Case Study - Operational Intelligence (Are We Actually Getting Safer?)

Quarter after quarter, same XSS, same S3, same OTP. Trends proved it wasn’t bad luck — it was the template.

ILLUSTRATION — POSTURE TREND (EXAMPLE)
Q1
48
Q2
31
Q3
17
−65% open criticals

Recurring-issue rate · exposure delta · MTTR · SLA adherence — per unit, per quarter

Client Context

Telco group — 5 subsidiaries, 3 years of pentests, C-level question: “spending up, are we safer?” No trend data — only per-engagement PDFs.

Challenge

Analyze vulnerability trends, recurring issues, security posture, and exposure change over time — turning point-in-time results into operational intelligence leadership can steer by.

Scope - Snipeyes Operational Intelligence

  • Normalized history: 3 years of findings deduplicated into recurring-issue taxonomy (auth, injection, config, secrets, patching)
  • Posture metrics: open criticals/high by age, exposure delta, MTTR/MTTR-by-unit, SLA adherence, retest pass rate
  • Recurrence analysis: which teams/templates/repo patterns reintroduce the same class
  • Output: security trends & posture pack — quarterly + live dashboard

Key Findings (redacted)

  • 71% of Q1–Q2 findings were repeats of 5 root causes: shared login template (XSS), base AMI (patch lag), copy-paste S3 policy, OTP library default, vendor VPN template
  • 1 subsidiary produced 52% of criticals with 18% of assets — coaching target identified
  • Exposure grew 22% (promo microsites) while vuln count fell — net risk flat, invisible without exposure-adjusted posture

Outcome

  • 5 template fixes killed the repeat classes — recurrence 71% → 9% in two quarters; open criticals −65%
  • Subsidiary scorecard published internally (healthy competition, no blame); worst-to-first story in one quarter
  • Board KPI now: exposure-adjusted posture + recurrence rate, not raw counts

Relevance for you: If every quarter feels like déjà vu — measure recurrence, fix templates.