Skip to main content

Getting Started with Illumio Insights

Vulnerability Exposure

Use the Vulnerability Exposure page to prioritize vulnerability remediation by combining CVE severity, workload exposure, enforcement status, and projected segmentation impact.

For the selected time range, vulnerability data summarizes across workloads and application labels so you can compare current exposure with projected exposure after mitigation.

Vulnerability Exposure widgets

Assess vulnerability exposure across your environment and identify where segmentation can reduce risk.

Data shown in all widgets reflects the selected date range and any applied page-level filters.

Widget

Use cases

Number of CVEs

View the number of CVEs detected in the network during the selected time range.

Use this widget to:

  • Quickly understand the volume of vulnerabilities present in the current scope.

  • Identify increases or decreases in detected CVEs over time.

  • Correlate new CVEs with changes in vulnerability scanner findings, workload inventory, or application deployments.

Workloads with CVEs

View the number of workloads that have one or more detected CVEs.

use this widget to:

  • Understand how broadly vulnerabilities are distributed across workloads.

  • Identify whether vulnerability exposure is concentrated or widespread.

  • Track whether remediation activity is reducing the number of affected workloads.

Workloads Reachable by CVEs

Compare the number of vulnerable workloads that are currently reachable with the projected number of reachable workloads after mitigation.

Use this widget to:

  • Estimate how segmentation can reduce vulnerability reachability.

  • Prioritize policy changes that reduce access to vulnerable workloads.

  • Communicate the projected impact of mitigation actions.

The Before Mitigation value represents the current number of workloads reachable by CVEs. The After Mitigation value represents projected reachability after segmentation-based mitigation. The delta indicates the expected reduction in reachable vulnerable workloads.

Segmentation Impact on Vulnerability Exposure

Data shown in the table reflects the selected date range and any applied page-level filters.

Use the Segmentation Impact on Vulnerability Exposure table to identify which application label groups have the greatest vulnerability exposure and where segmentation can have the largest projected impact.

The table helps you prioritize remediation by showing, for each application label grouping, how many CVEs are present, how many workloads are affected, how many vulnerable workloads are reachable, and how many would remain reachable after mitigation.

Column

Description

Application Labels

Application and environment labels associated with the affected workloads, such as production or staging application groups.

# CVEs

Number of CVEs detected for workloads in the label group.

Workloads with CVEs

Number of workloads in the label group that have one or more detected CVEs.

Workloads Reachable by CVEs

Number of vulnerable workloads in the label group that are currently reachable.

Workloads Reachable by CVEs after Mitigation

Projected number of vulnerable workloads that would remain reachable after segmentation-based mitigation. A lower value indicates reduced exposure. The change indicator shows the projected reduction from the current reachable count.

Application details slide-out

Click a row in the Segmentation Impact on Vulnerability Exposure table to open an application details slide-out for the selected application and environment label group.

The slide-out gives you more context about the selected application group and helps you understand why it contributes to vulnerability exposure.

The slide-out includes the following:

View

Description

Overview

Shows summary information for the selected application and environment, including application criticality, vulnerability distribution, total workloads, total flows, total bytes, and peer applications.

Application Map

Shows the application map for the selected label group. In the vulnerability view, the map displays workloads, containers, endpoints, and peer applications associated with the selected application.

Excessive Permissions

Shows permission-related findings for the selected application group, helping you identify access that may increase exposure.

Vulnerability Exposure

Shows vulnerability exposure details for the selected application group.

Guardrail Violations

Shows guardrail rule violations associated with the selected application group.

From the slide-out, you can also select View Policy Recommendation to review recommended segmentation policy for reducing exposure. See Policy Advisor.