Skip to content
Calcrivo

East-West Security Calculator

Measure lateral movement exposure inside a data centre: uninspected east-west traffic, exposed paths and agents still to deploy.

Inputs

workloads
Gbps
%

Modern data centres run 70–80% east-west.

%
flows

Uninspected Lateral Paths

7,200

East-West Traffic

45.00Gbps

Uninspected East-West Traffic

18.00Gbps

Total Lateral Paths

18,000

Protected Lateral Paths

10,800

Agents Still to Deploy

600

Unprotected Workload Share

40.0%

Step by step

  1. Values used

    Workloads in the data centre = 1,500 workloads; Total data centre traffic = 60 Gbps; Share of traffic that is east-west = 75 %; Workloads with an enforcement agent deployed = 60 %; Distinct peer flows per workload = 12 flows

  2. East-West Security

    east-west traffic = total × east-west share; exposed paths = workloads × flows per workload × (1 − agent coverage).

  3. Uninspected Lateral Paths

    = 7,200

  4. East-West Traffic

    = 45.00 Gbps

  5. Uninspected East-West Traffic

    = 18.00 Gbps

  6. Total Lateral Paths

    = 18,000

  7. Protected Lateral Paths

    = 10,800

  8. Agents Still to Deploy

    = 600

How it works

Most data centre traffic never passes the perimeter firewall, so perimeter inspection coverage says nothing about lateral movement. Weighting the east-west volume by agent coverage gives the traffic still flowing uninspected, and multiplying workloads by their peer flows gives the concrete number of paths an attacker could still use. Every uninspected lateral path is a route from an initial foothold to a crown-jewel system, and the exposed-path count is far more actionable in a risk review than a coverage percentage.

Formula

East-West Security

east-west traffic = total × east-west share; exposed paths = workloads × flows per workload × (1 − agent coverage).

east-west share
Portion of data centre traffic that never crosses the perimeter
agent coverage
Share of workloads running an enforcement agent

Frequently Asked Questions

How is East-West Security calculated?

east-west traffic = total × east-west share; exposed paths = workloads × flows per workload × (1 − agent coverage). Most data centre traffic never passes the perimeter firewall, so perimeter inspection coverage says nothing about lateral movement. Weighting the east-west volume by agent coverage gives the traffic still flowing uninspected, and multiplying workloads by their peer flows gives the concrete number of paths an attacker could still use.

Why does East-West Security matter?

Every uninspected lateral path is a route from an initial foothold to a crown-jewel system, and the exposed-path count is far more actionable in a risk review than a coverage percentage.

What values do I need to enter?

This calculator takes 5 inputs: Workloads in the data centre, Total data centre traffic, Share of traffic that is east-west, Workloads with an enforcement agent deployed, Distinct peer flows per workload. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Can I do east-west inspection without agents?

Partly. Hypervisor-level or fabric-level enforcement covers virtual machines without touching the guest, and cloud-native security groups cover instance-to-instance traffic. What neither sees is traffic between containers on the same host or between processes in the same pod, which is where agent or service-mesh enforcement is the only option.

You might also need