Articles

Why we're building vec0

Why vec0 models attacker progression through identities, permissions, and systems as paths toward sensitive data.

Security teams today are flooded with signals.

Alerts about suspicious logins.
Alerts about configuration drift.
Alerts about anomalous activity.
Alerts about vulnerabilities.

But breaches do not happen as alerts.

Breaches happen as trajectories.

An attacker starts somewhere in the environment, often with a legitimate identity. From there they move step by step through identities, permissions, and systems until they reach something valuable: sensitive data.

Each step may look normal in isolation. Logging in with valid credentials is normal. Assuming a role is normal. Querying a database is normal.

The problem is not the individual actions.

The problem is the sequence.

For a plain-English guide to that sequence, see How data breaches happen in cloud environments.

Breaches are multi-step systems problems

Look at almost any major breach and the pattern repeats.

An attacker gains an initial foothold.
They discover identities and permissions.
They move laterally across systems.
They escalate privileges.
Eventually they reach sensitive data.

None of those steps necessarily trigger a clear "malicious" signal. Attackers deliberately operate using valid identities and legitimate permissions to blend into normal activity.

Security tooling, however, largely treats events in isolation.

One system detects anomalous activity.
Another monitors configuration risk.
Another tracks identity permissions.

Each tool produces useful information, but none of them answers the question security teams actually care about:

Is someone moving closer to our sensitive data right now?

The missing concept: risk progression

What matters in a real attack is not the number of alerts.

What matters is whether an attacker is progressing through the environment.

If an identity suddenly gains a permission that opens access to a sensitive dataset, risk has changed.

If an attacker pivots from one identity to another that can access production systems, risk has changed.

If a new path to sensitive data becomes reachable, risk has changed again.

Security teams intuitively understand this idea. They talk about attackers "moving laterally" or "getting closer to the crown jewels".

But most security tools are not built to measure that progression.

They surface events, not trajectories.

vec0 models the path to data

vec0 is built around a simple observation:

breaches are paths through identities and permissions toward sensitive data.

Instead of looking at alerts in isolation, vec0 builds a shared model of how identities, permissions, systems, and data connect.

That model makes viable paths from compromised identities to sensitive data visible: identity-to-data breach vectors.

Some vectors already exist in the current environment.

Some are created or shortened by a proposed change.

Some become more credible as activity unfolds.

vec0 focuses on the vectors that matter and the changes that affect them.

We model the risk delta created by each step and identify when a sequence of actions forms a meaningful trajectory toward sensitive data.

One model, three ways to use it

The same identity, permission, resource, and data model supports three different security questions.

vec0 Assess provides a point-in-time view of which identity-to-data breach vectors matter now. It helps teams understand exposure, blast radius, and remediation priorities for risk reviews, board reporting, insurance, and planning.

vec0 Model lets teams test a compromised identity, a permission change, or a remediation option before it is applied. The question is not only what is exposed, but which change actually breaks the path to data.

vec0 Detect continuously evaluates runtime activity against those vectors. Its detection agents investigate whether identity activity is materially increasing data breach risk before sensitive data is reached.

These are not separate products with separate models. They are three ways to use the same understanding of how identities can reach data.

Detecting the attack before the data is touched

Most breach detection happens too late.

By the time traditional alerts fire, attackers may already be interacting with the data that matters.

The goal of vec0 Detect is earlier detection.

If an attacker begins chaining identities together, escalating permissions, or creating new paths toward sensitive data, that trajectory should be visible before the final step occurs.

By modelling how risk evolves across identities and permissions, vec0 Detect aims to surface those attack chains while they are still unfolding.

A data-centric view of security

Security systems often start from infrastructure or alerts.

vec0 starts from data.

Sensitive data is the ultimate objective in most breaches. That is where regulatory risk, reputational damage, and operational impact occur.

By modelling how identities and permissions connect to that data, vec0 focuses attention on the actions that materially increase the likelihood of a breach.

If an event does not move an attacker closer to sensitive data, it should not compete equally for attention with the events that do.

The goal

vec0 exists to help security teams answer three related questions:

What is our identity-to-data breach exposure right now?

Which change breaks the path to data?

Is someone moving toward our sensitive data right now?

By modelling identities, permissions, and activity as one system, vec0 helps teams understand exposure, test remediation, and make trajectories visible while they are still forming.

Because preventing a breach is much easier before the attacker reaches the data.

Next step

Want to see how identity-to-data paths look in your environment?

Book an early access call to walk through the paths, permissions, and risk transitions that matter most.