AWS and Cloudanix team co-authored this blog: Real-Time Threat and Anomaly Detection for Workloads on AWS
Contextual Severity · Cloudanix Security Graph

Everything is Critical.
Which is another way
of saying nothing is.

Every scanner ships one hard-coded severity per rule. So an internal-only bucket and an internet-facing one arrive in your queue with the same red badge, and your team spends Monday deciding which Criticals were real. Cloudanix computes severity per asset from the security graph — exposure, environment, data, identity — and always shows youwhy it landed where it did.

  • Severity per asset, not per rule
  • Every adjustment shows its reason
  • On by default — override any policy
One graph, two questions.What can be reached — and how loud it should be.
one policy · two assets · two severities
policyS3 Buckets Should Have A Secure Transport Policybase: Critical
acme-public-assets
  • internet-facing
  • production
  • reaches customer data
effective severityCriticalstays Critical — nothing here to discount
acme-internal-logs
  • internal-only
  • non-production
  • no sensitive data
effective severityMediumCritical → Medium · internal & non-prod
Same rule. Same account. Different asset — so a different number, and the reason travels with it.
Definition

Severity is a property of the rule.
Risk is a property of the asset.

"

Contextual severity means a finding's severity is decided by the asset it landed on — not by the rule that found it. Cloudanix reads the live context thesecurity graph already holds about that asset: how it is exposed, what it holds, what it can reach, what is running on it, and what it is part of. The finding arrives with a severity that reflects that reality, and the specific reasons that produced it. Nothing is hidden, nothing is silently suppressed, and the base assessment is always one hover away.

— Cloudanix product position
What a rule knows on its own
Policy failed on an assetCritical

One value, authored once, applied to every account, every environment and every asset it will ever touch. This is where every other tool stops.

What Cloudanix already knows about that asset
internet reachabilityenvironmentdata sensitivityidentity blast radiusattack-path presencewhat is running on itvulnerability exposurenetwork containmentownership & account tiercompliance scoperecent threat activity…and more each release

Which signals apply is decided per policy, not globally — a transport-encryption rule and an over-permissive-role rule care about different things.

What lands in your queue
effective severityMediumwas Critical
  • internal-only — no path from the internet
  • non-production account
  • holds no regulated data

Still open. Still in compliance scope. Still able to escalate the day any of that changes.

The problem

Static severity doesn't just fail to reduce noise.
It manufactures it.

A rule author has to pick one severity for every customer, every account and every asset that rule will ever touch. The only safe choice is the worst case. So the worst case is what everyone gets — thousands of times a day.

01

One number for every environment

The same rule fires on your sandbox and your payments account with identical weight. Everyone learns to distrust the badge, and the real Critical loses its only advantage — being rare.

02

Suppression is the only escape hatch

When severity can't move, the only way to quiet a finding is to mute it. Muting deletes the signal permanently — including the day that asset becomes internet-facing and the finding genuinely matters.

03

Per-finding overrides don't scale

Editing severity finding-by-finding is a manual queue that resets every scan. What teams actually want is apolicy: "in this workspace, this rule is Medium on internal assets." Once.

04

Prioritization sits in a side panel

Plenty of tools compute a smarter risk ranking — in a separate view, next to the severity that still drives alerts and reports. Two truths, one inbox. The engineers keep following the old one.

The control

It's already on. You don't have to do anything.

Contextual is how Cloudanix reports severity out of the box, so a quieter queue is the starting point rather than a project. If you ever want a flat number back, or your own, each policy can be switched in a click.

The Cloudanix severity mode picker showing three options — Contextual, which is selected and explains itself with the reason that the bucket is internal-only and not internet-facing, alongside Customer Defined with a severity selector and Cloudanix Defined showing a Critical badge.
Contextual, selected — explaining itself in plain English rather than showing you a score to interpret.
Default

Contextual

Severity that fits the asset.

Each finding is weighed against the asset it landed on, so the Criticals in your queue are the ones that can actually hurt you. Every adjustment shows its reason in plain English.

  • On by default
  • Quieter queue, same coverage
  • Always tells you why
Your call

Customer Defined

Pin whatever you want.

Some controls are non-negotiable for your business or your auditor. Set those to the severity you want and nothing will move them.

  • Your value, applied everywhere
  • Existing findings update too
Opt out

Cloudanix Defined

The flat number, if you prefer it.

One severity for the rule, everywhere, the way most tools do it. It is always there as the baseline, and switching back takes one click.

  • One value per rule
  • Maintained by Cloudanix
What you get

A shorter list, and you can trust it.

The point is not the scoring. The point is that Monday morning starts with a handful of findings that deserve your week, each one telling you plainly why it's there — and that nothing quietly went missing to achieve it.

01

Nothing to set up

No scoring model to build, no weights to tune, no rules to rewrite. The context that matters is already attached to every policy, so your queue re-ranks itself from day one.

02

No new agent, no new bill

The context comes from what Cloudanix already knows about your estate. Nothing extra to deploy, nothing extra to collect, no separate line item.

03

Your alerts finally mean something

Lists, dashboards, thresholds and Slack notifications all read the same severity. Point your pager at Critical and it means what you think it means.

04

Nothing is hidden from you

A quieter finding is still an open finding — visible, searchable, and in compliance scope. It gets loud again on its own the day your exposure changes.

The Cloudanix Policies screen for misconfigurations. A slideout for the policy S3 Buckets Should Have A Secure Transport Policy shows its compliance framework mappings, the three severity modes with Contextual selected, and the per-account table where the policy and its severity mode are enabled.
Settings → Misconfig → Policies. Compliance mappings, the severity mode, and per-account enablement in one place — because a severity decision is a policy decision, not a per-finding chore.
The context we read

Everything Cloudanix knows about the asset counts.

Not a fixed list of attributes, and not a closed set — the more of your estate Cloudanix covers, the sharper your severities get, without you changing a thing.

Exposure & reachability

Whether the asset can actually be reached — resolved through policies, ACLs, endpoints, load balancers and routes, rather than read off a single public flag.

Environment & ownership

Production or not, which account tier it belongs to, and who owns it. The coarsest signal, and often the one that resolves the most volume.

Data context

Whether the asset holds or can reach regulated or customer data. A weak control in front of nothing is not the same finding as one in front of PII.

Identity & blast radius

How far the identities attached to the asset can get — escalation, cross-account assumption, and what sits downstream if any of it is compromised.

Attack-path presence

Whether a confirmed chain already exists from the internet to this asset. When the graph has proven reachability, that is the strongest escalation signal there is.

Runtime & threat activity

What is actually running, whether the asset already carries an exploited vulnerability, and whether anything suspicious has touched it recently.

What this means for you

You don't tune any of this. The context that matters is already attached to each policy, so switching a rule to Contextual is a single choice — not a scoring model you have to configure, maintain, or explain to your auditor. And because it reads the same graph as the rest of the platform, every capability you turn on makes your severities sharper without you touching a thing.

Why this needs a graph

You can't contextualize severity
without a model of context.

"Is this bucket internet-facing?" looks like a one-field lookup and almost never is. The answer runs through policies, ACLs, VPC endpoints, load balancers, route tables and the identities that can reach it. A scanner with a flat finding table cannot answer it, which is exactly why static severity has survived this long.

Cloudanix already models your cloud as a typed asset graph to walk attack paths. Contextual severity is the same graph answering a different question — so it arrived as a correlation feature rather than a new product with a new agent and a new data pipeline.

one graph · two questions
Attack Path asks

“Can something out there reach this asset, and what does it touch next?”

Walk the chain →
Contextual Severity asks

“Given what this asset is and where it sits, how loud should this finding be?”

You are here
  • Exposure edges internet reachability, not just a public flag
  • Identity edges who can assume what, and how far
  • Data context which assets hold or reach regulated data
  • Environment production versus everything else
Guardrails

Quieter, without losing anything.

Anything that can lower a severity deserves suspicion. Here is what a de-escalated finding still does for you.

Your audit is untouched

Compliance is scored pass/fail, never weighted by severity. A de-escalated finding is still an open finding against every framework it maps to — so nothing "completes" SOC 2, ISO 27001 or PCI because a number went down. Your evidence pack does not change.

You can always answer "why is this a Medium?"

Every adjusted finding shows the conditions behind it and the severity it started from. When an auditor, a customer or your own board asks three months later, the answer is on the finding rather than in someone's memory.

It escalates the day your risk changes

Posture severity is re-evaluated as your assets change. The day an internal bucket becomes internet-facing, its findings get loud again on their own — the thing muting a finding can never do for you.

You stay in control of any policy

Contextual is on by default, and any single policy can be pinned to your own value or switched back to a flat severity in one click. You are never stuck with a number you disagree with.

Across the platform

One severity model, every finding surface.

Contextual severity is not a feature of one module — every surface that produces findings inherits it, so your posture, detection, workload, identity and code queues speak one severity language. Pick your surface below to see what that looks like in practice.

The honest comparison

Most tools give you three options.
None of them is "change the severity."

Context-aware prioritization is a real and growing part of this market — several platforms rank findings by exposure and reachability, and cloud-native services expose per-finding severity edits through their APIs. The difference is where the context lands. Below is what we think is actually distinct, stated narrowly enough to be true.

ApproachWhat you getWhere it falls short
Suppress or muteThe finding stops appearing.The signal is gone even when the asset's context changes and the finding starts to matter.
Per-finding severity editAn API call sets severity on findings that already exist.Manual, retroactive-only, and often restricted to admins — it is an incident action, not a policy.
Separate risk score or exposure viewA smarter ranking that factors in reachability.Lives beside the severity that still drives alerts, thresholds and reports. Two numbers, and the automation follows the old one.
Cloudanix contextual severityA per-policy mode that rewrites the effective severity per asset, with its reason attached.Needs a real asset graph underneath, so it is not something a standalone scanner can bolt on.

If you are evaluating us against a specific tool, ask them one question: can I express "this rule is Medium on internal assets and Critical on exposed ones" as a policy, and will my alerts respect it? That is the whole feature.

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo