Cap 1
Exposure trend over time
Validated exposure, mitigated exposure and remediation throughput by month, business unit and asset class.
CTEM Lifecycle · 05
Zafran gives CISOs a board-ready exposure map and gives operators the SLA, MTTR and trend analytics behind it. Every number carries its validation evidence and timestamp, so reports are audit-ready without a spreadsheet exercise.
Capabilities
Board-ready exposure reporting with validation evidence, SLA tracking and trend analytics.
Cap 1
Validated exposure, mitigated exposure and remediation throughput by month, business unit and asset class.
Cap 2
Where exploitable exposure sits across the business and how much is already covered by controls.
Cap 3
SLA adherence, mean time to mitigate and mean time to remediate by team and severity.
Cap 4
Each closed exposure lists what was validated, which control or patch resolved it, by whom and when.
Workflow
Validation results, mitigations and remediation tickets are timestamped in the Exposure Graph automatically.
Exposure aggregates by business unit, asset criticality and owner, not by scanner.
Board views, auditor evidence packs and operator dashboards come from the same data.
Compare
Zafran runs the whole lifecycle on one Exposure Graph; alternatives cover a slice of it.
| Capability | Zafran | Spreadsheet & BI reporting | Scanner-native dashboards |
|---|---|---|---|
| Reports validated exploitability, not raw CVE counts | |||
| Evidence and timestamps per closed exposure | |||
| SLA and MTTR by owner and business unit | |||
| Includes mitigations via existing controls | |||
| Cross-scanner, cross-cloud rollups | |||
| Board-ready output without manual assembly |
Proof
“Zafran lets us evaluate the effectiveness and ROI of our security stack against what is actually exploitable.”
Case study · Insurance
Read how the team ran this stage of the lifecycle with Zafran.
FAQ
Validated exploitable exposure by business unit, how much of it is already mitigated by existing controls, trend over time, and SLA performance. Zafran produces this view directly from the Exposure Graph rather than from exported CVE counts.
Each validated exposure gets an SLA based on exploitability and asset criticality. Zafran measures time to mitigate and time to remediate against it, and reports adherence and aging by owner, team and severity.
For every closed exposure: the validation result, the control or patch that resolved it, the approver, and timestamps. Evidence exports as an audit pack without manual assembly.
Yes. Exposures closed by compensating controls are reported alongside patched ones, with residual risk shown separately, so the board sees real exposure reduction rather than patch counts.
Scanner dashboards count their own findings; BI tools need someone to merge and maintain exports. Zafran reports on de-duplicated, validated exposure across every source, with the evidence attached.
Prioritize and fix what is truly exploitable using risk context from your existing security tools.