---
title: "A Guide to Stopping Kill-Chain Ransomware with… | Firevault"
description: "How Control Blueprint CP-01 uses Control Modules to stop ransomware moving, spreading or reaching the crown jewels, what good looks like, and how a deployment…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint#webpage",
      "url": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint",
      "name": "A Guide to Stopping Kill-Chain Ransomware with…",
      "description": "How Control Blueprint CP-01 uses Control Modules to stop ransomware moving, spreading or reaching the crown jewels, what good looks like, and how a deployment…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fstopping-kill-chain-ransomware-control-blueprint.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "A Guide to Stopping Kill-Chain Ransomware with a Control Blueprint",
          "item": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "A Guide to Stopping Kill-Chain Ransomware with a Control Blueprint",
      "description": "How Control Blueprint CP-01 uses Control Modules to stop ransomware moving, spreading or reaching the crown jewels, what good looks like, and how a deployment is scoped.",
      "url": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fstopping-kill-chain-ransomware-control-blueprint.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-27T22:40:59.012961+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/stopping-kill-chain-ransomware-control-blueprint"
      },
      "inLanguage": "en-GB",
      "articleSection": "Guides",
      "wordCount": 490,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

About this guideThe problem this blueprint addre…CP-01 at a glanceThe primary modulesThe supporting modulesWhat good looks likeHow the blueprint is deployedHow to scope itNext stepsMore

[Guides](/learn/knowledge?filter=guides)

Guides · 27 August 2026 

# A Guide to Stopping Kill-Chain Ransomware with a Control Blueprint

How Control Blueprint CP-01 uses Control Modules to stop ransomware moving, spreading or reaching the crown jewels, what good looks like, and how a deployment is scoped.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fstopping-kill-chain-ransomware-control-blueprint)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fstopping-kill-chain-ransomware-control-blueprint&text=A%20Guide%20to%20Stopping%20Kill-Chain%20Ransomware%20with%20a%20Control%20Blueprint%0A%0AHow%20Control%20Blueprint%20CP-01%20uses%20Control%20Modules%20to%20stop%20ransomware%20moving%2C%20spreading%20or%20reaching%20the%20crown%20jewels%2C%20what%20good%20looks%20like%2C%20and%20how%20a%20deployment%20is%20scoped.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fstopping-kill-chain-ransomware-control-blueprint)[](mailto:?subject=A%20Guide%20to%20Stopping%20Kill-Chain%20Ransomware%20with%20a%20Control%20Blueprint&body=How%20Control%20Blueprint%20CP-01%20uses%20Control%20Modules%20to%20stop%20ransomware%20moving%2C%20spreading%20or%20reaching%20the%20crown%20jewels%2C%20what%20good%20looks%20like%2C%20and%20how%20a%20deployment%20is%20scoped.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fstopping-kill-chain-ransomware-control-blueprint)

![A Guide to Stopping Kill-Chain Ransomware with a Control Blueprint](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fstopping-kill-chain-ransomware-control-blueprint.jpg)

Guides 

Why it matters

## What this means for organisations holding critical data

How Control Blueprint CP-01 uses Control Modules to stop ransomware moving, spreading or reaching the crown jewels, what good looks like, and how a deployment is scoped.

**On this page**[About this guide](#section-0)[The problem this blueprint addre…](#section-1)[CP-01 at a glance](#section-2)[The primary modules](#section-3)[The supporting modules](#section-4)[What good looks like](#section-5)[How the blueprint is deployed](#section-6)[How to scope it](#section-7)[Next steps](#section-8)

On this page

1.  [About this guide](#section-0)
2.  [The problem this blueprint addresses](#section-1)
3.  [CP-01 at a glance](#section-2)
4.  [The primary modules](#section-3)
5.  [The supporting modules](#section-4)
6.  [What good looks like](#section-5)
7.  [How the blueprint is deployed](#section-6)
8.  [How to scope it](#section-7)
9.  [Next steps](#section-8)

## About this guide

This guide is written for security, infrastructure and risk leaders who need to stop ransomware moving, spreading or reaching the crown jewels. It explains one Control Blueprint, CP-01, in plain terms: the failure it addresses, the Control Modules it uses, how those modules work together, and how a deployment is scoped.

Control by Firevault is a suite of nine purpose-built modules: a set of tools and techniques that give you physical control over the paths into and across your estate. A Control Blueprint is a proven combination of those modules assembled for a specific outcome. This guide covers one blueprint. The [Control overview](/control) covers the nine modules and the full set of blueprints.

## The problem this blueprint addresses

Ransomware rarely succeeds at the point of entry. It succeeds in the movement that follows: credential reuse, lateral hops between zones, and a clear path to the systems that matter most. Logical segmentation and policy alone do not stop that movement once an attacker holds a valid session.

## CP-01 at a glance

-   **Lead layer** FIRE
-   **Primary modules** Firebreak, Isolate, Execute
-   **Supporting modules** Unlink, Lock
-   **Typical sectors** Financial services, healthcare, public sector and defence

## The primary modules

These modules do the work the blueprint is named for.

-   **Firebreak** physically breaks the connection path, so a route only exists when it is deliberately opened.
-   **Isolate** separates an environment at hardware level, so a compromised zone cannot reach a clean one.
-   **Execute** fires the control action on signal, without waiting for a change window.

## The supporting modules

These modules round out the pattern and are usually added as the deployment matures.

-   **Unlink** removes the always-on dependencies that quietly tunnel between zones.
-   **Lock** holds access to the systems that matter behind identity and condition controls.

## What good looks like

-   Movement between zones requires a physical path that is closed by default.
-   Containment is triggered by signal, not by a change request.
-   The crown jewels remain unreachable even when identity is compromised.
-   Every control action is recorded locally as evidence.

## How the blueprint is deployed

Control Modules are a suite of tools and techniques deployed within your own estate and applied to the paths they govern: at a boundary, inside a zone, or at a third-party edge. Authorisation and evidence remain local, so losing connectivity to Firevault never opens a path.

Most deployments start with a single boundary or zone, prove the control behaviour, then extend the same blueprint across the estate. Modules can be customer-operated or co-managed.

## How to scope it

Scoping starts with the paths, not the product. A short discovery exercise identifies the boundaries that matter, who needs to cross them, how often, and what evidence is required. That produces the module count and placement, which in turn produces the price. Blueprints are combined where an estate has more than one problem to solve.

## Next steps

-   Read the full blueprint detail: [CP-01 blueprint](/control-blueprints/cp-01)
-   See all nine modules and the other blueprints: [Control by Firevault](/control)
-   Talk it through with our team: [contact Firevault](/contact)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Control by Firevault governs the physical paths into your systems.**[Explore Control →](/solutions/control)

Keep a clean copy**Offline Secure Storage® holds a copy no attacker can reach.**[Why #OSS →](/why-oss)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

[Get started](/get-started)[Talk to the team](/demo)

**No standing access**Paths exist only when you open them 

**Verification**Identity confirmed before any connection is made 

**Containment**A compromised account cannot reach what is disconnected 

**Control**Every window and closure is under your command 

## Continue learning

-   [
    
    ### IT Director's Guide to Ransomware Recovery, Backups and Infrastructure Resilience
    
    The practical recovery guide: immutable versus offline, Active Directory rebuild, management plane compromise, clean recovery environments, restore testing and realistic RTO and RPO.
    
    Read guide ](/learn/guides/it-director-guide-ransomware-recovery)
-   [
    
    ### CISO Guide to Cyber Resilience: Risk, Recovery and Physical Control
    
    Threat modelling, attack paths, blast radius and recovery from the CISO seat, and an honest read of where Offline Secure Storage, Control Modules and Control Blueprints do and do not help.
    
    Read guide ](/learn/guides/ciso-guide-cyber-resilience)
-   [
    
    ### A Guide to Controlling Third-Party Access with a Control Blueprint
    
    How Control Blueprint CP-03 uses Control Modules to give third parties access without giving them a permanent doorway, what good looks like, and how a deployment is scoped.
    
    Read guide ](/learn/guides/controlling-third-party-access-control-blueprint)
-   [
    
    ### A Guide to Enforcing Physical Segmentation with a Control Blueprint
    
    How Control Blueprint CP-04 uses Control Modules to make segmentation physically enforceable rather than only logical, what good looks like, and how a deployment is scoped.
    
    Read guide ](/learn/guides/enforcing-physical-segmentation-control-blueprint)

Related Reading

## You may also find these useful

[

![Protecting Students, Peers and Partners: A Practical Education Data Briefing](/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg)

Guides 

### Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

29 Jul 2026 13 min 







](/news/guide-safeguarding-education-data)[

![Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye](/__l5e/assets-v1/084c38b8-253b-4cc2-9056-c78a2fbd36c3/urgent-warning-triangle-20260714-2x.jpg)

Guides 

### Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye

Practical steps for serving and former politicians, councillors, campaigners, journalists, executives, broadcasters and anyone in the public eye, covering email security, device hygiene, threat handling and offline secure storage.

14 Jul 2026 22 min 







](/news/urgent-guide-protecting-personal-data-high-profile-public-eye)[

![500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fcontrolled-access-buyers-guide.jpg)

Guides 

### 500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide

In April 2026, approved researchers exfiltrated the health records, genetic data, and medical histories of 500,000 UK Biobank volunteers through authorised access channels, then listed the data for sale on Alibaba. The breach was not caused by a hack. It was caused by a model that assumes licence agreements can prevent data theft. This guide covers why that model fails and what physical controls replace it.

23 Apr 2026 18 min 







](/news/controlled-access-buyers-guide-offline-secure-storage)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up