Uncover Trends and Show AppSec Value with the Endor Labs Dashboard
Vulnerability metrics can help you uncover remediation and SLA trends, and demonstrate the value of AppSec investments to your leadership.
Vulnerability metrics can help you uncover remediation and SLA trends, and demonstrate the value of AppSec investments to your leadership.
Vulnerability metrics can help you uncover remediation and SLA trends, and demonstrate the value of AppSec investments to your leadership.
Vulnerability metrics can help you uncover remediation and SLA trends, and demonstrate the value of AppSec investments to your leadership.
Vulnerability metrics can help you uncover remediation and SLA trends, and demonstrate the value of AppSec investments to your leadership.
Customers use Endor Labs for insights and evidence about their vulnerability management programs. For example, Grip Security uses Endor Labs to answer security questionnaires, maintain compliance, and inform their Trust Center. They can quickly and accurately report on risk — answering questions like “Are we exceeding our SLAs for criticals and highs” and “Are we efficiently resolving risk without a lot of friction.”
While the Vulnerability Prioritization Funnel and Findings page make it easy to get these answers, we knew we could make it even easier by centralizing important information in an analytics dashboard. We wanted to arm teams with the data-driven insights they need to not only identify vulnerabilities, but also tell a compelling story about security progress over time.
We heard from customers that they didn’t just want to know the status of their current critical vulnerabilities—they wanted tangible evidence that their remediation efforts were paying off. They needed to showcase month-over-month improvement, highlight how certain shifts in process or technology led to a measurable dip in open issues, and prove to the business that their AppSec investments were bearing fruit. Our new dashboard helps them do exactly that.
Let’s explore some key highlights.
The vulnerabilities snapshot: A 90-day progress report
Right at the top, the new Vulnerabilities Snapshot delivers instant perspective on your security posture. In one quick glance, you’ll see:
- Newly Discovered Vulnerabilities: For example, 1 million identified in the last 90 days.
- Resolved Vulnerabilities: 4.4k remediated, showing not just what you’re finding, but whether things are getting fixed.
You can also filter the entire dashboard based on what you care about. By default, we see all vulnerabilities, regardless of severity or reachability. Instead of asking “How many total vulnerabilities did we find, and how many of them did we fix?”, we can apply a filter to ask “How many critical or high, function-reachable, fixable, vulnerabilities did we find in direct or transitive dependencies in the last 90 days, and how many of them did we fix?”
This snapshot isn’t just a static number—it’s a performance gauge. If your team is remediating as fast as issues appear, you’re on the right track. If the gap widens, it’s time to dig deeper.
We also added time-to-fix metrics, including:
- Mean Time to Remediate (MTTR) For instance, 30 days, indicating how quickly you’re addressing vulnerabilities across the board.
- Minimum Time to Remediate: For instance, 3 days, illustrating your team’s fastest fix time.
- Maximum Time to Remediate: For instance, 57 days, highlighting potential bottlenecks or lengthy delays that warrant immediate attention.
By comparing what’s discovered to what’s resolved—and how long it’s taking—you gain a clear read on the health and efficiency of your AppSec processes.
Trends over time: Explain your AppSec story to the business
At the heart of the new dashboard is the Vulnerabilities Over Time visualization, the crown jewel for teams who need more than just a point-in-time snapshot. Toggle this chart between Newly Discovered (when and how often new issues appear) and Resolved (how many got fixed). Sudden spikes might correlate with a code deployment, a new package introduction, or architectural changes.
For the customers who worked with us on this, this is the missing piece of the puzzle. They can now say, “Look, last month we had 14 critical vulnerabilities, and now we’ve driven that number down. Here’s the trend line to prove it.” This chart transforms raw data into a narrative that speaks to stakeholders at every level—from developers on the front lines to executives investing in AppSec tools.
Mean Time to Remediate (MTTR)
MTTR, by nature, is a metric that only has meaning over time. In this dashboard you can see how many vulnerabilities are being resolved over whatever time period is important to you. This allows you to directly connect initiatives—like switching scanning tools, implementing better developer training, or refining your triage processes—to tangible improvements in remediation speed.
SLA compliance: Don’t let vulnerabilities slip through the cracks
Whether you’re being held to business or customer SLAs, the New Open Vulnerabilities Approaching SLA panel ensures that no critical issue slips through the cracks unnoticed.
We break down vulnerabilities by severity and track how close each one is to breaching your SLA (editable to your needs). If you’ve got 34 critical issues nearing their 30-day mark, you know exactly where to focus your immediate attention.
This view isn’t just about metrics—it’s about compliance and continuous monitoring. Whether you’re aligning with FedRAMP or other regulatory frameworks, these insights help you stay ahead of deadlines, and get ahead of potential violations.
Build your AppSec narrative
From telling a compelling story that can influence internal stakeholders to ensuring you remain on top of SLA deadlines, the new Endor Labs dashboard transforms vulnerability data into meaningful insights and action items.
Our customers have asked for these deeper metrics—progress over time, ability to highlight successful remediation efforts, and clear indicators of compliance—and we’ve answered. With every new release, our goal is simple: give you the tools you need to run a more effective, transparent, and forward-looking AppSec program.
Book a demo to understand how Endor Labs turns your vulnerability prioritization workflows dreams into reality.