Solutions · CyberSec · Prove
Know what you cannot see.
Coverage Assurance measures what your security tools and telemetry actually observe across your estate, and treats every blind spot as a finding with a cause, an effect and the action that closes it.
More of your estate observed, and every blind spot on a list.
- More of each domain observed. Measured by VCR, Visibility Coverage Rate.
- Fewer open coverage gaps. Measured by open coverage gaps.
- Fewer unobserved segments on paths to your crown jewels. Measured by UNKNOWN segments on crown-jewel paths.
Supporting KPIs
Coverage per domain ↑
Share of each domain observed, against a denominator the twin discovered
coverage map
Open coverage gaps ↓
Blind spots with no closing action taken
coverage map
UNKNOWN segments on crown-jewel paths ↓
Unobserved segments on a path to a crown jewel
twin
Unowned and unclassified assets ↓
Assets with no owner or no business classification
twin
Answers refused for staleness ↓
Questions refused because their oldest fact exceeded its budget
twin history
Baselines are set in the 30-day diagnostic. Targets are committed in the 90-day scorecard. A KPI we cannot measure is reported as UNMEASURED.
No observed traffic is not no traffic.
When a log source is switched off, most tools show that environment as quiet. Quiet reads as safe, and nobody is told the difference.
Read why
Coverage is usually reported as the share of assets with an agent installed. That denominator counts only what someone already knew about. The asset nobody listed is covered by definition.
Every answer a security programme gives is only as good as what it could see, and almost none of them say so.
What it costs
- Blind spots presented as safe environments.
- Coverage figures that look complete because the denominator was incomplete.
- Decisions made on answers that never stated their limits.
Three environments. One of them is not quiet. It is unobserved.
- vpc-hl-prod · flow logs: present
- vpc-hl-dev · flow logs: partial
- vpc-hl-staging · flow logs: off · observed traffic: no data · UNKNOWN
Answers about staging say UNKNOWN. Never "no traffic, therefore safe".
illustrative · Harbourline Financial is the worked example used across this site
Coverage as a measured number, and every gap as work.
Coverage Assurance is the first thing SecSemantic's twin produces, and it keeps measuring for as long as the twin runs.
Within 30 minutes of connecting a cloud, a coverage report: here is what we can and cannot see.
Coverage is measured per domain against what the twin discovered in your estate, not against an asset list someone maintains.
A gap has a scope, a cause, a stated effect on what can be answered, and the action that closes it.
Below its coverage floor, SecSemantic returns "unranked" rather than a score, and it will not recommend an action it cannot support.
Findings from the tools you already run arrive normalised, deduplicated and attached to the real asset and the business service it affects.
Assets without an owner or a classification are findings, with a count that goes down over time.
Every answer carries the age of its oldest fact. Too old is refused, and it says why.
Every screen tells the two apart.
What you get
- A coverage report per domain and environment, with an evidence-derived denominator
- A gap register: every blind spot with its cause, effect and closing action
- A normalised, deduplicated view of your existing tools' findings on real assets
- An ownership and classification backlog
- A coverage trend over time
Industry lens
Evidence of what is and is not monitored, for the auditor's first question.
Coverage measured the same way on an air-gapped appliance.
A measured baseline of what an inherited estate lets you see.
What it is not
Not an asset inventory or a CMDB replacement. It measures what your estate reveals and what your tools can see.
FAQ
What exactly does the coverage report measure?
What the twin observes in each domain and environment, against a denominator it discovered from your estate, with every gap listed alongside its cause and the action that closes it.
How is this different from an agent-coverage dashboard?
Two ways. The denominator comes from evidence rather than from a list someone maintains, and a gap is a finding you can act on rather than a missing row.
What does UNKNOWN mean?
That part of the estate is not observed. It is treated as possibly open, never as safe, and any answer that depends on it says so.
Do we need to install anything?
No agents. Read-only credentials to your clouds, and the outputs your existing tools already produce.
How soon do we get the first report?
Within 30 minutes of connecting a cloud.
Does it replace our CMDB or asset inventory?
No. It measures what your estate reveals and what your tools see, and can show where they disagree.
Why start here?
Every other solution's answers are limited by what the twin can see. Coverage Assurance makes those limits visible first, so every later result can be believed.
How Coverage Assurance is delivered
A capability, the people who run it with you, and numbers you can check.
-
Diagnostic · days 0 to 30, at no cost.
The twin is launched and the first coverage report arrives within 30 minutes. Your existing tools' findings and telemetry are connected, the gap register is ranked by what each gap stops you from answering, and every KPI baseline is measured.
-
The 90-day KPI scorecard is agreed: VCR and the supporting KPIs, each committed against your baseline.
-
Outcome · days 30 to 90.
Gaps are closed with your teams in order of consequence, and ownership and classification backlogs are worked down.
-
The scorecard is reported with its evidence and who measured it. The outcome bonus is paid only against it.
-
The Semantic Loop · from day 90.
Every new account, environment and log source is measured as it appears.
The pod
two senior engineers and a fractional CISO advisor
-
Forward-deployed security engineer.
Deploys the twin, connects your sources, runs the gap register with your teams and owns the KPI baseline with you.
-
Exposure analyst.
Ranks every gap by what it stops you from answering and tracks each one to its closing action.
-
Fractional CISO advisor.
Owns the 90-day scorecard with your leadership and chairs the day-90 review.
What runs underneath
SecSemantic's Sentinel: the context graph, entity resolution, business context and crown jewels, findings and coverage, and trust and correctness. Insights presents posture and coverage, read-only.
Start with what you cannot see.
Connect one cloud, read-only. Within 30 minutes you have a report of what the twin can and cannot see, and every gap comes with the action that closes it.