Limit pod to pod communication using network policies that follow a default deny model. Allow only the flows that the application requires, including egress, so a compromised pod cannot pivot freely across the cluster.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.