Skip to main content

Risk Analytics

Overview

Risk Analytics dashboard providing a high-level overview of organizational security posture

The Risk Analytics dashboard provides an executive-level view of your organization’s security posture. It combines vulnerability statistics, organizational risk scoring, SLA compliance, threat exposure, and remediation trends into a single dashboard, enabling security teams and leadership to quickly understand where the greatest risks exist. Rather than focusing on individual vulnerabilities, Risk Analytics presents a comprehensive view of your security program, helping teams prioritize remediation efforts based on business impact and overall exposure.
Risk Analytics continuously aggregates vulnerability data to provide an always up-to-date view of your organization’s overall security posture.

Executive Summary

The summary cards at the top of the dashboard provide an instant snapshot of your current vulnerability landscape.

Available Metrics

  • Total Open
    • Displays the total number of unresolved vulnerabilities.
  • Critical
    • Number of active Critical severity vulnerabilities.
  • High
    • Number of High severity vulnerabilities.
  • Medium
    • Number of Medium severity vulnerabilities.
  • Unique CVEs
    • Total unique CVEs currently affecting your environment.
  • Unique CWEs
    • Number of unique weakness categories represented across findings.
  • Known Exploited Vulnerabilities (KEV)
    • Vulnerabilities listed in the CISA Known Exploited Vulnerabilities catalog.
  • Average CVSS
    • Average CVSS score across all active findings.

Organization Risk Score

The Organization Risk Score provides an overall measurement of your security posture. The score is dynamically calculated using multiple factors including:
  • Vulnerability severity
  • True Risk prioritization
  • Business impact
  • Asset exposure
  • Active vulnerabilities
  • Organizational risk weighting
As vulnerabilities are discovered or remediated, the score automatically updates to reflect your current risk posture.

SLA Compliance Overview

The SLA Compliance widget tracks remediation performance against defined Service Level Agreements. It provides visibility into:
  • Compliant vulnerabilities
  • At Risk vulnerabilities
  • Breached vulnerabilities
  • Vulnerabilities without assigned SLAs
Additional operational metrics include:
  • MTTR (Mean Time to Resolution)
  • Remediation Velocity
These metrics help measure how effectively vulnerabilities are being resolved within expected timelines.

Threat Exposure

The Threat Exposure panel summarizes your organization’s exposure based on multiple security indicators. Key metrics include:
  • Overall Exposure Score
  • Known Exploited Vulnerabilities (KEV)
  • High EPSS vulnerabilities
  • High and Critical findings
  • Average CVSS
  • Unique CVEs
These indicators help identify areas requiring immediate remediation.

Severity Trend

Historical severity trend showing changes in organizational risk over time

The Severity Trend graph visualizes how vulnerability severity changes over time. This allows teams to monitor:
  • New vulnerabilities introduced
  • Reduction through remediation
  • Overall security posture improvements
  • Historical remediation progress

Average Open Age

The Average Open Age by Severity visualization shows how long vulnerabilities remain unresolved across each severity level. This helps identify:
  • Aging Critical vulnerabilities
  • Long-standing High severity findings
  • Medium and Low severity backlog
  • Overall remediation efficiency

Executive Insights

The Executive Insights panel automatically highlights the most important remediation opportunities and security observations. Typical recommendations include:
  • Critical vulnerabilities with the highest impact
  • High severity findings driving organizational risk
  • SLA breaches requiring immediate attention
  • Remediation blockers delaying progress
  • Accepted risks that should be periodically reviewed
Executive Insights continuously adapt to changes in your vulnerability data, ensuring recommendations remain relevant as your environment evolves.

Why Risk Analytics Matters

Risk Analytics transforms vulnerability data into actionable security intelligence by helping organizations:
  • Understand overall organizational risk
  • Monitor remediation performance
  • Track SLA compliance
  • Measure threat exposure
  • Prioritize vulnerabilities effectively
  • Present executive-ready security metrics

Operational Analytics

Overview

Operational Analytics dashboard showing remediation progress, team performance, and vulnerability lifecycle metrics

The Operational Analytics dashboard provides a detailed view of your organization’s day-to-day vulnerability management activities. It focuses on remediation progress, vulnerability lifecycle tracking, SLA performance, and team productivity to help security teams monitor operational effectiveness. Unlike Risk Analytics, which focuses on overall organizational risk, Operational Analytics helps security teams understand how efficiently vulnerabilities are being managed and resolved.
Operational Analytics provides real-time operational insights, enabling security teams to identify bottlenecks and continuously improve remediation performance.

Operational Summary

The summary section provides an instant overview of vulnerability lifecycle states.

Available Metrics

  • Total Vulnerabilities
    • Total vulnerabilities currently tracked.
  • In Review
    • Findings awaiting triage.
  • Triaged
    • Vulnerabilities that have been reviewed and categorized.
  • Unresolved
    • Open vulnerabilities still awaiting remediation.
  • Duplicate
    • Duplicate findings linked to existing vulnerabilities.
  • Retest
    • Vulnerabilities awaiting verification after remediation.
  • Fixed in Staging
    • Vulnerabilities resolved in staging environments and awaiting production validation.
  • Resolved
    • Successfully remediated vulnerabilities.
  • Risk Accepted
    • Vulnerabilities accepted by the organization after risk assessment.
  • Rejected
    • Findings determined to be invalid or not applicable.

Vulnerability Discovery Timeline

The timeline visualizes how vulnerabilities are discovered over time, helping teams identify spikes in findings and monitor remediation trends. This visualization assists with:
  • Monitoring assessment activity
  • Identifying unusual increases in findings
  • Measuring remediation progress
  • Understanding long-term security trends

Operational Analytics widgets showing remediation performance and security operations

Operational Widgets

The dashboard includes several widgets that provide detailed operational insights.

Severity Distribution

Displays the distribution of vulnerabilities across:
  • Critical
  • High
  • Medium
  • Low
  • Informational
This helps teams understand where the majority of security issues exist.

Open vs Closed by Severity

Compares resolved and unresolved vulnerabilities across each severity level. This enables teams to quickly determine whether high-risk vulnerabilities are being remediated effectively.

SLA Compliance

Measures remediation performance against defined Service Level Agreements. Displays:
  • Within SLA
  • At Risk
  • Breached
  • No SLA Assigned
Helping organizations identify overdue remediation activities.

Top Performing Members

Ranks team members based on remediation activity and vulnerability closures. This provides visibility into:
  • Individual contributions
  • Team productivity
  • Workload distribution

Vulnerabilities by Business Unit

Displays how vulnerabilities are distributed across different business units. This helps organizations identify departments requiring additional security attention.

Remediation by Department

Measures remediation performance across organizational departments. Useful for identifying:
  • Teams resolving vulnerabilities quickly
  • Departments with growing remediation backlogs

Additional operational metrics including MTTC, vulnerability aging, and source analysis

Advanced Operational Metrics

Operational Analytics also includes advanced measurements for tracking remediation efficiency.

Mean Time to Close (MTTC)

Measures the average time required to resolve vulnerabilities. This KPI helps evaluate overall remediation effectiveness.

Average Vulnerability Age

Displays the average age of unresolved vulnerabilities grouped by severity. Older vulnerabilities often indicate remediation bottlenecks or resource constraints.

Vulnerability Source Distribution

Shows where vulnerabilities originate. Examples include:
  • Qualys
  • Nuclei
  • Trivy
  • Manual Assessments
  • Other integrated scanners
Understanding source distribution helps evaluate scanner usage and assessment coverage.

Custom Dashboards

Operational Analytics supports creating multiple custom dashboards for different teams, projects, or reporting requirements.

Create a new operational dashboard

To create a dashboard:
  1. Click the + button beside the dashboard selector.
  2. Enter a dashboard name.
  3. Provide an optional description.
  4. Select related assessments.
  5. Choose dashboard visibility.
  6. Save the dashboard.
Custom dashboards allow teams to maintain focused operational views for specific business units or security initiatives.

Configure dashboard information and linked assessments

Dashboard Configuration

Each dashboard can be customized with:
  • Dashboard Name
  • Description
  • Linked Assessments
  • Public or Private Visibility
This allows organizations to tailor reporting for different audiences while maintaining centralized vulnerability data.

Why Operational Analytics Matters

Operational Analytics transforms remediation activities into measurable operational metrics. It enables organizations to:
  • Monitor remediation progress
  • Track SLA performance
  • Measure team productivity
  • Identify operational bottlenecks
  • Improve remediation efficiency
  • Build customized dashboards for different teams
By combining lifecycle tracking with performance metrics, Operational Analytics helps security teams continuously improve their vulnerability management process.

Source Analytics

Overview

Source Analytics dashboard providing visibility into scanner performance and vulnerability source quality

The Source Analytics dashboard provides comprehensive insights into the quality, reliability, and effectiveness of every vulnerability source integrated with Snapsec VM. Rather than simply counting vulnerabilities, Source Analytics helps security teams understand where findings originate, how accurate those findings are, and which scanners provide the highest confidence results. This enables organizations to continuously improve their security tooling while reducing false positives and prioritizing trusted sources.
Source Analytics transforms scanner data into actionable intelligence by measuring accuracy, confidence, and overall signal quality across every integrated source.

Source Overview

The dashboard begins with a high-level summary of all registered vulnerability sources.

Available Metrics

  • Total Sources
    • Total number of configured vulnerability sources.
  • Active Sources
    • Sources currently contributing findings.
  • Total Findings
    • Combined findings across all configured sources.
  • Accuracy Rate
    • Overall percentage of validated findings.
  • Noisy Sources
    • Sources generating excessive false positives.
  • High Confidence Sources
    • Sources consistently producing reliable findings.
These metrics provide an immediate understanding of the overall quality of your vulnerability ingestion pipeline.

Source Performance

The dashboard includes several visualizations that help evaluate scanner performance.

Findings by Source

Displays how vulnerabilities are distributed across each integrated scanner or manual source. This helps identify:
  • Primary vulnerability producers
  • Scanner utilization
  • Assessment coverage

Findings Classification

Breaks down findings into categories such as:
  • Valid
  • False Positive
  • Risk Accepted
Helping teams understand overall signal quality.

Source Activity

Visualizes source activity over time, showing how many findings each source contributes throughout the year. This enables organizations to monitor scanner usage and identify changes in vulnerability discovery patterns.

Sources inventory displaying configured scanners and their performance

Sources Inventory

The Sources Inventory provides a centralized list of every registered vulnerability source. Each entry includes:
  • Source Name
  • Source Type
  • Linked Projects
  • Total Findings
  • Valid Findings
  • False Positives
  • Accuracy Percentage
  • Confidence Level
This inventory enables security teams to compare scanners and monitor the quality of imported findings.

Managing Sources

Each source can be searched, filtered, and managed directly from the inventory. Common management tasks include:
  • Viewing source performance
  • Comparing scanners
  • Tracking confidence levels
  • Reviewing historical activity
This makes it easy to identify sources that require tuning or validation.

Register a new vulnerability source

Registering a Source

New scanners and assessment tools can be added directly from the Source Analytics dashboard. When registering a source, configure:
  • Source Name
  • Source Type
  • Confidence Level
  • Description
This allows organizations to onboard commercial scanners, open-source tools, or manual assessment sources into a single reporting framework.

Signal Analytics measuring finding quality and scanner reliability

Sources List

Sources List displaying all registered vulnerability sources and their performance metrics

The Sources List provides a centralized inventory of every vulnerability source configured in Snapsec VM. It allows security teams to monitor source activity, compare performance, and review the quality of findings generated by each scanner or manual source. Each source includes detailed operational metrics, making it easy to evaluate reliability and identify underperforming integrations.

Information Available

  • Source Name
    • Name and description of the registered source.
  • Type
    • Indicates whether the source is a scanner, manual source, or another supported type.
  • Projects
    • Number of projects associated with the source.
  • Findings
    • Total vulnerabilities reported by the source.
  • Valid / False Positives
    • Breakdown of validated findings versus false positives.
  • Accuracy
    • Overall accuracy score based on validated findings.
  • Confidence
    • Confidence level assigned to the source.
Use the search bar to quickly locate a source or customize the table using the Columns option to display only the information most relevant to your workflow.

Signal Analytics showing scanner accuracy, noise analysis, and confidence distribution

Signal Analytics

Signal Analytics evaluates the quality and trustworthiness of vulnerability data collected from every integrated source. Rather than focusing on the number of findings, it measures how reliable each source is by analyzing accuracy and false-positive rates. This helps organizations identify trusted scanners, reduce noise, and improve overall vulnerability prioritization.

Noise vs Accuracy Analysis

For every configured source, Snapsec measures:
  • Total Findings
  • Valid Findings
  • False Positives
  • False Positive Rate
  • Accuracy Percentage
  • Signal Rating (High Trust or Noisy)
These metrics make it easy to distinguish high-quality scanners from sources that require tuning or validation.

Confidence Distribution

The dashboard also provides a confidence breakdown across all registered sources, grouping them into:
  • High Confidence
    • Sources consistently producing reliable, high-quality findings.
  • Medium Confidence
    • Sources with good accuracy that may require occasional validation.
  • Low Confidence
    • Sources generating inconsistent or low-confidence results.
Together, these insights help security teams improve scanner effectiveness, reduce false positives, and build greater confidence in the vulnerability data used for remediation decisions.

Why Source Analytics Matters

Source Analytics enables organizations to continuously improve the quality of vulnerability data entering Snapsec VM. It helps teams:
  • Measure scanner effectiveness
  • Reduce false positives
  • Increase confidence in findings
  • Optimize security tooling
  • Improve vulnerability prioritization
  • Build trust in remediation decisions
By combining operational metrics with scanner intelligence, Source Analytics ensures that remediation efforts are based on reliable, high-quality security data.

Explore Live Demo

Explore VM Live — No Signup Needed

Experience how Snapsec Risk Analytics provides real-time visibility into organizational risk, threat exposure, and remediation performance through a unified executive dashboard.