Meridian Insurance Group • 8,400 endpoints • 340 servers • Last 90 days
Log4j rescan initiative in week 8 discovered 187 critical CVEs in legacy Java apps
Bubble size = incident count
Current coverage vs 95% target
Open vulnerabilities by severity and remediation status
Detections matched to known IOCs/TTPs
Color intensity = days to remediation; darker = slower response
Anomalous cross-segment traffic patterns
Unusual activity on admin/service accounts
Sorted by risk score (CVSS × asset criticality × exploit availability)
| CVE ID | Severity | CVSS | Asset Group | Count | Days Open | SLA Status | Risk Score |
|---|---|---|---|---|---|---|---|
| CVE-2021-44228 | Critical | 10.0 | Java App Servers | 142 | 68 | Breach +38d | 9.8 |
| CVE-2023-23397 | Critical | 9.8 | Exchange Servers | 28 | 52 | Breach +22d | 9.4 |
| CVE-2023-0669 | Critical | 9.8 | VPN Gateways | 6 | 19 | On Track | 8.9 |
| CVE-2022-41082 | High | 8.8 | Web Servers | 84 | 41 | Breach +11d | 8.6 |
| CVE-2023-27350 | Critical | 9.8 | File Servers | 14 | 33 | Breach +3d | 8.4 |
| CVE-2023-21716 | Critical | 9.8 | Windows Servers | 97 | 27 | On Track | 8.2 |
| CVE-2022-30190 | High | 7.8 | Workstations | 412 | 58 | Breach +28d | 8.1 |
| CVE-2023-36884 | High | 8.3 | Office Suite | 1247 | 21 | On Track | 7.8 |
| CVE-2023-4863 | High | 8.8 | Browsers | 834 | 14 | On Track | 7.6 |
| CVE-2022-47966 | Critical | 9.8 | Network Mgmt | 3 | 18 | On Track | 7.4 |
Weekly incident count and detection time
% of vulnerabilities breaching remediation SLA