Skip to content

Analytics

Analytics is the reporting surface that reads across every module at once. Instead of opening each list and counting rows, you get control implementation, risk exposure, audit progress and operational load as charts and counters on a single page — and every counter is a link, so a number you do not like takes you straight to the filtered list behind it.

Overview → Analytics in the sidebar.

The page is organized as six tabs. The active tab is kept in the URL, so a link to a particular view survives a refresh and can be shared or bookmarked.

TabWhat it answers
SummaryWhere does the whole programme stand today?
GovernanceHow much structure and oversight exists, and what is moving?
RiskHow exposed are we, before and after treatment?
ComplianceHow far through each audit are we?
OperationsWhat is the day-to-day load — tasks, findings, incidents?
CustomWhatever you chose to put there

The Controls block counts your applied controls by state — Total, Active, Degraded, Deprecated, To do, In progress and On hold — and highlights the two numbers that usually need action: P1 controls still outstanding, and controls whose ETA has passed. Beside it, a radial chart distributes your reference controls across the CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), which is the fastest way to spot a function you have barely covered.

Below that, compliance and audit blocks show frameworks in use, audits and their progress, and recently updated audits. The risk block counts assessments, scenarios, mapped threats and accepted risks, with half-donut charts comparing current and residual risk levels.

Governance, Risk, Compliance and Operations

Section titled “Governance, Risk, Compliance and Operations”

Governance counts domains, frameworks, applied controls, policies, security exceptions and risk acceptances, and adds assessments per status, an activity calendar, an applied-control status breakdown, the follow-up distribution and the security exception flow.

Risk draws a treemap of the Threats breakdown across your scenarios — empty until somebody attaches threats to scenarios — plus qualification counts, donut charts for Inherent, Current and Residual risk level per scenario, and a vulnerability distribution.

Compliance shows per-audit progress bars and average progress, colour-coded by result so a non-compliant area is visible without opening the audit; View detailed recap jumps to the cross-audit recap.

Operations covers applied control distribution, task status, findings breakdown and the incident summary — total, this month, open, severity, monthly metrics and detection breakdown.

The Custom tab embeds one dashboard you have built yourself. Administrators pick it from the dashboard name at the top of the tab, and Clear default empties the tab again. The choice is instance-wide rather than per user, so pick a dashboard whose domain your audience can actually reach. See Dashboards and metrics.

Comparing risk assessments with the composer

Section titled “Comparing risk assessments with the composer”

The composer overlays several risk assessments into one comparative view: Current risk level per risk scenario, Residual risk level per risk scenario and Status of associated measures, side by side, for whatever selection you processed. It also reports inconsistencies found across the selection. The resulting page is driven entirely by the URL, so it can be bookmarked and revisited as the assessments evolve.

Extra → Experimental → Analytics Export produces the whole dashboard as a multi-sheet Excel workbook — Summary, Risk Levels, Compliance, Controls and Incidents — ready to drop into a reporting tool or a board pack. Use Export as Excel to download it.

Two modules ship their own overview rather than sharing this one:

  • Third parties → Overview shows one card per entity assessment, grouped by domain, so vendor questionnaire progress reads at a glance. See Third parties.
  • Privacy → Overview counts personal data categories identified, documented processings, data recipients, open right requests and open data breaches, with breakdowns by type and a data flow overview. See Privacy.