Simulated containment actions only. No production systems are modified.
INC-2041
Finance endpoint compromise
Switch scenario · resets workflow
Critical
Step 4 · Exposure

Blast Radius Map

A dependency view of how the threat could propagate from the compromised identity through endpoints, shared infrastructure and the business services that ride on top of them.

Blast radius
100
composite score
Nodes mapped
8
8 relationships
Suspected paths
2
unconfirmed lateral movement
Critical services
2
high/critical exposure

Propagation graph

CriticalHighMediumLowSuspected
Rendering propagation graph…

Drag nodes to explore. Dashed amber edges are suspected, unconfirmed paths; solid edges are observed relationships. Mock data only.

Why the radius scores 100

The score weights the criticality of every implicated identity, asset and business service, then adds graph connectivity — the more confirmed and suspected relationships, the further a threat can travel before containment closes the path.

This incident concentrates 3 implicated identities and 5 assets over 2 high/critical business services, with 2 suspected lateral paths still unconfirmed. That concentration of privilege over time-critical services — racing the payroll run — is what drives the radius up.

Exposure set

Identities
3
Assets
5
Business services
3
High/critical services
2
Evidence to preserve
4