Security Posture
An at-a-glance view of the organization's security posture — where risk sits and what to prioritize. Figures shown are representative and illustrative.
5Critical assetsinternet-facing + core
128Open vulnerabilitiesacross severities
4KEV exposureactively exploited, known
34 / 100Overall risk scoreMedium
Overall Risk Score
34 / 100 Medium
Aggregate risk across open vulnerabilities, knowing exploited exposure and critical asset reachability. Medium reflects finite but manageable risk.
Critical Assets
- Internet-facing customer portal critical Exposure: Public web / API
- Identity & SSO platform critical Exposure: Hybrid (edge + behind VPN)
- Core data warehouse (PII) critical Exposure: Internal, segmented
- Financial reconciliation engine high Exposure: Internal
- Remote access VPN concentrator high Exposure: Internet-facing
Open Vulnerabilities
- Critical6
- High23
- Medium58
- Low41
Known-Exploited Exposure (KEV)
- CVE-2017-0144 Microsoft SMBv1 — actively exploited
- CVE-2021-44228 Apache Log4j — actively exploited
- CVE-2017-0144 Legacy SMB exposure — legacy exposure
- CVE-2021-44228 Log4j adjacent apps — actively exploited
Compliance Coverage
- SOC 2 Type II in_progress 92% covered
- ISO/IEC 27001 compliant 96% covered
- PCI DSS in_progress 88% covered
- GDPR (processing) in_progress 90% covered
Threat Trends
- 2026-03 18 — Baseline after Q1 patching cycle
- 2026-04 22 — New KEV addition for edge devices
- 2026-05 19 — Contained internally; no breach
- 2026-06 27 — Ransomware family activity rising
- 2026-07 25 — Phishing campaigns against portal
- 2026-08 21 — Decreasing after mitigation
Related: Investigation Workspace · Security Briefings · Executive Dashboard