt or policy alone.

Read the detail
https://fire-vault.com/control-for-ai-systems

**10**Blueprint CP-04 and CP-05

### Control data centre and colocation infrastructure

The building can be physically secure while the paths inside it remain continuously exposed.

What changes

Cross-connects and management planes are opened on demand and closed by default.

Read the detail
https://fire-vault.com/control-for-data-centre-exposure

03 Data and digital assets

## If the need is a file, not a system, start with #OSS.

Personal records, intellectual property, ransomware recovery copies, customer data and long-term digital assets are held on physically disconnected hardware by Offline Secure Storage®.

Data needs 01 to 05: https://fire-vault.com/oss-for

Control Blueprints: https://fire-vault.com/control-blueprints

Full index

## Every Control by Firevault page

Every need, industry, utilities and blueprint page for Control by Firevault, in one place. Each page sets out the data paths it governs and the evidence it produces.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Protect what matters. Control what moves.

Choose your Vault and check out in minutes. Dedicated hardware, identity-locked to you, physically disconnected when closed.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-for#webpage",
    "url": "https://fire-vault.com/control-for",
    "name": "What Systems Do You Need to Control?",
    "description": "Five systems and access needs answered by Firevault Control: critical system exposure, lateral movement, third-party access, AI systems and data centre…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/assets/feature-controlled-access-C3gCWRg1.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-for#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-for#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Home",
        "item": "/"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Solutions",
        "item": "/solutions"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Control",
        "item": "/solutions/control"
      },
      {
        "@type": "ListItem",
        "position": 5,
        "name": "By need",
        "item": "/control-for"
      }
    ]
  }
]
```