---
title: "Firebreak for Water Utilities: Deployment | Firevault"
description: "A 28-page adoption and deployment playbook for water boards, CISOs, OT leaders and network architects, Layer 1 physical path control mapped against the Purdue…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/playbook/firebreak-water#webpage",
      "url": "https://fire-vault.com/playbook/firebreak-water",
      "name": "Firebreak for Water Utilities: Deployment",
      "description": "A 28-page adoption and deployment playbook for water boards, CISOs, OT leaders and network architects, Layer 1 physical path control mapped against the Purdue…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "/__l5e/assets-v1/87198e25-711c-49ab-95d1-5f7cc99553cb/firebreak-water-cover.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/playbook/firebreak-water#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/playbook/firebreak-water#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Playbooks",
          "item": "https://fire-vault.com/playbooks"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Firebreak for Water: Adoption & Deployment Playbook",
          "item": "https://fire-vault.com/playbook/firebreak-water"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Firebreak for Water: Adoption & Deployment Playbook",
      "description": "A 28-page adoption and deployment playbook for water boards, CISOs, OT leaders and network architects, Layer 1 physical path control mapped against the Purdue model.",
      "inLanguage": "en-GB",
      "author": [
        {
          "@type": "Person",
          "name": "Mark Fermor"
        },
        {
          "@type": "Person",
          "name": "David Bailey"
        }
      ],
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "url": "https://fire-vault.com"
      },
      "image": "/__l5e/assets-v1/87198e25-711c-49ab-95d1-5f7cc99553cb/firebreak-water-cover.jpg",
      "keywords": "water sector cyber security, OT cyber security playbook, Purdue model physical segmentation, SCADA path control, IT OT boundary, Layer 1 physical isolation",
      "mainEntityOfPage": "https://fire-vault.com/playbook/firebreak-water"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Who is the Firebreak for Water Playbook for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It is written for water boards, CISOs, heads of OT security, network and control-system architects, and CNI programme leads. It is equally useful to regulators and consultancies working with the sector."
          }
        },
        {
          "@type": "Question",
          "name": "Does Firebreak replace my firewalls?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Firebreak is a Layer 1 physical path control, it sits below the firewall and decides whether a path exists at all. Firewalls, segmentation and monitoring continue to do what they do best; Firebreak removes the standing route that a compromised control would otherwise use."
          }
        },
        {
          "@type": "Question",
          "name": "How does the playbook relate to the Purdue model?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Chapter three maps Firebreak Control modules against Purdue levels 0–3.5 and the IT/OT boundary, so architects can see exactly where physical path control belongs alongside existing zones and conduits."
          }
        },
        {
          "@type": "Question",
          "name": "Is this a technical or a leadership document?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Both. The first half is written for board and CISO audiences; the second half is a deployment reference for OT architects and engineering teams. Each chapter is designed to be read on its own."
          }
        },
        {
          "@type": "Question",
          "name": "How is the playbook delivered?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "You request it with your work email and receive a secure link within a minute. The 28-page PDF is tied to that email address and can be forwarded internally once downloaded."
          }
        },
        {
          "@type": "Question",
          "name": "Can you brief my team on the content?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Reply to the delivery email and we will arrange a working session with Mark or David for your board, OT team or architecture group."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Playbooks",
          "item": "https://fire-vault.com/playbooks"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Firebreak for Water: Adoption & Deployment Playbook",
          "item": "https://fire-vault.com/playbook/firebreak-water"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

1.  [Home](/)
2.  [Playbooks](/playbooks)
3.  Firebreak for Water Playbook

Firebreak for Water Playbook 

# Firebreak for Water  
Control the path. Protect the supply. 

A 28-page adoption and deployment playbook for water boards, CISOs, OT leaders and network architects, Layer 1 physical path control mapped against the Purdue model.

28 pages

22 min read

Water boards and executive teams

![Firebreak for Water: Adoption & Deployment Playbook cover](/__l5e/assets-v1/87198e25-711c-49ab-95d1-5f7cc99553cb/firebreak-water-cover.jpg)

## Get the playbook

Emailed to you within a minute

First name \*

Last name \*

Work email \*

Personal email addresses such as Gmail or Yahoo are not accepted.

Company \*

Sector \*Select one, ... 

Job title \*

I agree to receive the playbook and occasional Firevault briefings. See our [privacy policy](/privacy-charter). 

Email me and open the playbook

Email-gated  GDPR compliant 

01 Foreword 

## Written by the people who build the controls.

The water sector's connectivity story has been written by convenience, not by design. Remote sites, third-party support, engineering tools and telemetry now share paths that were never intended to carry them. The Firebreak for Water Playbook is a practical response: it explains, in plain language, how Layer 1 physical path control complements existing firewalls and segmentation, where it belongs on the Purdue model, and how a water operator can pilot and scale it without ripping up what already works. It is written for the boards, CISOs, OT leaders and architects who now have to prove, to regulators and to themselves, that connectivity choices are intentional. Every Firevault playbook is grounded in the same doctrine behind our Offline Secure Storage® platform: control the path, govern the agent, protect the asset.

**Mark Fermor** · Co-Founder, Firevault 

**David Bailey** · Co-Founder, Firevault 

02 What's inside 

## 6 parts. Written for the people who own the decision.

Each chapter opens with the decision it exists to help you make, and closes with the evidence you should expect back.

01

### The water-sector control problem

Why standing connectivity, third-party access and operational consequence sit at the heart of water cyber resilience.

-   Convenience connectivity is now a systemic risk 
-   Physical path control is missing from most reference architectures 

02

### What Firebreak is

A plain-English explanation of Layer 1 physical path control and how it complements, never replaces, firewalls, segmentation and monitoring.

-   Firebreak sits below the firewall, not beside it 
-   The path either exists or it does not, no software override 

03

### Control blueprint for water

From bridge to controlled exchange. Where Firebreak Control modules sit across Purdue levels 0–3.5 and the IT/OT boundary.

-   A defensible reference architecture for OT engineering 
-   Clear ownership boundaries between IT and OT 

04

### Deployment use cases

IT/OT boundary, SCADA protection, supplier access, remote sites, legacy systems, isolation and recovery, aviation air-lock, seven patterns end-to-end.

-   Each use case maps to a named Control module 
-   Every pattern includes an evidence trail for regulators 

05

### Adoption model

Ownership, selection and command design: who decides the path, who opens it, and how the evidence is captured.

-   Path decisions become auditable events 
-   Ownership sits with operations, not the supplier 

06

### Pilot to rollout

Four steps from assessment to company-wide deployment, with a pilot acceptance pack the board can sign off.

-   A pilot is judged on reach, authority, evidence and recovery 
-   Rollout is staged by consequence, not geography 

03 Who it's for 

## Read it if you're accountable for the decision.

-   Water boards and executive teams 
-   CISOs and heads of OT security 
-   Network and control-system architects 
-   Regulators and CNI programme leads 

Sectors we hear from

Water & wastewater Energy & utilities Critical national infrastructure Government & defence 

04 A look inside 

## Real pages from the playbook.

A short preview of what lands in your inbox.

![Firebreak for Water: Adoption & Deployment Playbook preview, Standing connectivity](/__l5e/assets-v1/2232048b-606b-4dd7-aaa5-b63acb05cf37/firebreak-water-spread1.jpg)

Standing connectivity  Full page in playbook 

![Firebreak for Water: Adoption & Deployment Playbook preview, Physical vs logical control](/__l5e/assets-v1/e0bae3d3-9ab8-4f81-ac15-1af9ef30c255/firebreak-water-spread2.jpg)

Physical vs logical control  Full page in playbook 

![Firebreak for Water: Adoption & Deployment Playbook preview, IT / OT boundary](/__l5e/assets-v1/bcd32d35-47c9-4d9f-95ca-f39b0e85c687/firebreak-water-spread3.jpg)

IT / OT boundary  Full page in playbook 

![Firebreak for Water: Adoption & Deployment Playbook preview, Isolation and recovery](/__l5e/assets-v1/3afb37a0-50fc-49a3-a55e-2b99cfd8cd57/firebreak-water-spread4.jpg)

Isolation and recovery  Full page in playbook 

05 Frequently asked 

## Questions leaders ask before requesting.

Something else on your mind? Reply to any Firevault email or write to [mark@fire-vault.com](mailto:mark@fire-vault.com).

### Who is the Firebreak for Water Playbook for? 

### Does Firebreak replace my firewalls? 

### How does the playbook relate to the Purdue model? 

### Is this a technical or a leadership document? 

### How is the playbook delivered? 

### Can you brief my team on the content? 

06 More Firevault playbooks 

## Board-level control blueprints.

Each playbook is written for the people who own the decision, practical, UK-grounded and free to request.

[

![The Leaders' Playbook cover](/__l5e/assets-v1/e8c2b388-0083-4aa9-a143-f8c4b11d2db3/leaders-cover.jpg)](/playbook/leaders)

Related playbook

### The Leaders' Playbook

A board-level briefing on sovereign data, succession resilience and physical protection.

28 pages  18 min read  Email-gated 

[Get the playbook](/playbook/leaders)

[

![A Control Blueprint for AI: 2026 Playbook cover](/__l5e/assets-v1/d10e0e16-e107-4d93-b690-87f7b33bea9b/ai-control-cover.jpg)](/playbook/ai-control-blueprints)

Related playbook

### A Control Blueprint for AI: 2026 Playbook

40-page blueprint on AI infrastructure, open weights, agents and kill-switch design.

40 pages  28 min read  Email-gated 

[Get the playbook](/playbook/ai-control-blueprints)

[

![Close the File. Protect the Record. cover](/__l5e/assets-v1/a563c7e7-cdd3-47c3-8557-57a4d04b97b7/legal-cover.jpg)](/playbook/legal)

Related playbook

### Close the File. Protect the Record.

File closure, retained records and offline custody for UK law firms.

28 pages  20 min read  Email-gated 

[Get the playbook](/playbook/legal)

[

![A Control Blueprint for Aerospace & Aviation cover](/__l5e/assets-v1/bb5110b1-edcd-4a3a-93fc-af134ae6e4b7/aerospace-cover.jpg)](/playbook/aerospace)

Related playbook

### A Control Blueprint for Aerospace & Aviation

Communication registers, operational states and rapid isolation for aerospace and aviation.

28 pages  22 min read  Email-gated 

[Get the playbook](/playbook/aerospace)

## Ready to read it?

Request Firebreak for Water. It lands in your inbox within a minute, tied to your email address. No download, no fuss.

[Get the playbook](#get-the-playbook)[Talk to Mark](mailto:mark@fire-vault.com)