Blast Radius (Cloud Security)
In cloud security, blast radius refers to the maximum reach of impact stemming from the compromise of a single resource — typically a workload, identity, or credential.
Calculating blast radius requires mapping the compromised entity's permissions, network reachability, role-assumption paths, accessible data, and downstream service trust relationships into one scope-of-impact view. Blast radius is essential to two workflows: prioritization (the worse the radius, the higher the urgency of fixing the underlying exposure) and incident response, where blast-radius analysis tells responders exactly what assets must be checked, contained, and rotated — turning hours of manual scoping into a single screen and reducing mean time to scope by up to 70% in modern cloud security platforms.
Learn more: Minimize the Vulnerability Blast Radius in the Cloud