CydentiCydenti
NHI Glossary

What Is Blast Radius?

Blast radius describes the extent of damage or access an attacker gains if a specific credential, identity, or system is compromised. In identity security, it refers to everything a compromised non-human identity — a service account, API key, or token — can reach: which systems it can access, what data it can read or modify, and which other identities or resources it can pivot to next. Blast radius is determined not just by the permissions directly assigned to that identity, but by the connections it has to other systems, the trust relationships it participates in, and any downstream credentials it can use or generate. A small blast radius limits a breach to a contained, low-impact event; a large one allows a single compromised credential to cascade across an environment.

Why It Matters

Blast radius is what turns an ordinary credential leak into a large-scale breach. A single non-human identity, if over-privileged or interconnected with other systems, can serve as the pivot point from which an attacker moves laterally through cloud infrastructure, code repositories, and downstream integrations — often undetected because NHI activity is rarely monitored with the same scrutiny as human logins. This dynamic explains why OWASP finds that 80% of identity breaches involve a non-human identity (OWASP NHI Top 10, 2025): one compromised machine credential rarely stays contained. In environments where non-human identities can outnumber human employees 45 to 1, and a typical 100-person company runs 2,000+ NHIs, mapping blast radius in advance — rather than discovering it during incident response — is essential to understanding true organizational exposure, and increasingly expected under frameworks like ANSSI's ReCyF Objective 13.

How Cydenti Helps

Cydenti builds a live identity graph that maps how every non-human identity connects to systems, data, and other credentials, making blast radius visible before an incident rather than after. By modeling these relationships continuously, Cydenti helps security teams see exactly what a given compromised credential could reach and prioritize containment measures — segmentation, permission reduction, or rotation — where the potential impact is greatest. This turns blast radius from an incident-response guess into a proactive, measurable metric. Explore how Cydenti's identity graph maps exposure across your environment.

Explore →

Frequently Asked Questions

How is blast radius calculated for a non-human identity?

It's derived from the identity's direct permissions plus its indirect reach — what other systems it can call, what trust relationships or downstream tokens it can access, and what data stores it touches. Mapping these connections, typically via an identity graph, reveals the full scope of potential impact, not just the obvious first-hop access.

How do you reduce blast radius?

The main levers are enforcing least privilege so each identity holds only necessary access, segmenting systems so compromise in one area doesn't grant reach into others, and regularly reviewing and revoking unused trust relationships or standing connections between services.

Ready to secure your future?

Discover the machine identities you didn't know you had — in 27 minutes, for free.

NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.

No commitment • No credit card • Data hosted in Europe • Response within 24h

What Is Blast Radius? | Cydenti