Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

CISO dashboard

This dashboard reveals the overall security posture of your organization, including security vulnerability and incidents.

Image omitted: ciso-dashboard.png
Partial view of the Security Operations Center tab of the CISO dashboard
Image omitted: ciso-dashboard-vulnerability.png
The Vulnerability Profile tab of the CISO dashboard
Image omitted: ciso-dashboard-sec-controls.png
The Security Controls Profile tab of the CISO dshboard with compliance metrics
Image omitted: ciso-dashboard-business-risk.png
The Business Risk Profile tab showing risks by category

End users and roles

End user and goalRequired role
CISO: Needs clear visibility regarding the current security posture of the overall organizationsn_si.ciso

CISO dashboard indicators

The CISO dashboard presents the following key performance indicators:

  • SI - Average Time to Identify

    A 7-day average of the time in minutes it takes to identify a security incident, calculated daily.

  • Average Time to Contain

    A 7-day average of the time in minutes it takes to contain a security incident, calculated daily.

  • Average Time to Eradicate

    A 7-day average of the time in minutes it takes to eradicate a security incident, calculated daily. Both Average Time to Contain and Average Time to Eradicate are based on the indicator SI - Average Duration Time broken down by Security Incident State.

  • New Security Incidents This Week

    The weekly sum of the score of the daily Number of new security incidents indicator.

  • Security Incidents Closed (weekly)

    The 7-day running sum of the daily Number of closed security incidents indicator.

  • New Security Incidents by Priority

    Daily breakdown of the Number of new security incidents indicator by Priority.

  • New vs Closed Security Incidents (weekly) volume

    The 7-day running sum time series of the Number of new incidents indicator charted against the 7-day running sum time series of the Number of closed incidents indicator.

  • Security Incident Heatmap

    A global map showing the number of open security incidents in each country.

  • Security Incident Treemap

    An interactive treemap where you can select to see:

    • Security incidents per business service, broken down by business criticality
    • Security incidents broken down by category or subcategory of incident
    • Security incidents per assignment group or per assignee
    • 'Victim stats' of security incident per affected resource or affected user

Breakdowns

The following breakdowns apply to the indicators on the dashboard:

  • Business criticality
  • Security Group
  • Security Incident Age
  • Security Incident Category
  • Security Incident Close Code
  • Security Incident Priority
  • Security Incident State
  • SI - Business Service
  • Vulnerability

Data visualizations

The dashboard includes the following visualizations:

TitleTypeDescription
Security Incidents Open for More Than 30 Days by Assignment Group and StateHeatmap
Image omitted: heatmap.png
Heatmap icon|Displays models with the most vulnerable items.|

|Risks by Category|Donut

Image omitted: donut-icon.png
Donut icon|Lists the age of reopened vulnerable items.|

|Citations by Authority Document|Donut

Image omitted: donut-icon.png
Donut icon|Number of active vulnerabilities|

|Security Incidents With Assignee That is not Active|Heatmap

Image omitted: heatmap.png
Heatmap icon|Displays the number of open vulnerable items associated with vulnerabilities, \(Common Vulnerability Enumeration \(CVE\) records\), from most to least.|

|Security Incidents Not Updated for More Than 30 Days by Assignment Group and State|Heatmap

Image omitted: heatmap.png
Heatmap icon|Displays publishers with the most vulnerable items.|

|Vulnerability Map|Map

Image omitted: map-icon.png
Map icon|A world map showing vulnerabilities by location|

|Most Vulnerable Models|Donut

Image omitted: donut-icon.png
Donut icon|The applications that contain the most vulnerabilities|

|Most Vulnerable CIs by Class|Donut

Image omitted: donut-icon.png
Donut icon|CIs by server type|

|Services with Critically Significant Vulnerabilities|List

Image omitted: scorecard-icon.png
List icon3| |

|Non-compliant profiles|Bar

Image omitted: column-icon.png
Bar icon|Non-compliant controls by profile|

|Control Overview|Bar

Image omitted: column-icon.png
Bar icon|Number of compliant and non-compliant controls|

|Policy Exceptions|List

Image omitted: scorecard-icon.png
List icon3|Policy exceptions with priority, owner, and short description|

|Risks by Category|Donut

Image omitted: donut-icon.png
Donut icon|The number of risks in each category of risk|

|Inherent Risk|Bubble

Image omitted: bubble-icon.png
Bubble icon|Inherent SLE vs Inherent ARO|

|Residual Risk|Bubble

Image omitted: bubble-icon.png
Bubble icon|Residual SLE vs Residual ARO|

|Moderate, High, and Very High Risks|Scores

Image omitted: latest-score-icon.png
Latest score icon|The numbers of moderate, high, and very high risks, respectively|

|Risk by Profile|Stacked Bar

Image omitted: stacked-column-bkdown-icon.png
Stacked bar icon|Risk count where you can select what to group by and what to stack by|

Parent Topic:Security Incident Response Platform Analytics Solutions

Related topics

Security Incident Management Premium dashboard

Security Incident Management dashboard

Security Incident Explorer dashboard

Security Operations Efficiency dashboard