Security Posture

Open contextual risk

Open critical

Known exploited

Exception cliff

Where the risk actually is

Applications ranked by contextual risk — severity weighted by tier, exposure, data, regulatory scope, KEV and live attack traffic.

Open critical and high, month end

Exceptions falling due

Accepted risk inside 30 days of expiry. No scanner knows these exist.

By business unit

Absolute risk says where the exposure is. Risk per application says who is managing it badly.

Regulated applications

What is open on applications carrying each flag. Not a compliance assessment.