---
title: "Security Architecture Guide: Physical Isolation… | Firevault"
description: "The deepest guide in the series: trust boundaries, attack paths, failure domains, Layer 1 isolation versus logical segmentation, control and management…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/security-architecture-guide#webpage",
      "url": "https://fire-vault.com/learn/guides/security-architecture-guide",
      "name": "Security Architecture Guide: Physical Isolation…",
      "description": "The deepest guide in the series: trust boundaries, attack paths, failure domains, Layer 1 isolation versus logical segmentation, control and management…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fsecurity-architecture-guide.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/security-architecture-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/security-architecture-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Security Architecture Guide: Physical Isolation, Segmentation and Cyber Resilience",
          "item": "https://fire-vault.com/learn/guides/security-architecture-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Security Architecture Guide: Physical Isolation, Segmentation and Cyber Resilience",
      "description": "The deepest guide in the series: trust boundaries, attack paths, failure domains, Layer 1 isolation versus logical segmentation, control and management planes, Zero Trust, the Purdue Model and IEC 62443.",
      "url": "https://fire-vault.com/learn/guides/security-architecture-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fsecurity-architecture-guide.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T06:40:39.037135+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/security-architecture-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Guides",
      "wordCount": 1170,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

Who this guide is forWhat the architect is actually r…Logical and physical isolationZero Trust, honestly appliedOT, the Purdue Model and IEC 62443Architecture patterns worth adop…Mapping modules to boundariesThe questions to ask of any designThe evidence to expectWhat happens when preventative c…Deciding what you actually needThe Control Blueprints most rele…Where to go nextSources and further readingAbout this guideMore

[Guides](/learn/knowledge?filter=guides)

Guides · 28 August 2026 

# Security Architecture Guide: Physical Isolation, Segmentation and Cyber Resilience

The deepest guide in the series: trust boundaries, attack paths, failure domains, Layer 1 isolation versus logical segmentation, control and management planes, Zero Trust, the Purdue Model and IEC 62443.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

7 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fsecurity-architecture-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fsecurity-architecture-guide&text=Security%20Architecture%20Guide%3A%20Physical%20Isolation%2C%20Segmentation%20and%20Cyber%20Resilience%0A%0AThe%20deepest%20guide%20in%20the%20series%3A%20trust%20boundaries%2C%20attack%20paths%2C%20failure%20domains%2C%20Layer%201%20isolation%20versus%20logical%20segmentation%2C%20control%20and%20management%20planes%2C%20Zero%20Trust%2C%20the%20Purdue%20Model%20and%20IEC%2062443.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fsecurity-architecture-guide)[](mailto:?subject=Security%20Architecture%20Guide%3A%20Physical%20Isolation%2C%20Segmentation%20and%20Cyber%20Resilience&body=The%20deepest%20guide%20in%20the%20series%3A%20trust%20boundaries%2C%20attack%20paths%2C%20failure%20domains%2C%20Layer%201%20isolation%20versus%20logical%20segmentation%2C%20control%20and%20management%20planes%2C%20Zero%20Trust%2C%20the%20Purdue%20Model%20and%20IEC%2062443.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fsecurity-architecture-guide)

![Security Architecture Guide: Physical Isolation, Segmentation and Cyber Resilience](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fsecurity-architecture-guide.jpg)

Guides 

Why it matters

## What this means for organisations holding critical data

The deepest guide in the series: trust boundaries, attack paths, failure domains, Layer 1 isolation versus logical segmentation, control and management planes, Zero Trust, the Purdue Model and IEC 62443.

**On this page**[Who this guide is for](#section-0)[What the architect is actually r…](#section-1)[Logical and physical isolation](#section-2)[Zero Trust, honestly applied](#section-3)[OT, the Purdue Model and IEC 62443](#section-4)[Architecture patterns worth adop…](#section-5)[Mapping modules to boundaries](#section-6)[The questions to ask of any design](#section-7)[The evidence to expect](#section-8)[What happens when preventative c…](#section-9)[Deciding what you actually need](#section-10)[The Control Blueprints most rele…](#section-11)[Where to go next](#section-12)[Sources and further reading](#section-13)[About this guide](#section-14)

On this page

1.  [Who this guide is for](#section-0)
2.  [What the architect is actually responsible for](#section-1)
3.  [Logical and physical isolation](#section-2)
4.  [Zero Trust, honestly applied](#section-3)
5.  [OT, the Purdue Model and IEC 62443](#section-4)
6.  [Architecture patterns worth adopting](#section-5)
7.  [Mapping modules to boundaries](#section-6)
8.  [The questions to ask of any design](#section-7)
9.  [The evidence to expect](#section-8)
10.  [What happens when preventative controls fail](#section-9)
11.  [Deciding what you actually need](#section-10)
12.  [The Control Blueprints most relevant to this role](#section-11)
13.  [Where to go next](#section-12)
14.  [Sources and further reading](#section-13)
15.  [About this guide](#section-14)

## Who this guide is for

This guide is written for security architects and senior engineers designing trust boundaries, segmentation and recovery architecture. It assumes familiarity with Zero Trust, the Purdue Model and [IEC 62443](/solutions/control/frameworks/iec-62443).

## What the architect is actually responsible for

-   Defining trust boundaries and stating what each boundary is assumed to withstand.
-   Mapping data flows and the attack paths that follow them.
-   Designing failure domains so that a compromise in one does not propagate to all.
-   Separating control planes, management planes and data planes.
-   Removing circular dependencies between production and recovery.

## Logical and physical isolation

Almost every control in a modern estate is logical. VLANs, policy, firewalls, conditional access and micro-segmentation are all configuration, and configuration is reachable by whoever holds the management plane. That is the assumption most architectures never state.

-   **Layer 3** controls depend on routing policy and on the devices enforcing it.
-   **Layer 2** segmentation depends on switch configuration and on the administrative domain around it.
-   **Layer 1** isolation removes the electrical path. There is nothing to reconfigure, because there is no route to permit.

See [physical versus logical air gap](/learn/physical-vs-logical-air-gap) and [Layer 1 in practice](/why-oss/layer-1) for the detail.

## Zero Trust, honestly applied

Zero Trust removes implicit network trust, but it moves the dependency onto the identity and policy plane. A mature architecture states what happens when that plane is the thing that fails. In most designs the answer is that every logical control fails open or fails unavailable at the same moment. A small number of physical boundaries around the recovery domain restores a floor beneath the design.

## OT, the Purdue Model and IEC 62443

-   Purdue levels remain a useful reference for zoning even where the model is flattened by modern connectivity.
-   IEC 62443 zones and conduits map cleanly onto physical boundary enforcement.
-   Safety and availability outrank confidentiality, so controls must fail into a safe, known state.
-   Remote maintenance is the dominant route between enterprise and process networks.

Our [Purdue Model diagram](/learn/purdue-model-diagram) shows the zoning we use in blueprint work.

## Architecture patterns worth adopting

1.  A recovery domain administered separately from production, with no shared tier-zero identity.
2.  Broker-mediated third-party access, where the path only exists while a validated session is live.
3.  Physically enforced zone boundaries at the points where a lateral move would be most damaging.
4.  Evidence capture written to a store the production estate cannot alter.
5.  A defined critical set held with no electrical path to the live network.

## Mapping modules to boundaries

Control by Firevault provides nine Control Modules. The FIRE layer governs the path: Firebreak breaks it, Isolate separates environments at hardware level, Relay mediates a controlled connection, Execute fires the action on signal. The VAULT layer governs the data and the record: Validate checks conditions before a path opens, Archive preserves evidence, Unlink removes a standing connection, Lock holds access behind identity and condition, Transfer moves data across a boundary under control.

Architects rarely deploy all nine. Choose the modules that enforce the boundaries your threat model says are load-bearing.

## The questions to ask of any design

1.  Which controls in this design are configuration, and who can change that configuration?
2.  What is the blast radius if the management plane for this zone is compromised?
3.  Does anything in the recovery path depend on the domain it is recovering?
4.  Which boundaries would still hold with no power to the policy plane?
5.  How is a boundary crossing evidenced, and can that evidence be altered from inside?

## The evidence to expect

-   Current data flow and trust boundary diagrams, with assumptions written down.
-   An attack path model referenced to MITRE ATT&CK.
-   Zone and conduit documentation for OT environments.
-   Test results showing a boundary holding under simulated administrative compromise.
-   A dependency-free recovery design, reviewed independently.

## What happens when preventative controls fail

Prevention buys time. It does not remove the need to answer a simple question: if an attacker holds your identity platform and your management console tonight, what still works tomorrow morning? Most organisations discover that their backup catalogue, their recovery credentials and their runbooks all depend on the systems that have just been taken. That is the dependency worth removing first.

No control removes the possibility of a serious incident. The realistic goal is a smaller blast radius, a recovery path that does not depend on the compromised estate, and evidence that both were tested.

## Deciding what you actually need

Architects should treat Firevault as a way to move a small number of load-bearing controls out of configuration and into physics. Everything else stays where it is. Firevault is the company. It provides three distinct things, and the honest answer is often that you need one of them rather than all of them.

-   **[Offline Secure Storage®](/offline-secure-storage)** holds a defined set of critical records and clean recovery data physically disconnected from the live estate. It is a protected set, not a replacement for your backup infrastructure.
-   **[Control Modules](/control)** are a suite of nine purpose-built tools and techniques that give you physical control over the paths into and across your estate. Introduce only the modules that map to the risk you are treating.
-   **[Control Blueprints](/control-blueprints)** are proven combinations of those modules assembled for a named outcome, such as containing a live breach or governing third-party access.

If your existing controls already deliver a tested recovery path that survives the compromise of your identity and management planes, and you can evidence it, you may not need any of this. Test that assumption before you buy anything. If you are unsure which of the three applies, the [Firevault Concierge](/find-my-oss) walks through the question set without a sales conversation.

## The Control Blueprints most relevant to this role

All seven blueprints are relevant to architecture work, and each blueprint page carries its own topology. Control by Firevault is a set of nine Control Modules, grouped into the FIRE layer (Firebreak, Isolate, Relay, Execute) and the VAULT layer (Validate, Archive, Unlink, Lock, Transfer). Seven Control Blueprints combine those modules for a specific outcome. You do not need all nine modules, and most organisations start with one blueprint.

-   **[CP-01 Stop Kill-Chain Ransomware](/control-blueprints/cp-01)** uses Firebreak, Isolate, Execute. Read the [stop kill-chain ransomware guide](/learn/guides/stopping-kill-chain-ransomware-control-blueprint).
-   **[CP-02 Contain Active Breaches](/control-blueprints/cp-02)** uses Firebreak, Isolate, Execute. Read the [contain active breaches guide](/learn/guides/containing-active-breaches-control-blueprint).
-   **[CP-03 Control Third-Party Access](/control-blueprints/cp-03)** uses Validate, Relay, Lock. Read the [control third-party access guide](/learn/guides/controlling-third-party-access-control-blueprint).
-   **[CP-04 Enforce Physical Segmentation](/control-blueprints/cp-04)** uses Firebreak, Isolate, Unlink. Read the [enforce physical segmentation guide](/learn/guides/enforcing-physical-segmentation-control-blueprint).
-   **[CP-05 Protect Critical Infrastructure](/control-blueprints/cp-05)** uses Firebreak, Isolate, Relay, Execute. Read the [protect critical infrastructure guide](/learn/guides/protecting-critical-infrastructure-control-blueprint).
-   **[CP-06 Prove Compliance Through Control](/control-blueprints/cp-06)** uses Validate, Lock, Archive. Read the [prove compliance through control guide](/learn/guides/proving-compliance-through-control-blueprint).
-   **[CP-07 Protect Aviation and Aerospace Networks](/control-blueprints/cp-07)** uses Firebreak, Isolate, Validate, Relay. Read the [protect aviation and aerospace networks guide](/learn/guides/protecting-aviation-and-aerospace-networks-control-blueprint).

The full set is on the [Control overview](/control) and the [Control Blueprints index](/control-blueprints).

## Where to go next

Read the [CISO guide](/learn/guides/ciso-guide-cyber-resilience) for the risk framing, the [CIO and CTO guide](/learn/guides/cio-cto-guide-cyber-resilience) for the estate view, and [physical layer security architecture](/learn/guides/physical-layer-security-architecture) for the underlying principles.

## Sources and further reading

-   [MITRE ATT&CK](https://attack.mitre.org/)
-   [IEC 62443 series](https://www.iec.ch/blog/understanding-iec-62443)
-   [NCSC Cyber Security Design Principles](https://www.ncsc.gov.uk/collection/cyber-security-design-principles)
-   [NIST Cybersecurity Framework 2.0](https://www.nist.gov/cyberframework)
-   [ISO/IEC 27001](https://www.iso.org/standard/27001)

## About this guide

**Author** Mark Fermor, Firevault. **Reviewed by** Firevault engineering review. **Last reviewed** 28 August 2026.

This guide draws on primary regulatory and technical sources together with Firevault's own field work on physical isolation and offline recovery. It is guidance, not legal advice. Where a legal or regulatory duty is in question, take advice on your own circumstances.

Other guides in this series are listed on the [role guide hub](/learn/guides/by-role).

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### Cyber Risk & Compliance Guide: Controls, Evidence and Resilience for GRC Leaders
    
    How risk and compliance leaders can move from control existence to control effectiveness: risk treatment, evidence, third-party assurance, exceptions and remediation that survive audit.
    
    Read guide ](/learn/guides/cyber-risk-and-compliance-guide)
-   [
    
    ### IT Director's Guide to Ransomware Recovery, Backups and Infrastructure Resilience
    
    The practical recovery guide: immutable versus offline, Active Directory rebuild, management plane compromise, clean recovery environments, restore testing and realistic RTO and RPO.
    
    Read guide ](/learn/guides/it-director-guide-ransomware-recovery)
-   [
    
    ### CISO Guide to Cyber Resilience: Risk, Recovery and Physical Control
    
    Threat modelling, attack paths, blast radius and recovery from the CISO seat, and an honest read of where Offline Secure Storage, Control Modules and Control Blueprints do and do not help.
    
    Read guide ](/learn/guides/ciso-guide-cyber-resilience)
-   [
    
    ### The CIO & CTO Guide to Cyber Resilience, Architecture and Recovery
    
    A technology leader's view of resilience: dependency mapping, recovery architecture, identity and cloud concentration, IT and OT convergence, and where physical controls earn their place.
    
    Read guide ](/learn/guides/cio-cto-guide-cyber-resilience)

Related Reading

## You may also find these useful

[

![Protecting Students, Peers and Partners: A Practical Education Data Briefing](/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg)

Guides 

### Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

29 Jul 2026 13 min 







](/news/guide-safeguarding-education-data)[

![Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye](/__l5e/assets-v1/084c38b8-253b-4cc2-9056-c78a2fbd36c3/urgent-warning-triangle-20260714-2x.jpg)

Guides 

### Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye

Practical steps for serving and former politicians, councillors, campaigners, journalists, executives, broadcasters and anyone in the public eye, covering email security, device hygiene, threat handling and offline secure storage.

14 Jul 2026 22 min 







](/news/urgent-guide-protecting-personal-data-high-profile-public-eye)[

![500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fcontrolled-access-buyers-guide.jpg)

Guides 

### 500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide

In April 2026, approved researchers exfiltrated the health records, genetic data, and medical histories of 500,000 UK Biobank volunteers through authorised access channels, then listed the data for sale on Alibaba. The breach was not caused by a hack. It was caused by a model that assumes licence agreements can prevent data theft. This guide covers why that model fails and what physical controls replace it.

23 Apr 2026 18 min 







](/news/controlled-access-buyers-guide-offline-secure-storage)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up