Onam Security
Illustrative scenarios — not customer results

Five worked scenarios

What an attack path looks like in five different estates — the chain, the choke point, and the question the security team is actually being asked. Each one is a worked example against an industry archetype.

Read this before you quote anything on this page

Onam has no public reference customers. Every scenario below is an illustration built against an industry archetype — not a real or named customer, and not an outcome we have delivered. The paths and figures show how the method works, not what it achieved for someone. When we have a named customer and real results, we will publish those instead and say so plainly.

Illustrative

A leading financial-services firm

AWS + Azure · trading apps, PII, payment data · PCI-DSS & SOX

The path
Public LB → app role → RDS (PII)

Audit season means assembling evidence from many tools, and the board asks the one question the stack cannot answer: how exposed are we, in dollars?

Illustrative

A high-growth e-commerce platform

Multi-cloud · checkout, customer data, seasonal scale

The path
Exposed service → over-privileged role → customer data store

Peak season doubles the footprint in a week. Which of the new findings actually reach checkout data?

Illustrative

A global gaming studio

Kubernetes-heavy · player data, live services

The path
Cluster workload → service account → player data

Hundreds of namespaces and constant deploys. Which RBAC grant is the one that matters this week?

Illustrative

A beauty and CPG brand

SaaS-heavy · marketing stack, consumer PII

The path
SaaS grant → shared identity → consumer data

Most of the estate is SaaS the security team never provisioned. Where does consumer data actually sit?

Illustrative

An SAP managed-service provider

Multi-tenant · regulated workloads, customer estates

The path
Management plane → tenant boundary → customer workload

Every tenant is someone else's audit. How do you prove isolation holds across all of them at once?

We would rather have your estate than an archetype

These scenarios exist because we have not earned real ones yet. If you run cloud infrastructure and want to know whether the paths we surface are real, run a read-only scan against a single account and tell us what you find — including if the answer is that it is noise. That is more useful to us than a signature.