ethira

Impact analysis

Breach blast radius, down to the datapoint.

A vendor breach maps from the third party through services to the data at stake. The blast radius is a path, not a guess.

Trusted by

Blast radius

Impact is a fact, not an estimate.

Bence Rózsavölgyi

Bence Rózsavölgyi

Engineer

We built impact analysis because “our vendor had a breach” should not start a two-week email thread. Ethira already maps how each third party connects into your environment, so the moment an incident lands, the blast radius is a query, not an investigation.

The path runs from the compromised vendor through the SaaS service it operates, into your internal services, down through databases and datasets, to the individual datapoints at stake. I worked on keeping that path precise: email, IBAN, PII, with sensitivity attached, so the answer is specific enough to act on.

That precision changes the conversation with legal and DPOs. Instead of “we think we might be affected”, you can say exactly which datapoints, which services, and which owners are involved.

Vendor → SaaS

The compromised third party and the SaaS service it operates, linked the moment the incident is known.

Service → store

Internal services that depend on the vendor, and the databases they write into.

Dataset → datapoint

The concrete datasets and fields at stake (email, IBAN, PII) with sensitivity attached.

Response

Hours, not weeks

Zsolt Szávó

Zsolt Szávó

Engineer

I focused on the moment the incident actually arrives. A supply chain event comes in from your vendors or from external intelligence, and impact analysis runs immediately against the current graph. There is no refresh cycle to wait for and no stale inventory to second-guess.

The output is built for the people who have to act: the affected assets and datapoints, the owners who can answer for them, and the evidence trail that shows how we got there. From there, an automation can start the diligence, notification, or reporting steps with the context attached.

We measure this in hours because that is what breach notification windows demand. When the next vendor incident becomes yours, the answer should already be waiting.

Get started

Know the impact before the scramble.

See the blast radius of every third party, before their next incident becomes yours.