Piscium SecurityPISCIUMSECURITY
How it works

How a run works, start to re-attack.

30-minute call · rules of engagement before anything runs · a run takes 2 to 4 weeks · reports at close

Radius runs the same loop an attacker runs (observe, reason, attack, validate, report) inside the rules of engagement you signed. Then, once you fix a path, it attacks that path again.

Five steps. One order.

Every run follows the same five steps, whether the environment is a cloud tenant, a corporate network or a plant floor. Radius does the technical work; Piscium scopes the run, drafts the rules of engagement and stays on the call.

  • Passive first: nothing is written to a controller unless you authorize it
  • The real chain, run inside the rules you signed
  • Three reports at three levels, then a re-attack once you fix it

Observe

Radius discovers and watches the surface: assets, services, identities and dependencies, including what was never in the inventory. It starts passively, so nothing is written to a controller.

  • Assets, services, identities and dependencies, as well as hosts
  • Finds what the inventory missed
  • Passive by default, with active probing only where you authorize it, asset by asset
Walk the discovery step
Attacker-side continuous discovery: sonar sweep surfacing typed network assetsA sonar sweep rotating over concentric depth rings. Each ping surfaces a typed asset (VPN, PLC, database, SCADA controller) labeled as it is discovered. Represents continuous attacker-side discovery across cloud, on-prem, and OT environments.EDGEDMZCOREVPN-04PLC-A12PG-PRODDMZ-WEBSCADA-01IAMλ · etl-22EP · ops-11SWEEP · 8 ASSETS SURFACED

Reason

Radius builds the attack graph and decides what to try first, by where each path leads, not by severity score. It starts from what it already knows about your environment from the last run.

  • Every path traced to what it reaches
  • Chains that share a hop share a fix
  • Findings mapped to MITRE ATT&CK techniques
Walk the attack graph
Prioritization by operational impact: attack path mapping and impact scoringThree assets (a cloud instance, a server, and a PLC) connected by an exploited attack chain climbing toward the critical asset, with a target reticle on the PLC and an animated operational impact score.Cloudaws · prodServerfileshare-02PLCline-4 · OTCROWN JEWEL0IMPACT SCORECHAIN · CLOUD → SERVER → PLCPrioritization by impactExploit chains · Operational risk · Work orchestration

Attack

Radius runs the real chain against your environment, inside the rules of engagement you signed. It does not simulate it. The rules live in the engine: every action is checked against them before it runs.

  • Per-asset rules of engagement, enforced before every action
  • Non-bypassable safety patterns above your own blocklist
  • A stop button that works mid-run
Read the testing safety posture
Demo attack path traveling from an internet-exposed asset through chained steps to a critical assetA multi-hop attack path flowing downward from Internet through Firewall, App Server, Database to Critical Asset. A particle travels the path illustrating how an adversary chains vulnerabilities across network segments.InternetFirewallApp ServerDatabaseCritical Asset

Validate

Radius confirms whether the path worked and how far it got. It stops before the destructive payload. Every action is logged with the decision, the reason and the rules in force at that moment.

  • How far the chain got, hop by hop
  • Stops short of impact
  • Command, timestamp and decision recorded
Walk the validation step
Attack path validation: shield icon verifying security fixes with animated pulse ringsA shield icon with concentric pulse rings validates that attack paths are broken. Two path segments separate and a green check confirms remediation success.Continuous ValidationAutomated re-tests · Evidence capture · Drift alerts

Report

Radius delivers reproducible evidence, the fix and the priority in three reports, each at three levels. Critical findings are communicated the moment they are validated, not at the end. After you fix a path, it attacks the same path again.

  • Executive, technical and compliance reports
  • Each at run, asset and finding level, nine documents in all
  • Re-attack of every fixed path
What a managed run delivers

Nine documents per run

RunAssetFinding
ExecutivePDFPDFPDF
TechnicalPDFPDFPDF
CompliancePDFPDFPDF

What you are left holding

Most testing leaves you with a PDF. A run leaves you with evidence, a trail and memory.

Executive

Executive report

What was exposed, what it would cost an attacker, and what changed after remediation. Written to be read by people who do not run the tooling.

For the board and the exec team

Technical

Technical report

The validated attack paths themselves: reachability, the chain at each hop, and the evidence captured when a path was proven exploitable.

For your security engineers

Compliance

Compliance report

The same run expressed as control evidence: what was tested, when, under whose authorization, and what the outcome was.

For your auditor and your supervisor

Trail

Safety audit trail

Every action an agent attempted, the decision taken on it, the reason, and a snapshot of the rules of engagement in force at that moment.

For anyone who asks what we did to your environment

Memory

Knowledge base

Configuration as found, how things connect, what was found before, what was fixed and what reopened. The next run starts from here, not from zero.

For the next run, and the board decision it feeds

Each report exists at three levels (the whole run, a single asset, a single finding), so the person who needs one line does not have to read the document written for someone else.

Where it plugs in

Radius connects to the environment you authorize, runs the loop, and delivers findings into your SIEM and ticketing flow with the validated chain behind each one. You supply the AI model key, or we do.

Platform architecture diagram showing connectors feeding into the Radius engine and out to integrationsArchitecture diagram: connectors (Cloud, On-Prem, OT/ICS) at the top feed data into the central Radius engine (Observe, Reason, Attack, Validate, Report), which outputs to SIEM, ITSM, and Dashboard at the bottom.CloudOn-PremOT / ICSRADIUS ENGINEObserveReasonAttackValidateReportSIEMITSMDashboard

Ready to see it against your environment?

A 30-minute call, a scoped proposal with a draft of the rules of engagement and a fixed price. The run starts only after you sign.

Frequently Asked Questions

How long does a run take?
A run takes two to four weeks depending on asset count and whether OT zones are in scope. Critical findings are communicated the moment they are validated, not at the end.
Do you run destructive tests?
Radius runs the real chain but stops before the destructive payload. Non-bypassable safety patterns sit above your own blocklist and the per-asset rules of engagement, and every decision is logged with the rules in force at that moment.
Which environments does it run on?
IT, cloud and OT/ICS environments alike, across every cloud provider and your SaaS applications. The safety controls were built for hardware you cannot reboot, so they hold anywhere.
What happens after I fix something?
Radius attacks the same path again and reports whether it is closed. Re-validation is part of the run, not a second purchase.

Related Resources

Guide
What Is Continuous Threat Exposure Management (CTEM)?

A practical introduction to CTEM, Gartner's framework for continuously validating and reducing cyber risk in critical infrastructure.

Read More
Demo
Live Demo: Piscium Radius Walkthrough

See Radius in action on the demo environment: discovery, the attack graph, the safety trail and the three reports.

Read More