The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Self-Score
Architecture Read
Five Free Policies
Deploy and Expand
All containment isn’t created equal.
Five properties separate a contained security incident from a catastrophic breach. Four harvest questions show whether your data is already leaving. Answer a few questions and see where your security stack has containment gaps — then download a report to share with your team, or continue to Phase 2 to measure the gaps from your own architecture.
Start Your AssessmentFive minutes. Three things you can act on.
No sales call, no gated form, no vendor pitch. Answer a few questions and see where your security stack has gaps that matter.
Containment gaps
Five properties that separate a small, contained security ncident from a catastrophic breach. Each one maps to a real-world failure.
Harvest exposure
Four questions that reveal whether encrypted traffic is leaving unmonitored and who really controls the keys.
Provisional blast radius
The percentage of the estate an attacker can reach when containment properties are missing. Sized to your actual infrastructure.
“The AI threat landscape changed our timeline. We looked at our cloud environment and realized web application firewalls were the only thing standing between our workloads and the internet. That was not enough. We needed network-layer containment, and we needed it now — not on a future roadmap.”
No containment means harvest risk.
Containment and harvest are two sides of the same exposure. A gap in one compounds the other: if outbound traffic is unrestricted, encryption alone is not enough. If data is already leaving, containment is already too late. This assessment scores both so you see the full picture.
Your security stack was designed for a network that no longer exists.
Application modernization moved workloads into containers, serverless functions, and managed services. The network security controls protecting them still assume a world of fixed perimeters and predictable traffic flows.
Two doors open, one locked
Every cloud workload is born with two doors open, outbound to the internet and sideways to its neighbors, and only the front door locked.
What breaks
Segmentation contains lateral movement.
Workloads communicate across segments by design. Lateral movement follows the application graph, not the network topology.
Firewalls govern egress.
Cloud-native traffic leaves through NAT gateways, service endpoints, and API calls that never touch a firewall rule.
Identity stops unauthorized access.
Most network security controls enforce at Layer 3/4. The identity of the workload — what it is, not just where it is — is invisible at the enforcement point.
Five containment properties test whether your security stack holds under these conditions. Four harvest questions test whether data is already leaving through the gaps. Most stacks fail on properties they were never designed to enforce.
Already know you have gaps? Phase 2: the Architecture Read measures reachability and containment time from your own data — the two variables that decide the improvement case, independent of how you price the assets.
What do you want to measure first?
Both tracks reach the same destination: Phase 2 measures the exposure from your own architecture and sizes it in dollars. The order determines which gap you see first.