Security Reports
Reports are produced by the
Draft board-pack and
Export 90d trend buttons
on the Board Metrics card below.
📊 Board Metrics — outcomes, not activity
The six numbers the board cares about. Alerts-per-day is activity. These tell you whether money is buying outcome.
MTTD · Mean Time To Detect (T390)
—
first signal → correlator-confirmed incident · industry median 7 d · target < 1 h
computing from Decision Ledger…
MTTR · Mean Time To Respond (T391)
—
alert → investigation closed · L1 auto-contain · L2/L3 human decision
computing from Decision Ledger…
Dwell Time (T392)
—
incident lifespan from first to last correlated event · industry median 11 d · elite < 24 h
computing from Decision Ledger…
Blast Radius (T393)
—
avg count of correlated events per confirmed incident · segmentation score
computing from Decision Ledger…
ATT&CK Coverage % (T394)
82%
of 213 relevant sub-techniques with a working detection tested in last 90 d
↑ 14 pts this quarter · gap-close in Defense Evasion (69%) + Discovery (67%)
Phishing Click-Rate + Report-Rate (T395)
2.4% click · 34% report
culture metric · target click < 3% · target report > 30% · trend 12 wk
Click-rate2.4%
Report-rate34%
both improving · finance cohort exemplary
Edge Patch SLA Compliance (T396)
96%
internet-facing critical CVE → patched or virtual-patched < 24 h · exception rate · longest-open counter
Met SLA96%
Exceptions4%
Longest open3 d
1 exception · legacy-VPN decommission window
Analyst Throughput Δ — before → after copilot (T397)
3.1×
actioned alerts per analyst per day · the productivity story for the board · cost-justifies the AI investment
Pre-copilot18 / d
With copilot56 / d
$ / actioned alert ↓ 68% · quality (TP rate) held at 92%
Dashboard Outcome Tiles + NOC Ticker (T398)
ON
dashboard.html shows the 8 metrics above + a live incident ticker · full-screen mode for NOC display
- • Outcome tiles replace the old activity-counters
- • NOC full-screen mode on
?noc=1 - • Live incident ticker streams from secops graph
- • Auto-refresh every 15 s · mute on blur to save tokens
Auto-PDF Monthly Board Report (T399)
SCHEDULED
copilot-drafted (T264) · human-edited · signed · timestamped · emailed to board-distro 1st of month
- • Pulls the 8 board metrics + trend
- • Top-3 incidents narrative + remediation status
- • Roadmap progress (build-order checklist)
- • Signed + notarised in evidence vault (7y)
- • Board-distro attests receipt for audit trail
📋
No reports yet
Generate a board-pack from the controls above. Every figure in it is sourced from the immutable Decision Ledger.