RiverClear: what an organization looks like inside Radius
RiverClear is a demo environment, not a customer. It models a multi-plant industrial operator whose IT, cloud and OT segments share more than they should: legacy controllers on flat segments next to corporate systems, a historian that talks to both sides, remote access that was never meant to be permanent. It exists so we can show the attack graph, the safety trail and the three reports without exposing a real organization. Its numbers are not results.
What RiverClear is
RiverClear is a demo environment, not a customer. It models a multi-plant industrial operator whose IT, cloud and OT segments share more than they should: legacy controllers on flat segments next to corporate systems, a historian that talks to both sides, remote access that was never meant to be permanent. It exists so we can show the attack graph, the safety trail and the three reports without exposing a real organization. Its numbers are not results.
What this page walks through
This page walks the screens a run produces on RiverClear, in the order a run produces them: what Radius observed, the attack graph it reasoned over, the chain it attacked and how far it got, the safety trail behind every action, and the three reports at three levels that come out the other end. Everything shown is demo data. The method is the real attack.
About this walkthrough: RiverClear is a demo environment. It is not a customer, nothing on this page is a measured outcome, and no figure from it appears anywhere on this site. It shows what an organization looks like inside Radius.
1. Observe: the surface as found
A run starts passively. Radius watches the RiverClear surface (assets, services, identities, dependencies) and writes nothing to a controller. The first screen is the inventory Radius built, including what the operator’s own inventory missed: the historian’s second interface, a remote-access appliance nobody owns, and a service account that both the corporate directory and the plant network trust.
2. Reason: the attack graph
From the inventory Radius builds the attack graph and decides what to try first, by where each path leads. On RiverClear the paths that matter end at the reservoir SCADA controller and the production warehouse. The graph orders them by consequence, not by the severity score of the first hop. Chains that share a hop (here, the trusted service account) are grouped, because they share a fix.
3. Attack: inside the rules that were signed
Radius runs the real chain against RiverClear: the remote-access appliance, the identity bridge, the stale service account, the engineering workstation. Every action is checked against the rules of engagement before it runs. The field controllers are marked passive-only in those rules, so the chain stops at the workstation that can reach them. That is the point that proves the path, before the payload that would affect the process.
4. Validate: how far it got
The findings screen shows each hop with the command, the timestamp and what came back. That is the evidence: not that a path is theoretically exploitable, but that this chain reached this host at this time, and stopped where the rules said it must.
The safety trail behind it
Alongside the findings sits the safety audit trail: every action an agent attempted, the decision taken on it, the reason, and a snapshot of the rules of engagement in force at that moment. On RiverClear the trail shows the attempts the interceptor refused at the controller boundary as clearly as the ones it allowed. An operations manager can read it and see what was done to the plant, action by action.
5. Report: three reports, three levels
The run ends with three reports (executive, technical, compliance), each at three levels: the whole run, a single asset, a single finding. On RiverClear the executive report says what was reachable and what a fix changes. The technical report carries the chain hop by hop. The compliance report expresses the run as control evidence: what was tested, when, under whose authorization, with what outcome.
After the fix
The fix on RiverClear is the chokepoint the graph pointed at: revoke the service account’s trust on the plant side and segment the workstation. Once it lands, Radius attacks the same path again. The ticket carries the chain that produced it and closes only when the re-attack fails.
Customer results will be published when a customer agrees to be named.
Related Resources
Now on your environment.
A scoped run: a 30-minute call, a draft of the rules of engagement, a fixed price, and the same screens on your paths.