Beyond-Zero: Containment Escalation

BEYOND ZERO

What is Containment?

When Beyond Zero's investigation engine detects probable compromise or a pattern of failed challenges, it applies a Containment — a durable access restriction that immediately limits what the accessor can do. Unlike a simple "lock out," containments are graduated and dynamic.

What it does for you: Stops breaches in real-time without waiting for human intervention. A compromised nurse account making 500 requests at 3 AM gets contained within 2 seconds — before your security team even wakes up. Legitimate users who trigger containment can de-escalate by passing a challenge (security key + re-authentication), so false positives resolve quickly without a support ticket.

Try it: Click "Escalate" to move through the 5 containment levels and see what each one blocks. Click "De-escalate" to step back down. Click "Lift" to remove containment entirely. Notice how each level restricts progressively more — from rate limiting to full denial.

Business Value for AI Architects & Consultants

What risk does this eliminate?

Who benefits: Security Operations Leads · CISOs · Incident Response Teams · NHS Digital Security Officers

Compliance: NIST Incident Response Framework · NHS DSPT (incident management) · Cyber Essentials Plus · ISO 27035 (security incident management)

Walk-Through Scenario: "The Compromised Credential"

Follow this story using the interactive demo below.

1An attacker gains access to a clinician's session. They begin making unusual, high-volume requests across multiple wards.
2L1 (Rate Limit): System detects anomalous volume — applies rate limiting. Attacker slowed. (Click through containment levels)
3L2 (Scope Restrict): Requests outside normal scope — restrict to home ward only. Attacker's lateral movement blocked.
4L3 (Suspend): Continued anomalies — full suspension. All access blocked pending investigation.
5Outcome: Attacker contained in under 60 seconds. No SOC analyst needed for initial response. Legitimate clinician can break-glass (L4) if this was a false positive.

Presenter tip: Show the escalation from L1→L3, then demonstrate break-glass (L4) as the safety valve for false positives.

Containment Level

Containment progressively restricts an accessor's capabilities as risk increases. Each level applies additional restrictions.

L0 — None

Restrictions at Current Level

Containment Log

System initialised at L0 — no containment active.