🛡️

Cyber Security Command Centre

Live
Last refreshed: 04 Aug 2026 · 08:42 UTC
68 / 100

Overall Cyber Health

Composite score across all
5 platforms & controls

⚠ Needs Attention
Critical Vulnerabilities
47
Unpatched · Tenable
▲ +12 this week
Active Threats
9
Open incidents · SentinelOne
↔ Same as last week
M365 Secure Score
61%
Target: 80% · Microsoft
▼ −3 pts regression this week
Industry Benchmark Rank
42nd
Percentile · Consulting sector
▲ Up from 38th last quarter
Vulnerability Exposure Tenable
47
Critical
119
High
284
Medium
531
Low
12
Exploitable
in the wild
31
Patch available
>30 days
8
Resurfaced
last 7 days
3.2d
Avg MTTD
critical
Critical vulnerabilities — 8-week trend
Jun 9Jun 23Jul 7Today
Active Threat Feed SentinelOne
48m
MTTR
Avg response time
✓ Below industry avg
4.2h
MTTD
Avg detection time
⚠ Industry avg: 2.8h
94%
EDR Coverage
Endpoints protected
⚠ Target: 100%
Open Incidents
Credential Dumping — Finance workstation (WS-FIN-07)
LSASS memory access · Isolated · Under investigation
T1003 2h ago
Lateral Movement — SRV-AD-02
SMB brute-force from internal IP 10.1.4.88
T1021 5h ago
Suspicious PowerShell — DEV-LAPTOP-12
Encoded command execution, C2 callback attempt blocked
T1059.001 12h ago
Ransomware Behaviour — SRV-FILE-01
Mass file encryption pattern · Quarantined automatically
T1486 1d ago
Suspicious Login Anomaly — 4 M365 accounts
Logins from new geography (Eastern Europe)
T1078 1d ago

Platform Scorecards

5 integrated platforms
Cyber Exposure72/100
Assets scanned1,842
Scan coverage87%
Avg patch lag (critical)18 days
Recurring vulns34
Hygiene Score74/100
Total known assets2,104
Shadow IT found+231 new
MFA enabled79%
Unpatched >30d148 devices
Protection Score79/100
EDR agent coverage94%
Threats blocked (30d)1,247
False positive rate1.2%
MITRE ATT&CK coverage76%
Secure Score61%
MFA adoption81%
Conditional access rules12 / 24
Risky sign-ins (30d)47
DLP policies active3 / 8
Secure Score58%
Resources assessed634
High severity alerts23
Internet-exposed assets19
Workload protection71%
How We Compare — Consulting Sector 340+ peer firms
Overall Cyber Score
68/73 avg
M365 Secure Score
61%/70% avg
EDR Coverage
94%/88% avg
MTTR
0.8h/4h avg
Patch Lag (critical)
18d/11d avg
MFA Adoption
79%/85% avg
Cyber Hygiene
74/77 avg
Us (bar) Consulting industry avg (line)
Hygiene & Compliance Posture ThreatAwareAzure
75%
Patch Currency
79%
MFA Coverage
71%
Cloud Coverage
60%
DLP Active
Regulatory Compliance
ISO 27001
82%
PCI DSS v4
67%
CIS Benchmark
71%
NIST CSF 2.0
64%
⚠ 231 previously unknown assets discovered by ThreatAware
11% of your estate was invisible to Tenable & SentinelOne. These devices have zero security controls — no scanning, no EDR agent.

Priority Fix-It List

Ranked by risk reduction impact
Cross-platform · Updated daily
#1
Patch 12 actively-exploited critical vulnerabilities now
Tenable flags 12 CVEs with confirmed in-the-wild exploitation. Average patch lag for these is 22 days — each unpatched day meaningfully raises breach probability. These should be treated as a P1 incident, not a scheduled patch cycle.
Tenable Effort: Medium — patching sprint Owner: IT Ops
▲ +8 pts score
#2
Enforce MFA on remaining 21% of M365 accounts (~440 users)
M365 Secure Score analysis shows this single action adds 9 points. Consulting sector average is 85% — closing this gap lifts your benchmark rank from 42nd to ~55th percentile. Can be done today with a Conditional Access policy update.
M365 ThreatAware Effort: Low — policy change Owner: Identity Team
▲ +9 pts score
#3
Onboard 231 shadow IT assets into Tenable & SentinelOne
ThreatAware found 231 devices invisible to your other tools — no vulnerability scanning, no EDR, no security controls at all. These are your biggest blind spot and explain the 6% EDR coverage gap SentinelOne shows. Deploy agents this sprint.
ThreatAware SentinelOne Effort: Medium — agent deployment Owner: IT Ops + Security
▲ +7 pts score
#4
Activate remaining 12 M365 Conditional Access policies
Only half of recommended Conditional Access rules are live. Missing policies include device compliance checks and risky sign-in blocking. The 47 risky sign-ins last month could be cut ~80% by enabling these today — one of which links to the M365 anomaly SentinelOne flagged.
M365 Effort: Low — policy activation Owner: Identity Team
▲ +5 pts score
#5
Remove or protect 19 internet-exposed Azure resources
Azure Defender flags 19 resources with unnecessary public internet exposure — including misconfigured storage accounts and VMs with public IPs. Each is a direct attack path into your cloud environment, directly correlated with the threat activity SentinelOne is detecting.
Azure Defender Effort: Medium — network config review Owner: Cloud Team
▲ +6 pts score
#6
Enable 5 remaining M365 Data Loss Prevention policies
Only 3 of 8 DLP policies are active. As a consulting firm handling client data, this is a direct ISO 27001 and PCI DSS compliance gap. Enabling these protects data in SharePoint, Teams, and Exchange and improves your compliance scores immediately.
M365 Effort: Medium — policy config & testing Owner: Compliance + IT
▲ +4 pts score
#7
Investigate 34 recurring vulnerabilities to break the patch loop
34 vulnerabilities keep coming back after patching — caused by image-baked vulns, configuration drift, or failed patches. Root cause analysis will break this cycle and lift patch success rate from ~82% to 95%+, saving significant re-work each sprint.
Tenable Effort: High — root cause investigation Owner: IT Ops + Engineering
▲ +3 pts score