Prevention as a Program: How Via Enforces Preventive Guardrails at Scale With Zero Disruption
How Via shifted from alert-chasing to prevention as a strategic program, letting a lean security team enforce preventive guardrails across its AWS Organization with zero disruption to production.
Via, a global TransitTech platform, runs mission-critical mobility and public-transit software that cities and transit agencies depend on around the clock. As the business grew, its cloud footprint grew faster than its security headcount, leaving a lean team chasing alerts and manually remediating the same kinds of misconfigurations across a large multi-account AWS estate.
This is the story of how Via stopped chasing alerts and made prevention a strategic program, enforcing preventive guardrails at scale across its AWS Organization with zero disruption to production. Here is how a small team hardened a growing estate without adding headcount.
Why alert-chasing could not keep up
Visibility told Via what was wrong, but it did not stop the next risky change from reaching production. In an environment where an outage means disrupted transit service for real communities, reactive remediation was both too slow and too risky. Fixing the same classes of issues one account and one team at a time could not keep pace with growth.
Via needed to move from alert-chasing to prevention, and to do it as a strategic, repeatable program rather than a series of one-off fixes. That framing mattered: prevention as a program, not a point tool, is what earned organizational buy-in.
Treating cloud prevention as a strategic program
Treating prevention as a program means moving from ad-hoc, reactive fixes to a repeatable, organization-wide practice: prioritizing the guardrails that matter, simulating their impact, enforcing them as native controls, and monitoring for drift. Standardized guardrails make security consistent across every team, so the same protections apply whether a workload is six months or six days old.
Enforcing preventive guardrails at scale on native AWS controls
With Blast’s Preemptive Cloud Defense Platform, Via gained a faster, safer way to understand, manage, and scale preventive cloud controls. Blast connected agentlessly to Via’s AWS Organization using read-only metadata. Instead of adding another detection layer, it operationalizes the native controls AWS already offers:
- Assess. Map cloud behavior, existing controls, and blast radius across Via’s AWS Organization.
- Plan. Tailor a prioritized guardrail plan to how Via actually operates, not generic policy.
- Simulate. Test the business impact of every guardrail before enforcement, so production transit services are never surprised.
- Enforce. Apply native AWS SCPs and RCPs across OUs and accounts at scale, with no agents and no middleware.
- Monitor. Track drift and keep the prevention posture intact as the environment changes.
Adaptive Accept-Risk handled exceptions without weakening posture. Simulating the impact of each control against the real environment was the key to earning trust for zero-disruption enforcement: the team could prove a guardrail was safe before it went live.
At Via, we see the shift from alert-chasing to prevention as a strategic program. Blast enables us to enforce preventive guardrails at scale, making our cloud environments more resilient with the same resources, less manual effort, and the trust to ensure zero disruption to the business.
Oren Hogery, CISO, Via
Prevention that scales with the team, not the headcount
Via now delivers prevention at scale with the same team and far less manual effort. Standardized, organization-wide guardrails replaced repetitive per-team remediation, and enforcement was achieved with zero disruption to the business, the direct result of a simulation-first rollout that proved each control safe before it went live.
Because Blast is agentless and enforces through existing AWS-native controls, Via added no sensor infrastructure and no new runtime to operate. The primary saving is leverage: one security team now covers a growing estate without added headcount, and simulation avoids the costly outages that manual, per-team hardening can trigger. Via procures Blast through the AWS Marketplace.
Frequently asked questions
What does it mean to treat cloud prevention as a strategic program?
It means moving from ad-hoc, reactive fixes to a repeatable, organization-wide practice: prioritizing the guardrails that matter, simulating their impact, enforcing them as native controls, and monitoring for drift. Framing prevention as a program, not a point tool, is what drove organizational buy-in at Via.
How can a lean security team enforce prevention at scale?
By standardizing preventive guardrails across accounts and enforcing them through native AWS controls instead of remediating team-by-team. Blast lets an existing team harden a growing multi-account estate with less manual effort and no added headcount.
How does Blast enforce guardrails without disrupting production?
Blast simulates every control against real environment behavior before enforcing it. Via used this to test the business impact of each guardrail first, then enforced native AWS controls with the confidence that legitimate workflows, and the transit services running on them, would keep working.
How does Blast integrate with AWS?
Blast connects agentlessly to your AWS Organization through a read-only, metadata-only role and enforces through native AWS SCPs and RCPs, with no agents, sensors, or middleware. It is available through the AWS Marketplace.
See it in your own environment. Learn how the Preemptive Cloud Defense Platform enforces preventive guardrails at scale on your native AWS controls, or get a demo.