
Three enforcement states, not two
Most gap analyses stop at “blocked versus not blocked.” This one separates blocking into what the existing rule set already handles, what an integrated OneFirewall enforcement point additionally catches, and what remains — the traffic that’s scored, corroborated, and still getting through both. That last group, 425 events, is exactly the Critical band from the severity breakdown: the highest-confidence malicious traffic in the dataset, still unaddressed.Why the 425 is the actionable figure
The first two numbers describe enforcement already in place. The 425 describes the delta — the specific set of events where applying the same Crime Score threshold already used elsewhere in the deployment would close the gap. It’s a small fraction of total traffic, which is the point: this isn’t a case for replacing the firewall, it’s a specific, bounded list of what the current setup doesn’t yet cover.Proof of Value engagements identify this same gap against a client’s own enforcement stack. Start a Proof of Value.

