Still one of the main problems in computing security is the scope malicious intruders can gain by introducing their own thread of control. To make this worse, coarse grained structures of current operating systems are not designed to contain such breaches. So essentially the task of maintaining security lies not only with the operating system, but also within the attacked process. Obviously however, a conventional process is not at all equipped properly to defend itself nor is this task within its scope of responsibility. In introducing a new concept called nano protection domains backed by the technique of so called one-step capabilities we strive to give the operating system a much finer grained structure which will make it much harder for a security breach to actually do harm. Keywords operating system structures, objects, capabilities, security, intrusion containment