Walk the security state yourself.
Seeded demo data, real product logic. Nothing here connects to a live tenant.
- 1 See the overall security state
- 2 Click a domain
- 3 Open a material cross-domain exposure
- 4 Ask SIA why it matters
- 5 See the underlying technical findings
- 6 Switch to Technical view
- 7 Choose a remediation route
- 8 Send the exposure to a Defender
- 9 Switch to a framework lens
Executive path
Start where a CISO starts: the state of the environment.
Overall state, six connected domains, material exposures across them, SIA explanation, and the switch to the technical evidence whenever you want it.
Security state
CONTROLLED, WITH EXPOSURE
72 / 100
+4 this monthYour environment improved this month, but three material exposures remain. Identity is stable. Data protection needs attention. AI adoption introduced two new governance gaps.
The score is a summary, not the truth. Material exposures below decide what actually happens next.
- 3material exposures
- 12risks being remediated
- 4new risks this month
- 17risks resolved
- 6configuration drifts
- 2emerging AI risks
- 1expert engagement active
Environment model
Select a domainSix domains, one connected model. Lines are real dependencies — the paths risk travels along.
Identities
Strong authentication, privileged access has 2 gaps
Material exposures
- 2 privileged identities sit outside the intended just-in-time access model
- Break-glass accounts are not covered by an alerting rule
What changed recently
- Number matching enforced for all Authenticator users (11 days ago)
- 1 new Global Administrator assigned outside change window (3 days ago)
- Affected assets
- 1,840 identities · 9 privileged accounts
- Ownership
- Identity team · M. Bakker
- Business impact
- A single standing administrator compromise would give full tenant control.
- Recommended next action
- Convert 2 standing administrators to PIM-eligible with approval.
What changed since your last visit
Material exposures
Risk that spans domains. Not a list of failed checks — a prioritized executive backlog.
SIA executive brief
What should I care about today?
Three developments deserve your attention. External data exposure increased after a SharePoint configuration change. Two privileged identities remain outside your target access model. Copilot usage increased while AI data controls remain incomplete.
Defender engagements
- Purview remediation60%
Defender engaged · Data
- Identity exposure cluster20%
Scoping with Defender · Identities
One security state. Multiple compliance lenses.
The same underlying exposure can affect CIS, NIS2 / CBW, BIO and NEN 7510 at once. Frameworks are evidence on top of the state, not the starting point.
All figures on this page are seeded demo data for illustration.