When Beyond Zero's investigation engine detects probable compromise or a pattern of failed challenges, it applies a Containment — a durable access restriction that immediately limits what the accessor can do. Unlike a simple "lock out," containments are graduated and dynamic.
What it does for you: Stops breaches in real-time without waiting for human intervention. A compromised nurse account making 500 requests at 3 AM gets contained within 2 seconds — before your security team even wakes up. Legitimate users who trigger containment can de-escalate by passing a challenge (security key + re-authentication), so false positives resolve quickly without a support ticket.
Try it: Click "Escalate" to move through the 5 containment levels and see what each one blocks. Click "De-escalate" to step back down. Click "Lift" to remove containment entirely. Notice how each level restricts progressively more — from rate limiting to full denial.
What risk does this eliminate?
Who benefits: Security Operations Leads · CISOs · Incident Response Teams · NHS Digital Security Officers
Compliance: NIST Incident Response Framework · NHS DSPT (incident management) · Cyber Essentials Plus · ISO 27035 (security incident management)
Follow this story using the interactive demo below.
Presenter tip: Show the escalation from L1→L3, then demonstrate break-glass (L4) as the safety valve for false positives.
Containment progressively restricts an accessor's capabilities as risk increases. Each level applies additional restrictions.