Onam Security
Illustrative scenarios

The attack path, priced — by sector.

Five industry archetypes showing the same story in each: the route to a crown jewel, the single choke point that cuts it, and the board-ready dollar figure.

These are illustrative archetypes, not customers. The paths and figures show how the platform reasons about sector-specific risk — they are not reported outcomes from named engagements.

A leading financial-services firm

AWS + Azure · trading apps, PII, payment data · PCI-DSS & SOX

Illustrative
The attack path Onam surfaces
Public LB
App role
Choke point
RDS (PII)
The challenge

Audit season means assembling evidence from many tools, and the board asks one question the stack can't answer: how exposed are we, in dollars?

What Onam brings

The public-LB → app-role → RDS (PII) path surfaces and is priced with FAIR/ALE; posture auto-maps to PCI-DSS controls on the same graph.

The advantage

A defensible dollar figure for the cardholder-data path plus the single fix that cuts it most — and audit evidence from one source.

The differentiator

The path is priced in dollars, so the CISO walks into the board meeting with a number rather than a spreadsheet of criticals.

A high-growth e-commerce platform

GCP + AWS · customer PII & payments · must not go down at peak

Illustrative
The attack path Onam surfaces
Internet fn
Choke point
IMDS
IAM role
S3 (PII)
The challenge

Security can't be the team that slows releases — but a breach at peak season is existential, and no tool shows what an attacker could actually reach.

What Onam brings

A four-hop path (internet function → IMDS → IAM → S3 PII) surfaces, is verified and priced; the function is the choke point.

The advantage

Fix one node and the largest cluster of reachable paths is gone. Read-only connect means zero drag on the release pipeline.

The differentiator

Priced paths within minutes of connecting, and peak-season exposure as a number you can track release over release.

A global gaming company

Multi-cloud live services · millions of players · CI/CD to prod daily

Illustrative
The attack path Onam surfaces
CI token
Choke point
Prod deploy
Player DB
The challenge

A compromised deploy is a breach and an outage at once; player data and uptime are the crown jewels, and the CI/CD path is invisible to point tools.

What Onam brings

A long-lived CI token → prod-deploy → player-DB path surfaces and is ranked by combined breach and downtime exposure; the token is the choke point.

The advantage

Rotate or scope one CI token and the riskiest deploy paths close — exposure tracked release over release.

The differentiator

Player-data and downtime exposure are priced on one graph, giving a live-ops board a single number instead of two disconnected risk stories.

A leading SAP managed-service provider

Multi-tenant SAP across AWS + Azure · dozens of enterprise customers

Illustrative
The attack path Onam surfaces
Internet
Jump host
Operator role
Choke point
Customer SAP
The challenge

Cross-tenant risk is correlated by hand across six consoles. One blind spot in a shared component can breach many customers at once.

What Onam brings

One graph across every tenant. A shared operator role surfaces as the choke point for the most cross-tenant paths — verified across five domains and MITRE-mapped.

The advantage

Scope that one operator role and the largest block of cross-tenant paths collapses together — measured, not guessed.

The differentiator

The cross-tenant route is priced in dollars on one graph — the assurance number an MSP's own customers ask for.

A leading beauty / CPG brand

M365 + SaaS (Okta, GitHub) + cloud · loyalty data · brand trust is the asset

Illustrative
The attack path Onam surfaces
Okta identity
Choke point
Cloud access
Loyalty DB
The challenge

Identity and data live in SaaS as much as in cloud, but the two are secured in separate tools — so the SaaS-to-cloud path to loyalty data is a blind spot.

What Onam brings

SSPM puts the SaaS identity on the same graph as cloud; a federated Okta identity → cloud → loyalty-DB path surfaces as the choke point.

The advantage

Tighten one federated identity and the SaaS-to-cloud brand-risk paths drop — visible only because SaaS and cloud share one graph.

The differentiator

SaaS (SSPM) and cloud sit on one priced graph, so brand-risk exposure is expressed in dollars rather than split across two tools.

Your sector. Your path. Your number.

These are archetypes. The real version takes minutes — connect one account read-only and Onam surfaces your actual attack paths, choke points and priced exposure.