Exposure Report
Path: /reports/exposure · Sidebar: Reporting → Reports
The Exposure report translates technical risk into business and financial exposure - the view a CISO takes to the board and a cyber-insurer takes to underwriting.
What it shows
- $ exposure - an estimated financial exposure per application and overall, derived from severity, exploitability, data sensitivity and business criticality.
- Internet-facing exposure - what's reachable from outside, with proven attack paths (from the Attack Map and Threat Models).
- KEV / exploitable exposure - the slice that is known-exploited (CISA KEV) or proven exploitable here - the "fix this first" set.
- Trend - exposure over time, so you can show the curve bending down.
Why it matters
Boards and insurers don't read CVSS - they read dollars and "could we be breached?". The Exposure report:
- prioritises by money at risk, not raw count;
- backs each number with proof (a confirmed finding / attack path), not a hypothetical;
- gives the actuarial view for cyber-insurance conversations.
Pair it with Scorecards for the per-team grade and the Posture score for the 0-100 program metric.