---
title: "Control Firebreak Module: cut network paths | Firevault"
url: https://fire-vault.com/control/modules/firebreak
description: "Firebreak severs network paths at Layer 1 in seconds, containing lateral movement before a breach can spread across IT or OT estates."
lang: en-GB
---

Control Module - FIRE

# FV-Firebreak. Physically open or close the path.

Firebreak governs whether a connection path exists at all. When the path is severed, the attack has no route to progress. Containment is delivered by removing the physical connection, not by inspecting traffic or trusting a configuration to hold.

Back to Control: https://fire-vault.com/solutions/control

Control at a glance

Image: FV-Firebreak module artwork: physically open or close the connection path (https://fire-vault.com/__l5e/assets-v1/37647b48-3ccb-4b8a-8244-16e01f003108/control-module-firebreak-hero.png)

Control removes the physical path. Blueprints show where each module sits.

The exposure in numbers

01

Severance happens at the connection itself, not in a rule set

Physical Severance happens at the connection itself, not in a rule set

02

Network paths remaining once Firebreak is engaged

Zero Network paths remaining once Firebreak is engaged

03

Every open and close requires explicit approval

Authorised Every open and close requires explicit approval

04

Each state change is recorded for evidential review

Auditable Each state change is recorded for evidential review

The Problem

## Filtering a path is not the same as removing it.

01

### Filtering trusts the filter

Firewall rules, ACLs and segmentation policies assume the enforcement plane is intact. A compromised management plane can quietly relax the same rules that are supposed to contain the attack.

02

### Logical boundaries leak

VLANs, overlays and software-defined boundaries can be bypassed through misconfiguration, trunk abuse or trust inheritance. The separation only exists while every layer behaves as intended.

03

### Reaction is too slow

Emergency rule changes need authoring, testing and propagation. An attacker moving laterally does not wait for the change window to complete.

Control Module - FIRE

> If the path can be filtered, it can be unfiltered. If the path is physically removed, there is nothing left to negotiate with.

The Scenario

### Scenario: cutting the route during a live incident

Detection confirms unauthorised activity reaching from a corporate segment into an operations environment. Rather than authoring emergency firewall rules and waiting for them to propagate, the duty engineer requests a Firebreak action on the inter-segment path. With co-approval, the path is physically opened. Traffic stops because the connection no longer exists. Investigation continues on each side without further risk of progression, and the path remains severed until the environment is verified clean and a controlled restoration is approved.

"Firebreak is the moment you stop debating containment and you simply remove the road."

FV-Firebreak in placement

## Where Firebreak physically severs the path.

Firebreak is engaged at every conduit where a severed path is the only acceptable default. It removes the connection itself, not the rule about the connection.

Grounded in IEC 62443-3-3 SR 5.1 Network Segmentation, NIST CSF PR.AC-5 and NCSC Cyber Assessment Framework B4.

Inputs ─┐ Telemetry ─┐

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)

FV-Firebreak

FIRE layer

┌─ Outputs ┌─ Control

01 SR 5.1

Internet to enterprise conduit

Severs the inbound path when no legitimate traffic is expected. The path comes up only for an authorised window.

02 SR 5.1 / SR 5.2

IT to OT boundary

Removes the standing route between corporate IT and operational technology. An IT compromise has nowhere to go.

03 PR.PT-5

Production to recovery vault

Holds the path to offline recovery copies severed at rest. Ransomware cannot encrypt what it cannot reach.

04 SR 1.13

Vendor maintenance conduit

Default-severed third-party reach. Opens only as a named, time-bound session and closes on schedule.

Relies on · prerequisites

- Physical interruption hardware in the conduit, not just a routing change
- Out-of-band authorisation channel that survives an IT compromise
- Tamper-evident audit of every open and close event

Pairs with · companion modules

Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Ransomware kill switch

In a ransomware incident the Firebreak device physically closes the path to backups and adjacent zones, stopping spread in seconds without waiting for rule changes to propagate.

02

### Path-level severance

Firebreak operates on the connection path itself, so a closed path cannot be reached, scanned or negotiated with from either side.

03

### No logical bypass

There is no rule plane to subvert and no configuration to mis-set. The contained state is the absence of the connection.

04

### Multi-party authorisation

Open and close actions require explicit approval from designated parties so no single account, compromised or otherwise, can change the boundary alone.

05

### Triggered or commanded

Actions can be initiated by an operator, by a scheduled task, or by an upstream detection in line with pre-approved conditions.

06

### Evidential record

Each state change, the requesting party and the approving party are recorded on physically separate storage through Archive.

07

### Controlled restoration

Paths are reopened deliberately and individually, through Relay where a defined purpose and window applies.

Demo to Live

## Adoption Guide

Step 1

#### Map the paths

Identify the connection paths where severance is a meaningful response, including inter-zone, inter-site and third-party links.

Step 2

#### Define the authority

Agree the approval pattern for open and close, the pre-approved automation conditions and the escalation route.

Step 3

#### Rehearse and validate

Walk the playbook with the responders, then exercise live severance and restoration on a non-production path.

Step 4

#### Operate and review

Run Firebreak as part of regular response, review state changes through Archive and tune the trigger conditions over time.

Step 1

#### Map the paths

Step 2

#### Define the authority

Step 3

#### Rehearse and validate

Step 4

#### Operate and review

Organise a Demo: https://fire-vault.com/contact

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

Control for Water Playbook

### Control for Water: Deployment Playbook

Chapter three places Firebreak on the Purdue model for a water operator and walks the pilot through to rollout.

Read the playbook: Control for Water: Deployment Playbook
https://fire-vault.com/playbook/firebreak-water

A Control Blueprint for AI

### A Control Blueprint for AI: 2026 Playbook

Sets out where physical path severance belongs around training clusters, inference estates and agent action authority.

Read the playbook: A Control Blueprint for AI: 2026 Playbook
https://fire-vault.com/playbook/ai-control-blueprints

Firevault Aerospace Playbook

### A Control Blueprint for Aerospace & Aviation

Applies path control to design authority networks, maintenance systems and airside operational technology.

Read the playbook: A Control Blueprint for Aerospace & Aviation
https://fire-vault.com/playbook/aerospace

## Explore More

### FV-Isolate

Zones and trust boundaries that Firebreak operates between.

Learn more about FV-Isolate
https://fire-vault.com/control/modules/isolate

### FV-Relay

Purposeful, time-bound restoration of severed paths.

Learn more about FV-Relay
https://fire-vault.com/control/modules/relay

### Ransomware containment

Cut the route before the encryption finishes spreading.

Learn more about Ransomware containment
https://fire-vault.com/control-for-ransomware-containment

### AI kill switch

A physical shutdown capability for autonomous AI systems.

Learn more about AI kill switch
https://fire-vault.com/ai-kill-switch

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control/modules/firebreak#webpage",
    "url": "https://fire-vault.com/control/modules/firebreak",
    "name": "Control Firebreak Module: cut network paths",
    "description": "Firebreak severs network paths at Layer 1 in seconds, containing lateral movement before a breach can spread across IT or OT estates.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/2a9868c7-789c-40f7-bb9f-e70f75005876/og-control-firebreak.png"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control/modules/firebreak#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control/modules/firebreak#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control",
        "item": "https://fire-vault.com/control"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Modules",
        "item": "https://fire-vault.com/control/modules"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Control Firebreak Module: cut network paths",
        "item": "https://fire-vault.com/control/modules/firebreak"
      }
    ]
  }
]
```