East-West Security Calculator
Measure lateral movement exposure inside a data centre: uninspected east-west traffic, exposed paths and agents still to deploy.
Inputs
Uninspected Lateral Paths
7,200
East-West Traffic
45.00Gbps
Uninspected East-West Traffic
18.00Gbps
Total Lateral Paths
18,000
Protected Lateral Paths
10,800
Agents Still to Deploy
600
Unprotected Workload Share
40.0%
Step by step
Values used
Workloads in the data centre = 1,500 workloads; Total data centre traffic = 60 Gbps; Share of traffic that is east-west = 75 %; Workloads with an enforcement agent deployed = 60 %; Distinct peer flows per workload = 12 flows
East-West Security
east-west traffic = total × east-west share; exposed paths = workloads × flows per workload × (1 − agent coverage).
Uninspected Lateral Paths
= 7,200
East-West Traffic
= 45.00 Gbps
Uninspected East-West Traffic
= 18.00 Gbps
Total Lateral Paths
= 18,000
Protected Lateral Paths
= 10,800
Agents Still to Deploy
= 600
How it works
Most data centre traffic never passes the perimeter firewall, so perimeter inspection coverage says nothing about lateral movement. Weighting the east-west volume by agent coverage gives the traffic still flowing uninspected, and multiplying workloads by their peer flows gives the concrete number of paths an attacker could still use. Every uninspected lateral path is a route from an initial foothold to a crown-jewel system, and the exposed-path count is far more actionable in a risk review than a coverage percentage.
Formula
East-West Security
east-west traffic = total × east-west share; exposed paths = workloads × flows per workload × (1 − agent coverage).
- east-west share
- Portion of data centre traffic that never crosses the perimeter
- agent coverage
- Share of workloads running an enforcement agent
Frequently Asked Questions
How is East-West Security calculated?
east-west traffic = total × east-west share; exposed paths = workloads × flows per workload × (1 − agent coverage). Most data centre traffic never passes the perimeter firewall, so perimeter inspection coverage says nothing about lateral movement. Weighting the east-west volume by agent coverage gives the traffic still flowing uninspected, and multiplying workloads by their peer flows gives the concrete number of paths an attacker could still use.
Why does East-West Security matter?
Every uninspected lateral path is a route from an initial foothold to a crown-jewel system, and the exposed-path count is far more actionable in a risk review than a coverage percentage.
What values do I need to enter?
This calculator takes 5 inputs: Workloads in the data centre, Total data centre traffic, Share of traffic that is east-west, Workloads with an enforcement agent deployed, Distinct peer flows per workload. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Can I do east-west inspection without agents?
Partly. Hypervisor-level or fabric-level enforcement covers virtual machines without touching the guest, and cloud-native security groups cover instance-to-instance traffic. What neither sees is traffic between containers on the same host or between processes in the same pod, which is where agent or service-mesh enforcement is the only option.
You might also need
- North-South Security CalculatorCommonly used together
- Micro-Segmentation CalculatorCommonly used together
- Network Security Score CalculatorCommonly used together
- Zero Trust Readiness CalculatorCommonly used together
- Network Segmentation CalculatorAlso in Network Security
- ARP Spoofing Risk CalculatorAlso in Network Security