Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
MITRE ATT&CK

Physical Countermeasures for ATT&CK Techniques

MITRE ATT&CK catalogues the techniques adversaries use. Control eliminates entire categories of those techniques by removing the network reachability they depend on. No path means no technique.

Back to Control
Control by Firevault product icon

MITRE ATT&CK

You cannot detect what you have prevented. Physical path removal eliminates entire categories of ATT&CK techniques before they can be attempted.

47

ATT&CK techniques mitigated through path removal

100%

Lateral movement prevention between zones

12

ATT&CK tactics addressed by Control modules

Full

Technique-to-module mapping documentation

The Detection Gap

Detection alone cannot stop sophisticated adversaries.

Technique Volume

ATT&CK catalogues hundreds of techniques. Organisations cannot maintain effective detection rules for every technique across every system.

Lateral Movement

Once inside a network, adversaries move laterally using legitimate tools and protocols that evade detection systems designed to spot malware.

Living Off the Land

Sophisticated attackers use built-in operating system tools and legitimate credentials, making their activity indistinguishable from normal operations.

The Scenario

Scenario: Living-Off-the-Land Attack Defeated by Path Removal

An advanced threat actor compromises a corporate workstation and uses built-in Windows tools, PowerShell, WMI, and RDP, to move laterally towards the SCADA network. Every tool they use is legitimate. Every credential they use is valid. No malware is deployed. Detection systems see only normal administrative activity. After three weeks, they reach the boundary of the OT network. With Control, the OT network is physically disconnected from corporate IT. The attacker's living-off-the-land techniques are irrelevant because the network path to the target does not exist. No detection was needed. The path was simply not there.

"Our threat hunting team spent six months tuning detection rules for lateral movement techniques. When we ran a red team exercise, they bypassed every rule using built-in Windows tools. We realised we were playing a game we could not win."

MITRE ATT&CK mapping

Where ATT&CK tactics meet Control modules.

ATT&CK describes how adversaries actually behave. Control removes the reachability and standing trust most of those behaviours depend on, so the tactic has nowhere to land.

Reference: MITRE ATT&CK Enterprise v15 tactics TA0001 to TA0040 and ATT&CK for ICS tactics where relevant.

SEC 01

Get in and stay in

  • TA0001

    Initial Access

    Remove the standing inbound reach the attacker assumes is there.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolate
  • TA0003

    Persistence

    Privileged reach is a named session, not a standing right.

    FV-Lock module iconLockFV-Unlink module iconUnlink
  • TA0004

    Privilege Escalation

    Boundary-altering actions require explicit, quorum approval.

    FV-Execute module iconExecuteFV-Validate module iconValidate
SEC 02

Move and learn

  • TA0007

    Discovery

    Reachable surface is scoped to the named session. Casual discovery has nothing to enumerate.

    FV-Isolate module iconIsolateFV-Lock module iconLock
  • TA0008

    Lateral Movement

    Inter-zone paths exist only when authorised, and only for the window required.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolateFV-Relay module iconRelay
SEC 03

Take or destroy

  • TA0009

    Collection

    Sensitive stores require an approved Lock event to be reachable.

    FV-Lock module iconLockFV-Isolate module iconIsolate
  • TA0010

    Exfiltration

    Outbound paths to unmanaged destinations are physically severed.

    FV-Firebreak module iconFirebreakFV-Unlink module iconUnlink
  • TA0040

    Impact

    Recovery copies live in an offline vault. The blast stops at the last severed conduit.

    FV-Archive module iconArchiveFV-Firebreak module iconFirebreakFV-Validate module iconValidate
SEC 04

ATT&CK for ICS

  • TA0108

    Initial Access (ICS)

    The IT-to-OT conduit is severed by default; vendor reach is time-bound.

    FV-Firebreak module iconFirebreakFV-Relay module iconRelay
  • TA0107

    Inhibit Response Function

    Safety-related changes are gated by Execute and confirmed by Validate.

    FV-Execute module iconExecuteFV-Validate module iconValidateFV-Lock module iconLock

Modules & symbols

FV-Firebreak module iconFirebreakPhysical sever
FV-Isolate module iconIsolateZone boundary
FV-Lock module iconLockNamed access
FV-Unlink module iconUnlinkRemove trust
FV-Execute module iconExecuteApproved action
FV-Validate module iconValidateIntegrity check
FV-Relay module iconRelayTime-bound path
FV-Archive module iconArchiveDisconnected copy
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

Technique Elimination

Rather than detecting techniques after execution, Control eliminates entire technique categories by removing the network paths they require.

Lateral Movement Prevention

Physical zone separation prevents all lateral movement techniques between zones, regardless of the tools or credentials used.

Living-Off-the-Land Immunity

Built-in tools and legitimate credentials cannot be used to cross physical zone boundaries, eliminating the primary advantage of sophisticated attackers.

Persistence Prevention

Time-limited access windows prevent persistent access techniques by physically deactivating paths between authorised sessions.

Technique Mapping Reports

Automated reports map Control module deployments to specific ATT&CK technique mitigations for risk assessment and audit.

Impact Technique Immunity

Verified control-plane baselines are immune to ransomware, data destruction, and recovery inhibition techniques that only affect network-connected systems.

Demo to Live

Adoption Guide

Step 1

Technique Exposure Assessment

Map your critical assets against ATT&CK techniques that rely on network reachability to identify where physical prevention provides the greatest risk reduction.

Step 2

Prevention Architecture Design

Design physical zone boundaries that eliminate the highest-risk technique categories while maintaining operational functionality.

Step 3

Red Team Validation

Deploy Control in a test environment and run a red team exercise to validate that physical boundaries defeat the techniques your detection cannot reliably catch.

Step 4

Production Deployment

Full deployment with automated technique mapping, continuous prevention evidence, and verified control-plane baseline restoration for impact technique immunity.

Step 1

Technique Exposure Assessment

Map your critical assets against ATT&CK techniques that rely on network reachability to identify where physical prevention provides the greatest risk reduction.

Step 2

Prevention Architecture Design

Design physical zone boundaries that eliminate the highest-risk technique categories while maintaining operational functionality.

Step 3

Red Team Validation

Deploy Control in a test environment and run a red team exercise to validate that physical boundaries defeat the techniques your detection cannot reliably catch.

Step 4

Production Deployment

Full deployment with automated technique mapping, continuous prevention evidence, and verified control-plane baseline restoration for impact technique immunity.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy