Control Module - VAULT

FV-Unlink. Remove the relationships that expose the asset.

Unlink removes persistent connections, live dependencies and inherited trust relationships that quietly keep sensitive assets reachable. Where the relationship is not needed, it should not exist.

Back to Control
Corridor of offline storage racks inside a Firevault bunker
The exposure in numbers
01
Persistent connections removed where they are not required
SeveredPersistent connections removed where they are not required
02
Live dependencies replaced with mediated patterns
DecoupledLive dependencies replaced with mediated patterns
03
Trust does not carry over from one context to another
No inheritanceTrust does not carry over from one context to another
04
Every removal is recorded with its reason
ReviewableEvery removal is recorded with its reason
The Problem

Most exposure is paid for by relationships nobody chose to keep.

01

Persistent connections

Always-on connections between systems remain long after the reason for them has passed, available to anyone who later finds them.

02

Live dependencies

Direct, live dependencies between sensitive systems and convenience services drag the security posture of one onto the other.

03

Inherited trust

Trust that exists because two systems share a domain, a directory or a network neighbourhood is trust nobody chose to grant.

Control Module - VAULT

An asset is as exposed as its weakest relationship. Remove the relationship and you remove the exposure with it.

The Scenario

Scenario: cutting a quiet path that no longer earns its keep

A review of a sensitive records system shows a long-standing integration with a reporting service that has not been used in over a year, plus an inherited trust relationship with a directory that no longer needs to see those records. Unlink removes both, with the rationale recorded. The records remain available to the work that genuinely needs them and disconnected from the paths that no longer do.

"Unlink is the audit of relationships you forgot you had."

FV-Unlink in placement

Where Unlink removes inherited trust.

Unlink is the deliberate revocation of a trust relationship. It removes the inherited reach a credential, certificate or federation gave away in the first place.

Grounded in NIST CSF PR.AC-6 and PR.AC-7, ISO 27001 A.5.16 Identity Management and IEC 62443-3-3 SR 1.3.

Inputs ─┐Telemetry ─┐
FV-Unlink module icon

FV-Unlink

Control layer

┌─ Outputs┌─ Control
01A.5.16

Departing-staff trust revocation

Identity and certificate trust is revoked at the boundary, not just disabled in a directory.

02PR.AC-6

Compromised vendor relationship

Severs the standing trust to a compromised vendor's infrastructure. Restoring it is a deliberate act.

03PR.IP-6

Decommissioned system trust

Removes the inherited reach a retired system had into adjacent zones, even after it is unplugged.

04SR 1.3

Federation and SSO trust review

Periodic Unlink reviews surface unused federations before they become an attack surface.

Relies on · prerequisites

  • An accurate inventory of standing trusts in the first place
  • An authoritative revocation path that downstream systems honour
  • Evidence that the revocation actually took effect

Pairs with · companion modules

FV-Lock module iconLockFV-Isolate module iconIsolateFV-Validate module iconValidateFV-Firebreak module iconFirebreak

Featured In

TechRadar Pro logoYahoo Finance logoChannel Insider logoSecurity Buyer logoSecurityBrief logo

Capabilities

What you get with every deployment

01

Connection removal

Persistent connections that no longer serve a purpose are removed rather than catalogued.

02

Dependency decoupling

Live dependencies are replaced with mediated patterns so the sensitive asset does not inherit the posture of its dependants.

03

Trust pruning

Inherited trust relationships are reviewed and removed where the inheritance is no longer warranted.

04

Sensitive-asset focus

Effort is concentrated on the relationships that touch the assets that matter, rather than spread thinly across the estate.

05

Authorised removals

Removals require the right authority and are scoped to the relationship under review.

06

Evidential record

Each removal is recorded with the rationale, the approver and the outcome through Archive.

Demo to Live

Adoption Guide

Step 1

Inventory the relationships

Catalogue persistent connections, live dependencies and inherited trust touching the sensitive assets.

Step 2

Review with the owners

Work through the inventory with the relevant owners to identify what is no longer warranted.

Step 3

Pilot the removals

Remove a defined batch and confirm operational continuity before broadening the work.

Step 4

Operate and review

Run Unlink as an ongoing discipline, with reviews recorded through Archive.

Step 1

Inventory the relationships

Catalogue persistent connections, live dependencies and inherited trust touching the sensitive assets.

Step 2

Review with the owners

Work through the inventory with the relevant owners to identify what is no longer warranted.

Step 3

Pilot the removals

Remove a defined batch and confirm operational continuity before broadening the work.

Step 4

Operate and review

Run Unlink as an ongoing discipline, with reviews recorded through Archive.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy