Product walkthrough · 3:44

    Risks and Gaps: Understand Exposure and What Needs to Improve

    Explore risk and gap KPIs, heatmaps, maturity comparisons and supporting evidence. Follow a temporary-access finding and see how AI pattern analysis helps reviewers connect related weaknesses.

    Published . Demonstration uses test data.

    Video transcript

    Before the quarterly security review, the team needs to explain a finding: temporary administrator access may remain active after the work ends. How serious is the exposure—and what needs to change?

    In AssessX, risks explain what could go wrong. Gaps explain which practices fall short. Let's follow this finding through both views. Start with Risk Assessment. The summary shows active risks,

    critical findings, unmitigated exposure and overdue work. The severity breakdown helps the team see the mix. Appetite and tolerance highlight exposure above the limits configured for this organisation. These figures cover the wider register.

    The domain heatmap shows where risks are concentrated. Switch to the classic view to compare likelihood and impact, then open a populated cell to inspect its findings.

    The radar lets you explore a domain and its subdomains. The domain bars offer another way to compare the distribution.

    The trend chart groups newly identified risks by period. Here, the data covers September; it does not yet show a longer-term trend or prove that controls have improved.

    Now open the temporary-access risk. Its likelihood and impact are both three. Together, they produce a score of nine—above this organisation’s appetite of eight. The description explains why: the sampled request has no

    expiry date or evidence of a later review. The mitigation view sets out the response: require an expiry time, revoke access automatically and monitor exceptions. Context connects the finding to its assessment, while History

    records changes. That explains the exposure. Gap Analysis shows the practice that needs improvement. Its summary highlights active and critical gaps, unresolved work and findings citing framework controls.

    A zero here does not establish compliance. The maturity shortfall summarises the distance between assessed practice and target maturity. The gap heatmap maps severity across domains and capabilities.

    Expand it to read the labels and compare the relevant capabilities. The maturity radar compares current and target levels, with cards that make the difference explicit. You can drill

    into the underlying subdomain and capability. A domain marked Not Assessed has no established baseline—it does not mean there are no weaknesses. The capability bars compare concentrations.

    The trend view shows when gaps were identified, with severity and domain groupings. For this finding, current maturity is two and the target is four: a shortfall of two.

    Context makes that difference tangible. The expected practice requires start and end times for temporary access. The actual finding shows that duration was optional and the sampled ticket lacked an expiry date.

    Remediation describes the improvement, its effort and priority, with an owner and due date. The team can inspect the evidence and review the change history.

    Now select the assessment campaign for AI pattern analysis, so the review uses this assessment’s findings. Across its four risks, AI connects the approval, provisioning, emergency-access and expiry weaknesses.

    One recommendation is to require start and end times and enforce automatic revocation. Across the four gaps, it identifies fragmented audit evidence and unstructured workflows.

    A proposed cause points to optional duration fields and incomplete requests. These are findings to review, not automatic fixes. The team checks the reasoning against its evidence. Saved analysis

    history preserves the result for later review. The team can now explain the exposure, the missing practice and the evidence behind both—and share the findings for follow-up.

    Thanks for watching. Explore more AssessX features, or book a demo with our team.