Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Cyber Essentials

Exceed UK Baseline Certification with Physical Isolation Evidence

Cyber Essentials establishes baseline security requirements for UK organisations. Control provides physical measures that demonstrably exceed baseline requirements, providing stronger evidence for Cyber Essentials Plus certification and supply chain assurance.

Back to Control
Control by Firevault product icon

Cyber Essentials

Cyber Essentials certification demonstrates baseline security hygiene. Physical enforcement demonstrates that those baselines are continuously maintained and cannot be accidentally undermined.

5/5

Technical controls with physical enforcement

100%

Boundary firewall requirements exceeded

CE+

Cyber Essentials Plus evidence strengthened

Full

Continuous certification evidence

The Certification Gap

Baseline certification is necessary but not sufficient.

Baseline vs Reality

Cyber Essentials certifies baseline controls at a point in time. Between assessments, control effectiveness can degrade through configuration drift and human error.

Boundary Device Limitations

Cyber Essentials requires boundary firewalls, but firewalls can be misconfigured, bypassed, or compromised, undermining the boundary they are meant to protect.

Supply Chain Requirements

Government and enterprise contracts increasingly require Cyber Essentials Plus. Stronger evidence differentiates organisations competing for these contracts.

The Scenario

Scenario: Supply Chain Tender with Physical Evidence

A government department evaluates three suppliers for a sensitive contract. All three hold Cyber Essentials Plus certification. However, the department's security assessment reveals that two suppliers rely entirely on software-based boundary controls that have experienced configuration incidents in the past year. The third supplier presents physical boundary enforcement evidence from Control, showing continuous, unbroken boundary protection with tamper-proof logs. The department selects the supplier with physical enforcement, noting that physical boundaries provide a higher assurance level for the sensitivity of the contract.

"All our competitors had Cyber Essentials Plus. What differentiated us was the ability to show physical boundary enforcement with continuous evidence. For the government buyer, physical controls meant genuine assurance, not just a certificate."

Cyber Essentials mapping

Where Cyber Essentials controls meet Control modules.

Cyber Essentials and Cyber Essentials Plus prescribe five technical control themes. Control hardens those themes with physical enforcement where logical configuration alone would not hold.

Reference: NCSC Cyber Essentials Requirements for IT Infrastructure v3.2 (April 2025).

SEC 01

Firewalls and boundary protection

  • CE 1

    Boundary firewalls

    The boundary is physical, not a configurable rule. Severed by default.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolate
SEC 02

Secure configuration

  • CE 2

    Secure configuration

    Configurations and golden images sit in tamper-evident offline storage.

    FV-Archive module iconArchiveFV-Validate module iconValidate
SEC 03

User access control

  • CE 3

    User access control

    Reach is named, scoped and time-bound, with revocation at the boundary.

    FV-Lock module iconLockFV-Unlink module iconUnlinkFV-Relay module iconRelay
SEC 04

Malware protection

  • CE 4

    Malware protection

    Removable media and inbound paths are governed Transfer events with validation.

    FV-Transfer module iconTransferFV-Validate module iconValidate
SEC 05

Security update management

  • CE 5

    Security update management

    Updates apply through named, time-bound Relay sessions with multi-party approval.

    FV-Relay module iconRelayFV-Execute module iconExecute

Modules & symbols

FV-Firebreak module iconFirebreakPhysical sever
FV-Isolate module iconIsolateZone boundary
FV-Archive module iconArchiveDisconnected copy
FV-Validate module iconValidateIntegrity check
FV-Lock module iconLockNamed access
FV-Unlink module iconUnlinkRemove trust
FV-Relay module iconRelayTime-bound path
FV-Transfer module iconTransferControlled move
FV-Execute module iconExecuteApproved action
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

Physical Boundary Protection

Physical network boundaries exceed Cyber Essentials boundary firewall requirements, providing demonstrable protection that cannot be misconfigured.

Governed Access Control

Multi-party authorisation provides access control evidence that exceeds baseline requirements and demonstrates active governance.

Continuous Evidence

Automated logging generates continuous compliance evidence, strengthening your position for Cyber Essentials Plus assessment and renewals.

Secure Configuration Support

Physical zone separation ensures secure configuration requirements are maintained regardless of individual system configuration states.

Assessment-Ready Logs

Tamper-proof logs provide complete audit trails ready for Cyber Essentials Plus technical verification.

Clean Recovery Capability

Verified control-plane baselines ensure clean system restoration, supporting malware protection requirements with guaranteed uncompromised recovery.

Demo to Live

Adoption Guide

Step 1

Baseline Assessment

Review your current Cyber Essentials controls and identify where physical enforcement provides the greatest assurance improvement.

Step 2

Physical Boundary Design

Design physical boundary enforcement for your network perimeter and internal zone boundaries aligned to your Cyber Essentials scope.

Step 3

Pre-Assessment Deployment

Deploy Control before your next Cyber Essentials Plus assessment to generate continuous evidence and validate physical boundary effectiveness.

Step 4

Full Boundary Enforcement

Organisation-wide physical boundary enforcement with continuous evidence generation and verified control-plane baseline restoration.

Step 1

Baseline Assessment

Review your current Cyber Essentials controls and identify where physical enforcement provides the greatest assurance improvement.

Step 2

Physical Boundary Design

Design physical boundary enforcement for your network perimeter and internal zone boundaries aligned to your Cyber Essentials scope.

Step 3

Pre-Assessment Deployment

Deploy Control before your next Cyber Essentials Plus assessment to generate continuous evidence and validate physical boundary effectiveness.

Step 4

Full Boundary Enforcement

Organisation-wide physical boundary enforcement with continuous evidence generation and verified control-plane baseline restoration.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy