---
title: "Control Solutions for Network Paths | Firevault"
description: "Govern every path in and out. Explore Control by need, by blueprint, by industry, by threat or by compliance framework, with Layer 1 governance enforced in…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/solutions/control#webpage",
      "url": "https://fire-vault.com/solutions/control",
      "name": "Control Solutions for Network Paths",
      "description": "Govern every path in and out. Explore Control by need, by blueprint, by industry, by threat or by compliance framework, with Layer 1 governance enforced in…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-solutions.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/solutions/control#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/solutions/control#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Solutions",
          "item": "https://fire-vault.com/solutions"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Control Solutions for Network Paths",
          "item": "https://fire-vault.com/solutions/control"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@graph": [
        {
          "@type": "CollectionPage",
          "name": "Control Solutions Hub",
          "description": "Control solutions organised by need, blueprint, industry, threat, module and framework.",
          "url": "https://fire-vault.com/solutions/control"
        },
        {
          "@type": "BreadcrumbList",
          "itemListElement": [
            {
              "@type": "ListItem",
              "position": 1,
              "name": "Home",
              "item": "https://fire-vault.com/"
            },
            {
              "@type": "ListItem",
              "position": 2,
              "name": "Solutions",
              "item": "https://fire-vault.com/solutions"
            },
            {
              "@type": "ListItem",
              "position": 3,
              "name": "Control",
              "item": "https://fire-vault.com/solutions/control"
            }
          ]
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Control, systems and access 

# Govern every path in and out .

Control governs connectivity in hardware at Layer 1. Paths open on command, close on command and leave an audit trail. Start with the need you have, then move to the blueprint that delivers it.

Book a walkthrough[How Control works](/control)

05

Needs covered for systems and access

07

Deployment blueprints, CP-01 to CP-07

09

Control modules across the platform

L1

Governance enforced in hardware at Layer 1

01 What Control is 

## Physical governance for the paths your systems depend on.

Every Control module runs on a Layer 1 connection controller. It opens and closes network paths in hardware, on command, over an authenticated out-of-band channel. If the path does not exist, no attack can travel it.

Hardware enforcement

The path is broken in physics, not in a rule set that can be misconfigured.

Command and audit

Every open and close is authorised, time-bound and logged for evidence.

Modular deployment

Seven blueprints, CP-01 to CP-07, matched to the environment you run.

02 By need 

## What do you need to protect?

Five needs covering systems and access. Each one leads to the Control blueprint built to deliver it.

[

06 

### Critical systems and network exposure

Leads to Blueprint CP-04 and CP-05.

Explore ](/control-for-critical-systems)[

07 

### Ransomware and lateral movement

Leads to Blueprint CP-01 and CP-02.

Explore ](/control-for-lateral-movement)[

08 

### Third-party and remote access

Leads to Blueprint CP-03.

Explore ](/control-for-third-party-access)[

09 

### AI systems and infrastructure

Leads to the AI Control patterns.

Explore ](/control-for-ai-systems)[

10 

### Data centre and colocation exposure

Leads to Blueprint CP-04 and CP-05.

Explore ](/control-for-data-centre-exposure)

[All Control needs](/control-for)

03 By blueprint 

## Seven deployment blueprints.

Each blueprint, CP-01 to CP-07, is an outcome-led pattern for isolating, containing or proving control. Pick the one that matches your environment.

[

CP-01 

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

](/control-blueprints/cp-01)[

CP-02 

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

](/control-blueprints/cp-02)[

CP-03 

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

](/control-blueprints/cp-03)[

CP-04 

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

](/control-blueprints/cp-04)[

CP-05 

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

](/control-blueprints/cp-05)[

CP-06 

### Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

](/control-blueprints/cp-06)[

CP-07 

### Protect Aviation and Aerospace Networks

Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.

](/control-blueprints/cp-07)

[All blueprints](/control-blueprints)

04 By industry 

## Control blueprints for your industry.

Sector-specific deployments for the environments where path governance matters most.

[

### AI Systems

Control patterns for AI and model infrastructure.

](/control-for-ai-systems)[

### Data Centres and Colocation

Tenant isolation and cross-connect governance.

](/control-for-colocations)[

### Operational Technology

Physical-path governance for SCADA and ICS.

](/control-for-ot-environments)[

### Critical Infrastructure

National-grade path governance.

](/control-for-critical-infrastructure)[

### Telecommunications

Carrier and backbone path governance.

](/control-for-telecoms)[

### Utilities

Grid and utility SCADA isolation.

](/control-for-utilities)[

### Water

Treatment and distribution SCADA control.

](/control-for-water)[

### Public Sector

Government network isolation.

](/control-for-public-sector)[

### Military and Defence

Network severance for national security.

](/control-for-defence)[

### Healthcare

Clinical network and device isolation.

](/control-for-healthcare)

[All industries](/control-for-industry)

05 By threat 

## Pick the attack pattern you need to contain.

From ransomware to insider risk and supply chain compromise. Each threat maps to a Control response.

[

### Ransomware Containment

Sever the path before ransomware spreads.

](/control-for-ransomware-containment)[

### Insider Threat

Remove persistent access outside operational windows.

](/control-for-insider-threat)[

### Supply Chain Risk

Disconnect third-party paths when not in active use.

](/control-for-supply-chain-risk)[

### IT/OT Convergence

Physically separate IT from operational technology.

](/control-for-it-ot-convergence)[

### Management Plane Exposure

Isolate management interfaces from production networks.

](/control-for-management-plane)

[All threats](/control-for-industry)

06 Modules and frameworks 

## The platform underneath, and the standards it evidences.

Nine Control modules deliver the enforcement. Compliance frameworks are mapped to outcomes, so audits get evidence rather than assertions.

Control modules

[

### FV-Firebreak

Cut the Path. Physically open or close connection paths.

](/control/modules/firebreak)[

### FV-Isolate

Separate the Zones. Split systems, networks and environments.

](/control/modules/isolate)[

### FV-Relay

Open Briefly. Connectivity only when needed, for a defined window.

](/control/modules/relay)[

### FV-Execute

Trigger Action. Initiate control on rule, approval, alert or override.

](/control/modules/execute)[

### FV-Validate

Confirm the Asset. Owner, authority and purpose before access.

](/control/modules/validate)[

### FV-Unlink

Remove Exposure. Strip persistent connections and inherited trust.

](/control/modules/unlink)[

### FV-Archive

Preserve the Asset. For recovery, retention, compliance and evidence.

](/control/modules/archive)[

### FV-Lock

Restrict Access. By identity, authority, policy and permission.

](/control/modules/lock)[

### FV-Transfer

Move Under Control. Approved paths, defined windows, verified authority.

](/control/modules/transfer)

[All modules](/control/nine-modules)

Frameworks mapped

[

### IEC 62443

Industrial automation security and Purdue model compliance.

](/solutions/control/frameworks/iec-62443)[

### MITRE ATT&CK

Map Control modules to MITRE techniques and mitigations.

](/solutions/control/frameworks/mitre-attack)[

### NIS2

Operational resilience for essential and important entities.

](/solutions/control/frameworks/nis2)[

### DORA

Digital operational resilience for financial services.

](/solutions/control/frameworks/dora)[

### ISO 27001

Information security management and Annex A controls.

](/solutions/control/frameworks/iso-27001)[

### NIST CSF

Identify, protect, detect, respond, recover alignment.

](/solutions/control/frameworks/nist-csf)[

### Cyber Essentials

UK baseline certification with physical isolation evidence.

](/solutions/control/frameworks/cyber-essentials)

[Compliance hub](/compliance)

Playbooks 

## Published playbooks

Board-ready briefings for Control decision makers. Free to download after a quick identity check.

[All playbooks](/playbooks)

[

Playbook · 28 pages 

#### The Leaders' Playbook

A board-level briefing on sovereign data, succession resilience and physical protection.

Read the playbook 

](/playbook/leaders)

[

Playbook · 40 pages 

#### A Control Blueprint for AI: 2026 Playbook

40-page blueprint on AI infrastructure, open weights, agents and kill-switch design.

Read the playbook 

](/playbook/ai-control-blueprints)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up