What an attacker can reach
An asset list says what exists. Radius maps what an attacker can actually reach from where they already are, so a critical CVE on an unreachable host stops competing for your week.
Piscium Radius attacks your environment the way an adversary would, inside rules you sign, and proves which paths reach the systems you cannot afford to lose. It runs on IT, cloud and OT/ICS environments alike, and re-attacks every path after you fix it.
Demo data · Attack path validation
3 chains → 1 fix
This is what continuous threat exposure management (CTEM) means in practice: a path you can follow hop by hop, and a fix you can watch collapse it. The chains below are demo data from the RiverClear environment.
Most tools hand you a ranked list of findings. Radius hands you the handful of changes that break the most paths to your critical assets, and proves each one worked.
An asset list says what exists. Radius maps what an attacker can actually reach from where they already are, so a critical CVE on an unreachable host stops competing for your week.
Nothing reaches your queue on a CVSS number. Radius runs the chain against your real environment first, and every finding arrives with the path that produced it, the command and the timestamp.
Chains that share a hop share a fix. Radius ranks the few changes that collapse the most paths, then re-attacks each one the moment it lands.
Every run leaves knowledge. Radius does not begin from zero: it knows how your environment is configured today, what it found before, what was fixed and what reopened. That memory is what a board decision is built on.
Radius runs the same loop an attacker runs, and does not stop at the report. After you fix a path, it attacks that path again.
Discovers and watches the surface: assets, services, identities and dependencies, including what was never in the inventory. It starts passively, so nothing is written to a controller.
Builds the attack graph and decides what to try first, by where each path leads, not by severity score.
Runs the real chain against your environment, inside the rules of engagement you signed. It does not simulate it.
Confirms whether the path worked and how far it got. Stops before the destructive payload. Every action logged.
Delivers reproducible evidence, the fix and the priority in three reports, each at three levels. After you fix it, attacks the same path again.
Industrial hardware cannot be rebooted to see what happens. Radius observes passively first, so no packet reaches a controller unless you authorize it, asset by asset, and when it attacks it stops at the point before impact.


RiverClear is a demo environment: a modeled multi-plant operator with IT, cloud and OT segments that share more than they should. It is how we show the attack graph, the safety trail and the three reports without exposing a customer. It is not a customer and its numbers are not results.
Walk through RiverClear →A scoped run against the environment you authorize: fixed scope, fixed price, re-validation included, credited toward continuous coverage if you keep going. It starts with a 30-minute call, and nothing is touched before the rules are signed.