About the Remediation Performance Report
The Remediation Performance report presents remediation KPIs such as MTTR (Mean Time to Remediation), average daily remediated/introduced vulnerabilities, campaign coverage stats, remediation across business groups, MTTR stats, and more. The report generates a wide perspective on the remediation workload capacity in your organization so you can better evaluate and estimate your remediation pace and performance. Use the "Filters" pane on the right to focus your report, click on a specific data element to filter the entire report or to access more data, and hover over a widget for more actions and info.
Before you dive in
First, make sure you cover the Reports (Analytics) Filters and Data Drilling to learn about the expected behavior of the trends and presented data.
KPIs
The Remediation KPIs are the first and main widgets you encounter when entering the Remediation Performance report.
What does each KPI represent?
KPI | Description | What to strive for? |
MTTR in Days | "Mean Time To Remediate" is an industry-standard KPI used to refer to remediation progress. In this context, it represents the average time in days it takes to remediate findings (instances). The days count starts when the vulnerability is "first seen" in Vulcan Cyber ExposureOS, and sometimes the in the connector when we receive this data, and ends when remediation is completed. | The lower the MTTR is, the better your organization is doing regarding the time it takes to remediate vulnerabilities. |
Average Daily Remediation | Average count of remediated findings (instances) of the selected period. | Strive for a higher number, as it means more findings (instances) are being remediated. |
Remediation Capacity Current | The daily average number of remediated findings (instances) divided by the average number of newly introduced findings (instances) of the selected period = percentage of average daily remediation | Strive for remediating 100%+ of the introduced findings (instances). If there are 1,000 newly introduced findings (instances) at any given day and you remediate 800 findings (instances), your workload remediation capacity is 80% (800/100=0.8).
|
Campaign Coverage | Percentage of findings (instances) in remediation campaigns (in open tickets) out of all existing findings (instances) | Strive for a higher % as it means more findings (instances) are in remediation campaigns. |
Widgets and trends
Campaign Coverage over time
Percentage of findings (instances) with remediation campaigns over time by Risk Level. You should strive to have Critical/High-risk vulnerabilities in remediation campaigns.
Click a Risk level to better highlight the trend in the graph
Filter to focus on specific Risk level
Use the data-drilling buttons to dig deeper into the data
Using the "Has Campaign" filter
We've also added a special filter called "Has Campaign" to help you view data only on findings (instances) covered by campaigns. In the example below, we use the "Has Campaign" filter and the Risk Level filter to show valuable data, such as MTTR, only on High Risk Level findings (instances) covered by campaigns.
Average Daily Remediation by Business Group
Count of average daily remediation by business groups and how their rank shifts (Current vs. Previous Rank). The more remediations done on findings (instances) in a Business Group, the higher the rank climbs for that Business Group.
Strive for a higher remediation count for the Business Groups with the most critical impact.
MTTR by Business Group
"Mean Time To Remediate" is an industry-standard KPI used to refer to remediation progress. In this context, it represents the average time in days it takes to remediate findings (instances) per Business Group. The days count starts when the vulnerability is "first seen" in Vulcan Cyber ExposureOS, and sometimes the in the connector when we receive this data, and ends when remediation is completed.
The lower the MTTR, the better the Business Group is doing regarding the time it takes to remediate vulnerabilities. High MTTR indicates that the findings (instances) in this Business Group take the most time to remediate.
MTTR over time
Count of MTTR in days over time. This graph shows how the "Mean Time to Remediation" changes over time. Lower MTTR indicates faster remediation. You can use the data-drilling buttons to drill up and down.
MTTR by Risk Level
"Mean Time To Remediate" is an industry-standard KPI used to refer to remediation progress. In this context, it represents the average time in days it takes to remediate findings (instances), distributed by Risk Level. The days count starts when the vulnerability is "first seen" in Vulcan Cyber ExposureOS, sometimes the in the connector when we receive this data, and ends when remediation is completed.
Strive to keep your MTTR as low as possible, particularly on High and Critical risk level. Lower MTTR indicates faster remediation.
Tip: Click on a severity level to present more focused data across the other MTTRs.
MTTR by Risk (focused view).
MTTR by Asset Type
"Mean Time To Remediate" is an industry-standard KPI used to refer to remediation progress. In this context, it represents the average time in days it takes to remediate findings (instances), distributed by Asset Type. The days count starts when the vulnerability is "first seen" in Vulcan Cyber ExposureOS, and sometimes the in the connector when we receive this data, and ends when remediation is completed.
Strive to keep your MTTR as low as possible, particularly on asset types of most interest and impact (Such as AppSec assets, i.e., Code Projects and Websites).
Campaign vs. No Campaign MTTR
An insight into the MTTR difference between findings (instances) with campaigns and those without. Campaigns lower the MTTR of the organization and significantly increase remediation.
Cumulative Remediation
Count of newly introduced findings (instances) (i.e., newly identified by the Vulcan Cyber ExposureOS platform) vs. remediated findings (instances) with and without campaigns. The delta between newly introduced and remediated vulnerabilities shows the remediation program's capacity versus its workload. If there are consistently more new campaigns than remediated, the workload exceeds the available capacity.
Remediation Capacity by Risk Level
Percentage of remediation capacity (Remediated / Introduced = capacity) per Risk Level. The percentage shows the remediation program's capacity dedicated to each risk level.
Remediated Capacity by Asset Type
Percentage of remediation capacity (Remediated / Introduced = capacity) per Asset Type. The percentage shows the remediation program's capacity dedicated to each asset type.
Reports (Analytics) FAQ and Data Validation
Read our Reports (Analytics) FAQ and Data Validation article here.