
Why these two numbers are grouped together
670 is an event count; 549 is a source count. Read together, they say something an event count alone doesn’t: the high-severity traffic in this window isn’t dominated by a small number of actors making repeated attempts, it’s spread across a comparably large set of distinct sources — roughly 1.2 events per actor. That ratio matters for response planning, since it rules out the possibility of resolving most of the exposure by addressing one or two persistent IPs.The 30% is a change indicator, not a static count
This figure is measured against the prior period, not presented as an absolute. An increase of this size in high-severity permitted traffic is the kind of shift a continuously running analysis surfaces immediately, rather than something that would only become visible on the next scheduled reporting cycle.What “permitted, then intercepted” means
Both figures describe traffic the client’s firewall already allowed through. OneFirewall’s detection layer classified and intercepted it after the fact, which is why these numbers exist as a distinct category rather than being folded into the firewall’s own blocked-traffic count.Proof of Value engagements surface this same event-to-actor ratio against a client’s own high-severity traffic. Start a Proof of Value.

