Proprietary method · inside OnlyWay™

OnlyPath™

The only path is the one we draw.

Cybersecurity only works when the IT infrastructure is configured the right way. OnlyPath™ designs and configures the key components of your IT with an attacker's mindset: we draw the paths a criminal can take, so any incident is anticipated, visible and manageable.

  • Configuration led by offensive security experts
  • Forced attack paths, watched by sensors and decoys
  • Manageable incidents: logs, playbooks and containment ready
  • Results verified with the Data Breach Simulator, before and after
OnlyPath: the maze with the attacker's forced path, watched by sensors, up to the trap; the core stays protected
ApproachAttack-led configuration
VerificationData Breach Simulator, before and after
DeliverableAttack Path Blueprint
IndicatorIncident Readiness Score
AlignmentNIS2 · DORA
Designed by a hacker. To stop hackers.
The starting point

Today, the attacker chooses the path.

In most infrastructures the paths to data and privileges are many, hidden and unwatched. Attackers find them before defenders do and, by the time the incident surfaces, it is too late to understand what happened.

Too many paths
Routes to privileges that nobody has ever mapped
Little visibility
Incomplete or tamperable logs, alerts without context
No plan
Incidents handled by improvisation, at the expense of business continuity
How it works

The forced path, in four steps

We flip the perspective: we don't wait for the attacker, we prepare the path. And on that path, we are waiting.

STEP 01

We map the paths

Using offensive techniques, we identify every route an attacker could take to reach data and privileges.

STEP 02

We close the shortcuts

We remove unnecessary routes and keep open only the ones we decide.

STEP 03

We watch the path

Sensors, logs and decoys along the way: every step the attacker takes becomes visible.

STEP 04

We prepare the response

Playbooks, containment and backups ready: the incident is managed, not suffered.

OnlyPath diagram: forced path with sensors, decoys in dead ends and the alarm and containment point
The method at a glance: the attacker gets in, but can only follow the path we drew. Sensors along the way, decoys in the dead ends, alarm and containment where we decide.
The six principles of OnlyPath™

One idea, six ways to put it into practice

Principle 01

Forced path

"The only path is the one we draw."

The attacker can get in, but can only move along the routes we designed, watched by sensors at every point.

Principle 02

Chosen ground

"We choose the battlefield."

Whoever chooses the ground wins before the fight: the network is designed so the confrontation happens where we are strongest.

Principle 03

Trap architecture

"Every move the attacker makes triggers an alarm we set."

Decoy credentials, honeytokens and canary accounts: the more the attacker moves, the more they reveal themselves.

Principle 04

Hacker-Designed

"Designed by a hacker. To stop hackers."

The configuration is led by offensive security experts, who know the attack paths because they walk them for a living.

Principle 05

Incident-Ready by Design

"An incident is handled well only if it was anticipated when the IT was designed."

Logs, playbooks and backups ready before the emergency: you execute, you don't improvise. In line with NIS2 and DORA obligations.

Principle 06

The maze

"They get in. But only where we want them."

Every deviation from the expected path is a signal, and every signal maps to a decision that is already prepared.

What we configure

Seven components, configured with an attacker's mindset

You don't need more tools: you need the right ones set up the right way. That is what makes an incident manageable.

01

Segmentation and tiering

A tiered Active Directory: the possible paths are few, known and watched.

02

Identities and privileged access

No shortcuts to the highest domain privileges.

03

Mandatory chokepoints

Critical traffic passes where we concentrate control.

04

Centralised telemetry and logs

Tamper-proof: every step along the path stays visible and traceable.

05

Deception

Decoys that trigger the alarm at the first wrong step.

06

EDR/XDR tuned on real paths

Configured against real attacks, not left on factory settings.

07

Immutable backups and playbooks

When the incident hits, you execute a plan, you don't improvise.

The proof

We don't claim it. We prove it.

The Data Breach Simulator measures before and after: the same real attack, in a controlled environment, before and after the OnlyPath™ configuration. We also verify whether EDR/XDR, SOC and MDR can be bypassed, and give those who run them targeted guidance to make them truly effective.

Before and after OnlyPath: before, the attacker chooses the path and bypasses EDR/XDR, SOC and MDR with no alarms, resulting in full compromise; after, they move only along the drawn path, sensors and decoys reveal them, those running the defences receive targeted guidance, and the attack is seen and contained

Illustrative example. Actual results depend on the infrastructure and are measured for each client with the Data Breach Simulator.

Attack Path Blueprint Incident Readiness Score Before/after verification Board report
Frequently asked questions

Answers for decision-makers

Do I need to replace my security tools?

Usually not. OnlyPath™ works mainly on the configuration of what you already have: Active Directory, identities, segmentation, logs, EDR/XDR and backups. If integrations are needed, we tell you, with priorities and reasons.

What does "you draw the path" mean?

It means we design the infrastructure so that the routes to data and privileges are few, known and monitored. An attacker can still get in, but every move goes through points we control and that trigger the alarm.

How does it relate to NIS2 and DORA?

Both require incidents to be prevented, detected and handled in a structured way. OnlyPath™ makes these capabilities concrete and demonstrable, with evidence that is also useful for audits and management bodies.

How do you measure the result?

With the Data Breach Simulator: the same real attack, in a controlled environment, before and after the configuration. The comparison is objective and summarised in the Incident Readiness Score.

How long does it take?

It depends on the size and complexity of the infrastructure. After the initial assessment we propose a plan with phases, priorities and timelines.

Is OnlyPath™ a standalone service or part of OnlyWay™?

It is the method at the core of OnlyWay™ and it integrates with CISO advisory, data breach simulation and IT team training.

OnlyPath™ · inside OnlyWay™

You decide where the next attack will go.

We design your IT infrastructure with an attacker's mindset, so every incident is anticipated, visible and manageable.

Designed by a hacker. To stop hackers.