Custom · 6 sections
Choose and order sections
In this report
Choosing and ordering sections is part of the free assessment. The shape travels in the address, so it survives a reload and can be bookmarked; nothing is stored. A link to your own report still needs your session — a report link somebody else can open is not built yet.
1Where the gaps are
170 gaps in total, 95 of them critical or high.
| Severity | Control | Where | What is wrong |
|---|---|---|---|
| critical | Authenticated Dynamic Scan | Production · CI Pipeline | nothing covers it |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Periodic Penetration Test | Production · Manual Review | expected runs automatically, actual run by hand |
| critical | Vulnerable Dependency Gate | Production · Java · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Java · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · Spring Boot · Release Gate | nothing covers it |
| critical | Vulnerable Dependency Gate | Production · React · CI Pipeline | expected blocking, actual a warning |
| critical | Vulnerable Dependency Gate | Production · React · Release Gate | nothing covers it |
| critical | Admission Policy Enforcement | Production · Kubernetes · Admission | nothing covers it |
| critical | IaC Misconfiguration Detection | Production · Helm · Pull Request | it runs elsewhere, but not for this technology |
| critical | IaC Misconfiguration Detection | Production · Helm · CI Pipeline | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Continuous Scan | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Terraform · Runtime | it runs elsewhere, but not for this technology |
| critical | Infrastructure Drift Detection | Production · Azure · Continuous Scan | it runs elsewhere, but not for this technology |
The remaining 80 critical or high gaps are in the CSV export.
2Across the lifecycle
The same scope cells, grouped by where in the delivery lifecycle they are demanded. A phase with nothing required is not a failing phase.
| Phase | Coverage | Open gaps |
|---|---|---|
| Plan | 0% | 1 |
| Design | 67% | 1 |
| Code | 78% | 10 |
| Build | 89% | 6 |
| Test | 14% | 15 |
| Release | 0% | 12 |
| Deploy | 29% | 21 |
| Operate | 38% | 58 |
| Monitor / Respond | 32% | 7 |
3Coverage by capability
Every capability the profile required, with the share of its scopes that something covers and the maturity of what covers them.
| Capability | Coverage | Maturity | Open gaps |
|---|---|---|---|
| API Security Testing | 0% | 0 | 9 |
| Fuzzing | 0% | 0 | 4 |
| Kubernetes Security | 0% | 0 | 9 |
| Runtime Security | 0% | 0 | 12 |
| Security Requirements | 0% | 0 | 1 |
| DAST | 7% | 0.1 | 8 |
| Vulnerability Scanning | 17% | 0.3 | 25 |
| Penetration Testing | 29% | 0.3 | 7 |
| Admission Control | 33% | 0.7 | 3 |
| Network Security | 33% | 0.7 | 12 |
| Drift Detection | 50% | 1 | 12 |
| IaC Security | 50% | 1 | 6 |
| Threat Modeling | 50% | 0.5 | 1 |
| Secrets Management | 60% | 1.2 | 2 |
| Cloud Configuration Security | 67% | 1.3 | 2 |
| Code Review Security | 67% | 0.7 | 1 |
| Secret Scanning | 67% | 2.7 | 1 |
| SIEM | 67% | 1.3 | 1 |
| Workload Identity | 67% | 1.3 | 6 |
| SCA | 73% | 1.5 | 9 |
| Container Security | 100% | 4 | 0 |
| Incident Response | 100% | 1 | 0 |
| SAST | 100% | 3.2 | 0 |
| Secure Architecture | 100% | 1 | 0 |
| Vulnerability Management | 100% | 2 | 0 |
4What was assessed
Web application, API, Critical criticality, internet-facing, holds personal data, holds financial data. Built from 11 technologies across 3 environments.
No scanner was connected and no repository was read. Everything below is derived from the answers given in the assessment.
5The three numbers
Coverage
47%
Effectiveness
61%
Maturity
1.0 / 5 (Available)
198 covered221 not covered
- Coverage
- 198 of 419 weighted scopes are covered by something. 250 scopes were required in total.
- Effectiveness
- How much those controls actually do. 35% of this score could not be assessed, because evidence collection and ownership are not part of this release; those components were excluded rather than guessed.
- Maturity
- Averaged over everything the profile requires, with uncovered scope counting as level 0. Coverage and maturity move independently: a control can run everywhere and still be an immature process.
6Recommended next improvements
- 1. Introduce Known Vulnerability ScanCoverage impact +7.2 % · risk reduction critical · closes 15 scopes
- 2. Introduce Vulnerable Dependency GateCoverage impact +6.4 % · risk reduction critical · closes 9 scopes
- 3. Extend Infrastructure Drift Detection to the rest of your stackCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 3. Introduce Runtime Threat DetectionCoverage impact +5.7 % · risk reduction critical · closes 12 scopes
- 5. Extend Known Vulnerability Scan to every environmentCoverage impact +4.8 % · risk reduction high · closes 10 scopes
At most 5 improvements are ranked here, by what each would move. This is the top of the list, not the whole work list — everything still open is in the CSV export.

