Case Study - Operational Intelligence (Are We Actually Getting Safer?)
Quarter after quarter, same XSS, same S3, same OTP. Trends proved it wasn’t bad luck — it was the template.
48
31
17
Recurring-issue rate · exposure delta · MTTR · SLA adherence — per unit, per quarter
Client Context
Telco group — 5 subsidiaries, 3 years of pentests, C-level question: “spending up, are we safer?” No trend data — only per-engagement PDFs.
Challenge
Analyze vulnerability trends, recurring issues, security posture, and exposure change over time — turning point-in-time results into operational intelligence leadership can steer by.
Scope - Snipeyes Operational Intelligence
- Normalized history: 3 years of findings deduplicated into recurring-issue taxonomy (auth, injection, config, secrets, patching)
- Posture metrics: open criticals/high by age, exposure delta, MTTR/MTTR-by-unit, SLA adherence, retest pass rate
- Recurrence analysis: which teams/templates/repo patterns reintroduce the same class
- Output: security trends & posture pack — quarterly + live dashboard
Key Findings (redacted)
- 71% of Q1–Q2 findings were repeats of 5 root causes: shared login template (XSS), base AMI (patch lag), copy-paste S3 policy, OTP library default, vendor VPN template
- 1 subsidiary produced 52% of criticals with 18% of assets — coaching target identified
- Exposure grew 22% (promo microsites) while vuln count fell — net risk flat, invisible without exposure-adjusted posture
Outcome
- 5 template fixes killed the repeat classes — recurrence 71% → 9% in two quarters; open criticals −65%
- Subsidiary scorecard published internally (healthy competition, no blame); worst-to-first story in one quarter
- Board KPI now: exposure-adjusted posture + recurrence rate, not raw counts
Relevance for you: If every quarter feels like déjà vu — measure recurrence, fix templates.