Why OSS

Cyber Resilience Guides by Role

Seven guides, one for each seat at the table. Each one starts with what the role is responsible for, the decisions it owns, the questions to ask and the evidence to expect, and only then covers where Firevault fits.

Corridor of offline storage racks inside a Firevault bunker
R1

Choose the guide that matches your accountability

Responsibility for cyber resilience is shared, but it is not identical. A board needs assurance and evidence. Finance needs a loss model. Technology and security leaders need architecture and containment. Compliance needs control effectiveness. Each guide is written for one of those jobs.

Board and managing directors · Foundational

Cyber Security for Boards

You are accountable for cyber risk without running security. This guide sets out what the board owns, what it should delegate, the questions to put to management and the evidence to expect back.

Read the guide
CFO and finance directors · Foundational

Cyber Risk, Financial Resilience and Recovery

You are asked to fund security without a way to price the risk it removes. This guide builds the loss model first, then reads what cyber insurance genuinely transfers and what stays retained.

Read the guide
CIO and CTO · Intermediate

Cyber Resilience, Architecture and Recovery

Recovery fails on dependencies, not on tooling. This guide maps identity, management plane, cloud and supplier dependencies, then sets out how to design a recovery architecture that survives them.

Read the guide
CISO and heads of security · Advanced

Risk, Recovery and Physical Control

You already have detection. This guide concentrates on attack paths, blast radius after a privileged compromise, containment speed and an honest statement of residual risk.

Read the guide
IT directors and infrastructure · Intermediate

Ransomware Recovery, Backups and Resilience

Immutable, air-gapped and offline are not the same thing. This guide covers the rebuild sequence, identity recovery, recovery credentials and restore testing that produces a defensible RTO.

Read the guide
Risk, compliance and governance · Intermediate

Controls, Evidence and Assurance

Auditors ask whether controls work, not whether they exist. This guide covers risk treatment, control effectiveness, third-party assurance, exceptions and the evidence that survives challenge.

Read the guide
Security architects · Advanced

Physical Isolation, Segmentation and Resilience

Almost every control in a modern estate is configuration. This guide works through trust boundaries, failure domains, Layer 1 isolation, Zero Trust dependencies, the Purdue Model and IEC 62443.

Read the guide

How these guides relate to the Firevault portfolio

Firevault is the company. It provides Offline Secure Storage® for a defined set of critical records and clean recovery data, nine Control Modules that govern the physical paths into an estate, and seven Control Blueprints that combine those modules for a named outcome. Each role guide introduces only the parts that are relevant to that role.

If you are unsure which applies, the Firevault Concierge works through the questions without a sales conversation.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up