Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
NIST CSF

Physical Enforcement Across All Five CSF Functions

The NIST Cybersecurity Framework organises security into five functions: Identify, Protect, Detect, Respond, and Recover. Control provides physical enforcement capabilities that strengthen every function.

Back to Control
Control by Firevault product icon

NIST CSF

The NIST CSF is a framework for organising security capabilities. Physical enforcement is what makes those capabilities genuinely effective against determined adversaries.

5/5

CSF functions with physical enforcement

23

CSF categories addressed by Control

100%

Physical protection for critical assets

Full

Automated CSF maturity evidence

The Maturity Challenge

Advancing CSF maturity requires stronger controls.

Protect Function Gaps

Most organisations achieve basic Protect function maturity but struggle to demonstrate that protective controls are continuously effective against sophisticated threats.

Respond Function Speed

Incident response depends on the ability to contain threats quickly. Software-based containment takes time and may be undermined by the same compromise it is trying to contain.

Recover Function Assurance

Recovery capabilities are only as good as the integrity of backup systems. Network-connected backups can be compromised alongside production systems.

The Scenario

Scenario: CSF Maturity Assessment with Physical Controls

An organisation assesses its CSF maturity and finds it is at Tier 2 (Risk Informed) across most functions. The Protect function relies on firewalls and access controls that have been bypassed in penetration tests. The Respond function takes hours to contain incidents because containment requires coordinated firewall changes. The Recover function uses network-connected backups that would be compromised in a real ransomware attack. With Control, the organisation advances to Tier 4 (Adaptive) for Protect, Respond, and Recover functions. Physical zone boundaries cannot be bypassed. Incident containment operates in seconds through physical path severance. Control-plane recovery is guaranteed through verified configuration baselines.

"We were stuck at Tier 2 maturity for three years. Every improvement we made was incremental. Physical enforcement moved us to Tier 4 for our most critical functions because it fundamentally changed the assurance model."

NIST CSF mapping

Where NIST CSF functions meet Control modules.

NIST CSF 2.0 organises cybersecurity outcomes into six functions. Control delivers the physical enforcement and recovery posture the Protect and Recover functions depend on.

Reference: NIST Cybersecurity Framework 2.0, functions Govern, Identify, Protect, Detect, Respond, Recover.

SEC 01

Govern and Identify

  • GV.OC-3

    Legal, regulatory and contractual requirements

    Continuous signed evidence demonstrates the boundary holds.

    FV-Validate module iconValidateFV-Archive module iconArchive
  • ID.AM-3

    Communication and data flows mapped

    Zone and conduit inventory is enforced as physical fact.

    FV-Isolate module iconIsolateFV-Firebreak module iconFirebreak
SEC 02

Protect

  • PR.AA-3

    Identities and credentials

    Privileged reach is named, scoped and time-bound.

    FV-Lock module iconLockFV-Relay module iconRelay
  • PR.AA-5

    Access permissions and authorisations

    Boundary-altering actions require explicit approval.

    FV-Execute module iconExecute
  • PR.IR-1

    Network communications integrity

    Inter-zone paths exist only when authorised. Default is severed.

    FV-Firebreak module iconFirebreakFV-Isolate module iconIsolate
  • PR.PS-6

    Data backups created and protected

    Recovery copies live in an offline vault, off the live network.

    FV-Archive module iconArchiveFV-Transfer module iconTransfer
SEC 03

Detect

  • DE.CM-1

    Network monitored

    Continuous attestation of conduit and vault state surfaces drift before incident.

    FV-Validate module iconValidate
SEC 04

Respond and Recover

  • RS.MI-1

    Incidents contained

    Firebreak severs governed conduits on alert. The blast radius is bounded.

    FV-Firebreak module iconFirebreak
  • RC.RP-3

    Recovery actions integrity verified

    Restoration is an evidenced Execute event with quorum approval.

    FV-Execute module iconExecuteFV-Validate module iconValidate

Modules & symbols

FV-Validate module iconValidateIntegrity check
FV-Archive module iconArchiveDisconnected copy
FV-Isolate module iconIsolateZone boundary
FV-Firebreak module iconFirebreakPhysical sever
FV-Lock module iconLockNamed access
FV-Relay module iconRelayTime-bound path
FV-Execute module iconExecuteApproved action
FV-Transfer module iconTransferControlled move
Direct mapModule satisfies clause

Featured In

TechRadar Pro logoSecurity Buyer logoYahoo Finance logoSecurityBrief logoChannel Insider logo

Key Capabilities

Identify: Asset Boundary Mapping

Control modules define and enforce physical boundaries around critical assets, providing clear asset identification and boundary documentation.

Protect: Physical Access Control

Physical zone separation and multi-party authorisation provide protective controls that cannot be circumvented through software techniques.

Detect: Boundary State Monitoring

Continuous monitoring of physical boundary states provides detection capabilities for any unauthorised path activation.

Respond: Seconds-Fast Containment

Physical path severance provides incident containment in seconds, dramatically reducing the window of exposure during active threats.

Recover: Verified Safe-State Restoration

Verified baselines of control-plane configuration enable restoration regardless of the scope of network compromise.

Maturity Evidence

Continuous logging and automated CSF mapping documentation supports maturity assessments and demonstrates advancement over time.

Demo to Live

Adoption Guide

Step 1

CSF Maturity Assessment

Assess your current CSF maturity tier across all functions and identify where physical enforcement would provide the greatest maturity advancement.

Step 2

Target Profile Alignment

Map your Target Profile to Control modules to design a deployment that advances maturity for your priority CSF categories.

Step 3

Function Validation

Deploy Control for your highest-priority function and validate maturity advancement through a controlled assessment.

Step 4

Full CSF Deployment

Organisation-wide deployment with physical enforcement across all functions, continuous maturity evidence, and automated CSF reporting.

Step 1

CSF Maturity Assessment

Assess your current CSF maturity tier across all functions and identify where physical enforcement would provide the greatest maturity advancement.

Step 2

Target Profile Alignment

Map your Target Profile to Control modules to design a deployment that advances maturity for your priority CSF categories.

Step 3

Function Validation

Deploy Control for your highest-priority function and validate maturity advancement through a controlled assessment.

Step 4

Full CSF Deployment

Organisation-wide deployment with physical enforcement across all functions, continuous maturity evidence, and automated CSF reporting.

Questions

Frequently Asked

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy