Skip to main content

Exposure Report

Path: /reports/exposure · Sidebar: Reporting → Reports

The Exposure report translates technical risk into business and financial exposure - the view a CISO takes to the board and a cyber-insurer takes to underwriting.

What it shows

  • $ exposure - an estimated financial exposure per application and overall, derived from severity, exploitability, data sensitivity and business criticality.
  • Internet-facing exposure - what's reachable from outside, with proven attack paths (from the Attack Map and Threat Models).
  • KEV / exploitable exposure - the slice that is known-exploited (CISA KEV) or proven exploitable here - the "fix this first" set.
  • Trend - exposure over time, so you can show the curve bending down.

Why it matters

Boards and insurers don't read CVSS - they read dollars and "could we be breached?". The Exposure report:

  • prioritises by money at risk, not raw count;
  • backs each number with proof (a confirmed finding / attack path), not a hypothetical;
  • gives the actuarial view for cyber-insurance conversations.

Pair it with Scorecards for the per-team grade and the Posture score for the 0-100 program metric.