Recent Breaches
Breaches
View All →
Utilities - Gas

Physical isolation for gas SCADA, AGI control and safety systems

Gas operators run a high-consequence SCADA estate across compressor stations, above ground installations and pressure reduction stations. Firevault Control puts a real boundary between the office, the SCADA control room, the AGI telemetry and the safety systems behind them.

Back to Utilities
Control

Utilities - Gas

When SCADA, AGI control and safety systems share the same network, every software vulnerability becomes a candidate for a pressure or supply incident.

100%

Safety system isolation from control fabric

Zero

Persistent remote access to AGI and PRS controllers

7

Control modules deployed per gas zone

Full

Evidence for NIS2, COMAH and Ofgem

The Challenge

Gas control networks combine high-consequence operations with broad reach.

High-consequence pressure control

Compressor and pressure reduction kit governs the safe envelope of the network. Unauthorised setpoint changes carry safety and supply consequences.

Distributed AGI estate

Above ground installations and PRS sit across the network and depend on remote telemetry to be operated safely.

Shipper and market interfaces

Shipper nominations and market interfaces sit close to the operational estate, creating paths that attackers can traverse.

The Scenario

Scenario: AGI controller firmware compromise

Attackers compromise a vendor firmware distribution server and push a malicious update into an AGI controller during a routine maintenance window. The update propagates through a shared engineering network to several neighbouring sites before it is detected. Operators lose confidence in the integrity of pressure readings for hours. With Firevault Control, vendor firmware crosses into operations only through a brokered path with origin and integrity checks. Updates that reach an AGI controller require named, multi-party approval per site. The safety integrity system sits on its own fabric and cannot be reached from the control network at all. Verified baselines for AGI configuration are held on infrastructure that has no live network path to production and require multi-party authorisation to release.

"If the safety system and the control system share a network, you do not have a safety system. You have a wish."

Module deployment · gas transmission and distribution network

Where each Control module is deployed across compressors, AGIs and the distribution grid.

Gas operators run a high-consequence SCADA estate across compressor stations, above ground installations and pressure reduction stations. Control puts a real boundary between the office, the SCADA control room, the AGI telemetry and the safety systems that keep pressure in band.

Grounded in NIST SP 800-82 Rev. 3, IEC 62443-3-2, HSE COMAH guidance and Ofgem security expectations.

L5

Cloud / Internet

External

Shipper portals
Cloud services
FirebreakValidate

Shipper and cloud traffic terminates at the perimeter.

L4

Enterprise

IT

SOC
SIEM
Identity
Nominations

Office, shipper nominations and corporate systems.

Office, shipper nominations and corporate systems.

IsolateFirebreak

Office cannot reach the DMZ on its own.

L3.5

Industrial DMZ

DMZ · trust boundary

Jump server
Patch & AV
Telemetry broker

Brokered exchange. No straight-through paths into operations.

Brokered exchange. No straight-through paths into operations.

RelayValidateExecute

Engineering and flow data crosses on scheduled, approved routes.

L3

Operations systems

OT

Historian
Engineering workstation
Flow computation
Isolate

Engineering and SCADA on separate fabrics.

L2

Supervisory control

OT

Gas SCADA
HMI
Leak detection

Control room view of transmission and distribution.

Control room view of transmission and distribution.

ExecuteLock

Pressure and valve actions need named, authorised approval.

L1

Basic control

Field

AGI PLCs
PRS controllers
Compressor DCS

Above ground installations, pressure reduction, compressors.

Above ground installations, pressure reduction, compressors.

Isolate

Safety integrity sits on its own fabric. It is never the same network as control.

SIS

Safety systems

Field

Safety PLC
ESD

Safety integrity. Last line.

Safety integrity. Last line.

L0

Physical

Field

Valves
Pressure sensors
Methane detectors
OSS

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

AGI configurations, compressor and PRS baselines, safety system records and the recovery sets you need after an incident.

Offline by design · secure by default

Modules & symbols

FirebreakPhysical sever
ValidateIntegrity check
IsolateZone boundary
RelayTime-bound path
ExecuteApproved action
LockNamed access
DMZ boundaryTrust transition
OSS calloutOff-network detail

Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

  1. Isolate

    At every Purdue boundary and around the SIS

    Office, SCADA, AGI control and safety systems all sit on separate physical fabrics. Safety integrity is never on the same network as control.

  2. Firebreak

    On the L5 to L4 link and the L4 to L3.5 link

    Real off switches on the public and office boundaries during a live incident.

  3. Validate

    On the L5 to L4 link and inside the L3.5 DMZ

    Shipper, engineering and flow traffic is checked for origin and integrity before it crosses into operations.

  4. Relay

    Inside the L3.5 DMZ

    Cross-domain data moves on scheduled routes only.

  5. Execute

    Inside the L3.5 DMZ and on the L2 to L1 link

    Firmware, pressure setpoints and valve actions hold until the right authority signs them off.

  6. Lock

    On the L2 to L1 link and the L1 to L0 link

    Access to AGIs, PRS and compressors ties to named engineers. Standing access is the exception.

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Sovereign gas data

Operational and shipper data remains within the agreed jurisdiction in carefully selected Firevault Bunkers.

Multi-party control

Pressure and major valve operations require sign-off from both control room and security teams.

Regulatory evidence

Continuous compliance evidence aligned to NIS2, HSE COMAH and Ofgem cyber expectations.

Out-of-band management

Cellular and dedicated paths keep the control plane reachable when primary networks are compromised.

Tamper-proof logging

Every access, configuration change and pressure action lands in immutable logs on physically separate infrastructure.

Verified configuration baselines

Verified baselines of AGI, PRS and compressor configuration enable a known-good restore of control-plane state.

Demo to Live

Adoption Guide

Step 1

Network assessment

Map every path between corporate IT, SCADA, AGI control and the safety integrity systems to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your transmission and distribution estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring an AGI and SIS pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the gas estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Step 1

Network assessment

Map every path between corporate IT, SCADA, AGI control and the safety integrity systems to identify convergence and persistent vendor connections.

Step 2

Zone architecture design

Design physically separated zones aligned to your transmission and distribution estate, with Control modules at each boundary.

Step 3

Non-production pilot

Deploy in a test environment mirroring an AGI and SIS pair with full zone separation, multi-party authorisation and compliance logging.

Step 4

Operational deployment

Full deployment across the gas estate with verified configuration baselines, continuous compliance evidence and 24/7 out-of-band management.

Questions

Frequently Asked

Gas blueprint - PoC

Speak to the team to organise a PoC

Walk through your blueprint with the Firevault team and scope a proof of concept on your estate. 30 minutes, no sales pitch.

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®