CISO Guide to Cyber Resilience: Risk, Recovery and Physical Control
Threat modelling, attack paths, blast radius and recovery from the CISO seat, and an honest read of where Offline Secure Storage, Control Modules and Control Blueprints do and do not help.
Why it matters
What this means for organisations holding critical data
Threat modelling, attack paths, blast radius and recovery from the CISO seat, and an honest read of where Offline Secure Storage, Control Modules and Control Blueprints do and do not help.
Who this guide is for
This guide is written for chief information security officers and heads of security who already have a control programme and need to reduce blast radius and prove recoverability rather than add more detection.
What the CISO is actually responsible for
- A defensible view of the threats that matter to this organisation, not the industry at large.
- Attack path analysis, and the blast radius that follows a privileged or identity compromise.
- Containment: the ability to stop movement quickly and decisively during an incident.
- Assurance that crown-jewel data and clean recovery data survive an attacker with administrative rights.
- An accurate statement of residual risk to the board.
The decisions you own, and what you can delegate
- Own the threat model, the control strategy and the residual risk statement.
- Own the containment authority: who may disconnect what, and how fast.
- Delegate operations, tuning and engineering, against clear outcomes.
- Delegate testing execution, but own the scenario design.
Modelling the paths that matter
Map the routes to your highest-value outcomes using an established taxonomy such as MITRE ATT&CK, then trace what each path reaches. The useful output is not a heat map. It is a short list of dependencies whose compromise gives an adversary everything at once.
- Identity compromise: tier-zero accounts, federation, and the consoles that trust them.
- Management plane compromise: hypervisor, backup, endpoint and network administration.
- Supplier and remote maintenance paths, which frequently sit outside standard controls.
- Data staging and exfiltration routes for crown-jewel data.
- Recovery paths that share credentials or infrastructure with the production estate.
Reducing blast radius
- Break the shared trust that lets a single credential reach multiple failure domains.
- Separate the recovery domain so that it is not administered from the production domain.
- Make containment a physical action that a responder can take in seconds without a change window.
- Hold a verified set of crown-jewel and recovery data that an administrator cannot reach or alter.
- Preserve evidence outside the estate so forensics survive the incident.
The questions to ask your own team
- If tier zero fell today, which controls would still hold, and how do we know?
- How long does it take to isolate a compromised zone, measured, not estimated?
- Which copies of our crown-jewel data can a domain administrator delete?
- What evidence would survive an attacker who dwelt for thirty days before acting?
- What residual risk are we knowingly carrying, and has the board accepted it?
The evidence to expect
- An attack path analysis with named dependencies and mitigation status.
- Measured containment and isolation times from exercise, not policy.
- Proof that recovery data is outside the administrative reach of the production estate.
- A tested clean-room recovery procedure.
- A residual risk register the board has actually seen.
What happens when preventative controls fail
Prevention buys time. It does not remove the need to answer a simple question: if an attacker holds your identity platform and your management console tonight, what still works tomorrow morning? Most organisations discover that their backup catalogue, their recovery credentials and their runbooks all depend on the systems that have just been taken. That is the dependency worth removing first.
No control removes the possibility of a serious incident. The realistic goal is a smaller blast radius, a recovery path that does not depend on the compromised estate, and evidence that both were tested.
Deciding what you actually need
A CISO can usually name the dependency that needs removing. The choice is whether it is removed by process, by logical control, or by a physical one. Firevault is the company. It provides three distinct things, and the honest answer is often that you need one of them rather than all of them.
- Offline Secure Storage® holds a defined set of critical records and clean recovery data physically disconnected from the live estate. It is a protected set, not a replacement for your backup infrastructure.
- Control Modules are a suite of nine purpose-built tools and techniques that give you physical control over the paths into and across your estate. Introduce only the modules that map to the risk you are treating.
- Control Blueprints are proven combinations of those modules assembled for a named outcome, such as containing a live breach or governing third-party access.
If your existing controls already deliver a tested recovery path that survives the compromise of your identity and management planes, and you can evidence it, you may not need any of this. Test that assumption before you buy anything. If you are unsure which of the three applies, the Firevault Concierge walks through the question set without a sales conversation.
The Control Blueprints most relevant to this role
This is the fullest view of the Firevault portfolio of any guide in the series, because the CISO usually has to hold the whole picture. Control by Firevault is a set of nine Control Modules, grouped into the FIRE layer (Firebreak, Isolate, Relay, Execute) and the VAULT layer (Validate, Archive, Unlink, Lock, Transfer). Seven Control Blueprints combine those modules for a specific outcome. You do not need all nine modules, and most organisations start with one blueprint.
- CP-01 Stop Kill-Chain Ransomware uses Firebreak, Isolate, Execute. Read the stop kill-chain ransomware guide.
- CP-02 Contain Active Breaches uses Firebreak, Isolate, Execute. Read the contain active breaches guide.
- CP-03 Control Third-Party Access uses Validate, Relay, Lock. Read the control third-party access guide.
- CP-04 Enforce Physical Segmentation uses Firebreak, Isolate, Unlink. Read the enforce physical segmentation guide.
- CP-05 Protect Critical Infrastructure uses Firebreak, Isolate, Relay, Execute. Read the protect critical infrastructure guide.
- CP-06 Prove Compliance Through Control uses Validate, Lock, Archive. Read the prove compliance through control guide.
- CP-07 Protect Aviation and Aerospace Networks uses Firebreak, Isolate, Validate, Relay. Read the protect aviation and aerospace networks guide.
The full set is on the Control overview and the Control Blueprints index.
Where to go next
Take the architecture detail from the security architecture guide, the recovery mechanics from the IT director guide, and the board framing from cyber security for boards. Our crown jewels audit is a practical first step.
Sources and further reading
- MITRE ATT&CK
- NCSC, Mitigating malware and ransomware attacks
- CISA StopRansomware
- NIST Cybersecurity Framework 2.0
- ISO/IEC 27001
About this guide
Author Mark Fermor, Firevault. Reviewed by Firevault security research. Last reviewed 28 August 2026.
This guide draws on primary regulatory and technical sources together with Firevault's own field work on physical isolation and offline recovery. It is guidance, not legal advice. Where a legal or regulatory duty is in question, take advice on your own circumstances.
Other guides in this series are listed on the role guide hub.
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.



Put this guide into practice
Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.
Takes about 2 minutes. No account needed.


