---
title: "Control: Governance for Offline Vaults | Firevault"
description: "Roles, approvals and a full audit trail for every offline vault your firm runs. Control is the governance layer that sits beside the hardware, never inside it."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control#webpage",
      "url": "https://fire-vault.com/control",
      "name": "Control: Governance for Offline Vaults",
      "description": "Roles, approvals and a full audit trail for every offline vault your firm runs. Control is the governance layer that sits beside the hardware, never inside it.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control#breadcrumb"
      },
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".lead-paragraph"
        ]
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control: Governance for Offline Vaults",
          "item": "https://fire-vault.com/control"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Product",
      "@id": "https://fire-vault.com/control#product",
      "name": "Control",
      "description": "Nine modules govern how data is accessed, moved, and disconnected across your environment. Hardware-encrypted, physically disconnected, offline by default.",
      "brand": {
        "@type": "Brand",
        "name": "Firevault"
      },
      "image": "https://fire-vault.com/images/og/og-platform.jpg",
      "url": "https://fire-vault.com/control",
      "category": "Data Path Governance",
      "manufacturer": {
        "@id": "https://fire-vault.com/#organization"
      },
      "offers": {
        "@type": "Offer",
        "price": "0",
        "priceCurrency": "GBP",
        "availability": "https://schema.org/InStock",
        "url": "https://fire-vault.com/control",
        "description": "Enterprise pricing. Contact for consultation.",
        "seller": {
          "@id": "https://fire-vault.com/#organization"
        }
      },
      "additionalProperty": [
        {
          "@type": "PropertyValue",
          "name": "Module Count",
          "value": "9"
        },
        {
          "@type": "PropertyValue",
          "name": "Modules",
          "value": "Firebreak, Transfer, Lock, Archive, Unlink, Vault, Execute, Relay, Isolate"
        },
        {
          "@type": "PropertyValue",
          "name": "Capability",
          "value": "Data path governance, access, movement, and disconnection orchestration"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Why Control

Nine modulesFirebreakWhat is includedAlternativesUK governanceUse casesWho it is for

![Control - data path governance for enterprise](/assets/control-icon-B9EWHzCT.png)Control 

# Control: network paths you can physically verify .

Nine purpose-built modules across two layers. The Fire  layer decides which paths exist. The Vault  layer decides what those paths are allowed to touch. Every decision is enforced in hardware you can see, hear and physically verify.

[Explore Control Blueprints](/control-blueprints) Speak to a member of the team

9

Modules

2

Layers

6

Blueprints

L1

Physical

FIRE, Control the path

VAULT, Protect the asset

![Control - data path governance for enterprise](/assets/control-icon-B9EWHzCT.png)

Control

![Relay module icon](/assets/relay-icon-CVhJDRO7.png)

Relay

![Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)

Unlink

![Lock module icon](/assets/lock-icon-UU3vOaKE.png)

Lock

Control Blueprint 

Vendor Access Window

-   ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)
    
    Relay Opens a controlled, time-bound path 
    
-   ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)
    
    Lock Restricts who can use it 
    
-   ![FV-Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)
    
    Unlink Removes the connection when done 
    

Live path control across Purdue Levels 0 to 5

01 Why we built this 

## Software alone was never going to be enough.

Three failures repeat in every incident report. Control removes all three by moving the decision into hardware, off the network it protects.

### An attacker who is in, gets to walk around

One compromised laptop is rarely the goal. It is the way in. Without a physical break in the path, the next system is only a hop away.

### The off switch sits on the wires it is meant to cut

If the kill command travels the same network as the threat, the attacker is already standing next to the off switch. Control moves that switch off the network entirely.

### Pulling cables works, it just does not scale

Every team that has handled a real incident knows the feeling. Control gives you the same outcome on demand, from anywhere, with a clean audit trail.

02 Nine modules 

## Four Fire modules decide the path. Five Vault modules decide the payload.

Every Control Blueprint is assembled from these nine modules. Nothing is bolted on afterwards.

[

### Firebreak

FIRE 

Physically opens or closes connection paths to prevent unauthorised access and stop attack progression.



](/control/modules/firebreak)[

### Isolate

FIRE 

Separates systems and networks into controlled zones to reduce lateral movement and enforce trust boundaries.



](/control/modules/isolate)[

### Relay

FIRE 

Allows connectivity only when needed, for a defined purpose, under controlled conditions and for a limited time.



](/control/modules/relay)[

### Execute

FIRE 

Initiates control actions when a policy, approval, schedule, incident state or supervisory override requires action.



](/control/modules/execute)[

### Validate

VAULT 

Checks whether a request, command or approval should proceed before access, action or transfer is allowed.



](/control/modules/validate)[

### Archive

VAULT 

Preserves critical files and records for recovery, retention, compliance, continuity and evidential integrity.



](/control/modules/archive)[

### Unlink

VAULT 

Removes persistent connections, live dependencies and inherited trust relationships that keep sensitive assets exposed.



](/control/modules/unlink)[

### Lock

VAULT 

Restricts access through identity, authority, policy, permission and operational controls.



](/control/modules/lock)[

### Transfer

VAULT 

Controls how sensitive assets move into, out of or between protected environments through approved paths.



](/control/modules/transfer)

03 Firebreak 

## Firebreak is the physical control point.

Where a Blueprint calls for a Layer 1 cut, Firebreak delivers it. Per-zone, independently, in milliseconds, over a command path that never touches the production network.

[See the Firebreak range](/firebreak)

RW

Stop Kill-Chain Ransomware

CB

Contain Active Breaches

3P

Control Third-Party Access

SG

Enforce Physical Segmentation

CI

Protect Critical Infrastructure

AG

Prove Compliance Through Control

Zone A

Segment A hosts

![FV-Fb module icon](/assets/firebreak-icon-7zSCkB1t.png)

Firebreak

Zone B

Segment B hosts

![FV-Un module icon](/assets/unlink-icon-B8GFAVW1.png)

Unlink

High-Trust Enclave

Classified, secrets

Zone A

Segment A hosts

![FV-Fb module icon](/assets/firebreak-icon-7zSCkB1t.png)

Firebreak

Zone B

Segment B hosts

![FV-Un module icon](/assets/unlink-icon-B8GFAVW1.png)

Unlink

High-Trust Enclave

Classified, secrets

SG · Break network trust, remove persistent exposure between systems. 

Module deck

Is

![Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)

Isolate

Re

![Relay module icon](/assets/relay-icon-CVhJDRO7.png)

Relay

Ex

![Execute module icon](/assets/execute-icon-kJl5Gtmk.png)

Execute

Va

![Validate module icon](/assets/vault-icon-CD3Pv4ri.png)

Validate

Ar

![Archive module icon](/assets/archive-icon-B3rc85NY.png)

Archive

Lo

![Lock module icon](/assets/lock-icon-UU3vOaKE.png)

Lock

Tr

![Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)

Transfer

Fire, path control Protect, asset protection 

04 What is included 

## Three properties every deployment inherits.

What Every Blueprint Includes

## Four pillars under every Control Blueprint

Whatever the outcome, every Blueprint rests on the same physical foundation.

### Out-of-band command path

Commands arrive over dedicated management Ethernet, cellular SMS, or an authenticated API. They never traverse the production network they control.

[Learn more](/firebreak#range)

### Per-zone independence

Each zone is switched independently. Isolate one circuit, one tenant, one SCADA segment, without touching the rest.

[Learn more](/control#how)

### Auditable, evidential log

Every action is logged locally and to SysLog. Verifiable records for NIS2, DORA, insurer scrutiny and internal audit.

[Learn more](/solutions/control/frameworks/nis2)

05 Against alternatives 

## Detection tells you. Manual cabling costs you. Control does it.

## Control vs the alternatives

Detect-and-respond and manual shutdown are the two positions most teams pick between. Control is the third.

Posture

Detect & respond

Manual shutdown

Control

Time to contain

Minutes to hours 

Minutes, manual 

Milliseconds, scheduled or on-demand 

Reversible without site visit

Yes 

No 

Yes 

Auditable physical action

No 

Ad hoc 

Yes 

Depends on uncompromised software

Yes 

No 

No, hardware path 

Scope of action

Alerts, blocks, isolates a host 

Whole segment, all or nothing 

Per-zone, per-module, per-blueprint 

Out-of-band command path

No 

No 

Yes 

Maps to NIS2 / DORA isolation

Indirect 

Indirect 

Yes 

06 UK governance 

## Board-level evidence, not screenshots.

UK Board-Level Cyber Governance

## Hardware-enforced accountability the board can sign off

The NCSC Cyber Security Toolkit for Boards and the UK NIS2 regime both put personal, evidenced accountability on directors. Control turns that duty into a physical artefact: a switch position, an out-of-band command and a signed log, not a policy assertion.

### NCSC Cyber Security Toolkit for Boards, mapped to Control

NCSC Board Toolkit, Principle A

#### Embed cyber security into your governance

Control gives the board a single, physical control point over connectivity. Zone state is a governance artefact, not a screenshot. Board packs cite the actual switch position, not an intent.

NCSC Board Toolkit, Principle B

#### Build a positive cyber security culture

Out-of-band command paths remove the temptation to bypass. Operators cannot silently reconnect a segment: every action requires a named identity on a separate management plane.

NCSC Board Toolkit, Principle C

#### Establish baseline security controls

Physical segmentation between OT and IT, between crown-jewel data and the estate, and between third parties and production. Hardware-enforced, not policy-enforced.

NCSC Board Toolkit, Principle D

#### Manage cyber risk in the supply chain

Supplier and MSP access is scheduled, identity verified and time bound. When the window closes, the segment is physically disconnected. Third-party breach blast radius is bounded by hardware.

NCSC Board Toolkit, Principle E

#### Plan your response to cyber incidents

Firebreak provides a rehearsed, board-authorised kill switch. Isolation happens without walking to a rack, without touching the compromised network, and produces a signed, timestamped record for the post-incident review.

Reference: [NCSC Cyber Security Toolkit for Boards](https://www.ncsc.gov.uk/collection/board-toolkit). Firevault maps controls to Toolkit principles; the Toolkit is guidance, not certification.

### UK NIS2 director duties, evidenced by hardware

#### Management body accountability, Article 20

NIS2 puts network security decisions on the board personally. Control makes those decisions evidenceable at the hardware layer, not just in policy documents, so directors can demonstrate they have discharged the duty.

[See NIS2 mapping](/solutions/control/frameworks/nis2)

#### Cybersecurity risk-management measures, Article 21

Article 21 requires network security, access control, supply-chain security and incident handling. Control's out-of-band command path, per-zone independence and signed logs map directly to Article 21(2)(a), (d), (e) and (i).

[See NIS2 mapping](/solutions/control/frameworks/nis2)

#### 24 and 72 hour incident notification, Article 23

The evidential log is generated at the moment of isolation, not reconstructed afterwards. Boards can meet the 24 hour early warning and 72 hour incident notification obligations with a defensible timeline.

[See NIS2 mapping](/solutions/control/frameworks/nis2)

07 Use cases 

## Where Control is already doing the work.

Use Cases

## Every sector reaches into the same seven Blueprints.

[

### Healthcare

Clinical data, medical devices and OT held behind physical isolation. Patient safety protected at Layer 1.

View use case ](/control-for-healthcare)

[

### Finance

Hardware-enforced isolation for banking, investment and financial services. Regulatory and operational evidence by design.

View use case ](/control-for-banking)

[

### Water Utilities

A new line of defence for the diverse OT and IT environments of the water sector. Assets protected from the physical layer up.

View use case ](/control-for-water)

[

### Oil and Gas

Physical protection of OT and IT for upstream, midstream and downstream estates. Removes the remote path to critical kit.

View use case ](/control-for-oil-and-gas)

[

### Telecoms

Physically isolating core telco infrastructure, satellite uplinks, OSS and BSS, and third-party access at the connection layer.

View use case ](/control-for-telecoms)

[

### Utilities

Operational continuity for electricity, gas and broader utility estates. Layer 1 control where software defences end.

View use case ](/control-for-utilities)

[

### Defence

Mission systems, classified enclaves and tactical kit held behind hardware-enforced disconnection.

View use case ](/control-for-defence)

[

### Public Sector

Government estates, councils and arm's-length bodies. Auditable physical control over connectivity.

View use case ](/control-for-public-sector)

[

### Education

Research networks, exam infrastructure and student data shielded from cyber attack at the physical layer.

View use case ](/control-for-education)

[

### Critical Infrastructure

The last line of defence for CNI. Removes remote attack paths to the systems a country cannot afford to lose.

View use case ](/control-for-critical-infrastructure)

08 Who it is for 

## Built for the teams who own the consequences.

Who Control Is For

## From OT segments to national infrastructure

Control is built for operators who need physical certainty over what is reachable, when, and by whom.

[

### Critical national infrastructure

Energy, water, rail and telco operators who need verifiable physical isolation on the IT/OT boundary.

](/control-for-critical-infrastructure)

[

### OT and SCADA environments

Sever legacy control networks on command for patching, incident response and routine isolation.

](/control-for-ot-environments)

[

### Defence and national security

Air-gap-on-demand for classified enclaves, test ranges and partner-connected programmes.

](/control-for-critical-infrastructure)

[

### Regulated finance

Demonstrable physical control for settlement enclaves, trading floors and audit-led isolation.

](/solutions/control/frameworks/nis2)

[

### Enterprise IT under NIS2 / DORA

Map a logical containment story to an evidential physical control that regulators and insurers recognise.

](/solutions/control/frameworks/nis2)

[

### Healthcare and research

Protect clinical systems, research data and connected medical equipment from lateral movement.

](/solutions/control)

## Decide what stays connected.

We will walk your architecture, map the modules you need and show you the evidence the board will be asked for.

Speak to a member of the team [Explore Blueprints](/control-blueprints)

[![Firevault - physical control for critical data](/assets/logo-white-official-BKfZ19hm.png)](/)

International cyber resilience

## Protect what matters. Control what moves. 

Firevault is an international cyber resilience company specialising in Offline Secure Storage® and OT cyber security, helping organisations protect critical data and govern how systems connect and how data moves.

[hello@fire-vault.com](mailto:hello@fire-vault.com)United Kingdom 

Cyber security certified 

[

![Cyber Essentials Certified](https://fire-vault.com/__l5e/assets-v1/6f8f42a2-89e1-4c20-938f-3f34d30bc90c/cyber-essentials-2026.png)

![Cyber Essentials Plus Certified](https://fire-vault.com/__l5e/assets-v1/8a77bf2c-6711-4762-b093-c4d650153bc9/cyber-essentials-plus-2026.png)

](https://registry.blockmarktech.com/certificates/)

Start here

### Not sure what you need?

Use the OSS Concierge to find the right protection or control approach for your organisation.

[Find your starting point ](/find-my-oss)

01  · Data protection & storage

[](/offline-secure-storage)

[

### Offline Secure Storage®

](/offline-secure-storage)

Physically disconnected by default, identity verified and built on dedicated hardware, from 300GB personal storage to enterprise-scale infrastructure.

[OSS overview](/offline-secure-storage)[LUV](/luv)[Vault](/vault)[Storage](/storage)[Enterprise](/enterprise)[Bunkers](/bunkers)

02  · Network evolution and rapid protection

[](/control)

[

### Control

](/control)

Nine governance modules across FIRE and VAULT, composed into Control Blueprints around the outcome, environment and risk you need to manage.

[Control overview](/control)[Nine modules](/control/nine-modules)[Blueprints](/control-blueprints)[Firebreak](/control/modules/firebreak)[Control by industry](/control-for-industry)

### Knowledge

-   [Knowledge Vault ](/learn/knowledge)
-   [Buyer guides ](/learn/guides/by-role)
-   [Technical guides ](/learn/guides/technical)
-   [Firevault Playbooks ](/playbooks)
-   [White papers ](/learn/whitepapers)
-   [Learn and explainers ](/learn)
-   [Breach tracker ](/learn/breaches)
-   [FAQs ](/learn/faq)

### Firevault

-   [About Firevault ](/about)
-   [Security ](/security)
-   [Partners ](/partners)
-   [Press and media ](/press-media)
-   [Help Centre ](/help)
-   [Careers ](/careers)
-   [Invest in Firevault ](/investors)
-   [Contact ](/contact)

© 2026 Firevault Limited · Company No. 16320803 · VAT No. 490 8551 64 · Registered in England and Wales 

[Site Map](/sitemap)[Privacy Charter](/privacy-charter)[Terms](/terms)[Planet Pledge](/planet-pledge)[Vault Commitment](/vault-commitment)[LUV Commitment](/luv-commitment)[Cookie Policy](/cookies)

[](https://www.linkedin.com/company/firevault-limited)[](https://twitter.com/firevaultuk)

![Firevault](/favicon.svg)

Real people, straight answers. 

Privacy 

## You decide what we measure

Essential cookies keep this site working. Everything else is optional and off until you say otherwise. Read the [Privacy Charter](/privacy-charter) or the [Cookie Policy](/cookies).

Accept allEssential only

Manage options