Crypto Agility · Enterprise Scale Validation

Enterprise Posture Report — Scale Validation

Purpose: validate the assessment pipeline against a multi-account, multi-region synthetic enterprise at customer-scale volumes. Metrics represent the full generated population; interactive drill-down is intentionally capped for browser performance. No customer data or credentials were accessed.

Enterprise scope & evidence coverage

Scenario / customer scope
Generic Enterprise · Production
Accounts / organizational units
25 / 25
Regions observed
5
Evidence model
Synthetic / provenance simulated

Full-population metrics are generated across the configured enterprise-scale scenario and environment. Interactive drill-down is capped at 20,000 records to keep the report responsive.

65
Moderate
Enterprise posture score / 100
5,000
Systems assessed
3,512
Security findings
9,524
Evidence & audit events
868
HNDL-exposed systems
0
Migrations blocked
6.0%
PQC-ready systems
10
Business units

Findings by severity

Critical 206
High 2176
Medium 1130

Cryptographic estate

ECC P-256 949
RSA-2048 850
AES-256 657
ECC P-384 649
RSA-3072 561
AES-128 421

Top risk signals

Click a signal to filter the finding explorer below.

HNDL exposure868
PQC migration required868
Certificate expires <90d384
Certificate expires <30d328
Missing asset owner268
Weak RSA key206
Key rotation overdue186
Missing evidence134
Configuration drift87
SHA-1 usage86

Systems by business unit

Click a business unit to filter the finding explorer below.

Security535
Engineering516
Customer Operations516
Finance516
Digital Products504
Supply Chain497
Corporate IT491
Cloud Platform484

GenAI & Internal LLM Risk Assessments

AI risk by severity

Critical 32
High 528
Moderate 2474
Low 4022

AI risk profile

10,000
AI assessments
8
Critical
176
High

Combined GenAI exposure and internal LLM misuse. AI findings are included directly in the unified Finding Explorer.

Top AI risk signals

Click a signal to filter the unified Finding Explorer to AI Risk.

GenAI exposure: Sensitive data to model2526
Internal LLM misuse: Sensitive internal prompt1146
GenAI exposure: Unapproved external model888
Internal LLM misuse: Unapproved model or endpoint692
GenAI exposure: Shadow AI use597
Internal LLM misuse: Excessive data access482
Internal LLM misuse: Policy bypass behavior423
GenAI exposure: Prompt exfiltration signal302

AI risk by business unit

Click a business unit to filter the unified Finding Explorer to AI Risk.

Security791
Engineering728
Digital Products727
Customer Operations726
Supply Chain717
Finance697
Corporate IT683
Shared Services671
Cloud Platform663
Data & Analytics653

C-level summary

Enterprise risk is concentrated where modernization constraints, business exposure, and control gaps intersect. The immediate priority is to reduce critical and high findings while removing the technology dependencies that can block migration — particularly legacy algorithms, HNDL exposure, HSM/PKI constraints, certificate and ownership gaps, and unsupported libraries. In parallel, AI risk requires governance over sensitive-data flows, unapproved models or endpoints, prompt-mediated exfiltration, excessive data access, and policy-bypass behavior. For the CEO, this frames the business exposure and investment priorities; for the CTO, it identifies engineering dependencies that can delay modernization; for the CISO, it identifies the control and evidence gaps requiring remediation. Use the unified Finding Explorer to move from an enterprise signal to the affected system, evidence, recommended action, and remediation status.

Finding Explorer

One investigation surface for cryptographic and AI risk findings. Use the scope toggle, filters, or any risk signal above to drill down.

DomainSeveritySignalSystemBusiness unitRecommended action
CryptographyMediumWeak RSA keyVendor-Integration-00001Supply ChainMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighCertificate expires <30dInternal-Service-00004Data & AnalyticsRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dInternal-Service-00005Corporate ITRotate certificate and validate dependent chains.
CryptographyMediumCertificate expires <90dCI/CD-Platform-00008Cloud PlatformSchedule rotation.
CryptographyHighCertificate expires <30dDatabase-00009Supply ChainRotate certificate and validate dependent chains.
CryptographyMediumWeak RSA keyVendor-Integration-00010FinanceMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighCertificate expires <30dVendor-Integration-00010FinanceRotate certificate and validate dependent chains.
CryptographyMediumThird-party dependencyCertificate-Service-00016Customer OperationsObtain vendor roadmap and migration compatibility statement.
CryptographyCriticalHNDL exposureKubernetes-Platform-00017EngineeringPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Platform-00017EngineeringSelect approved hybrid target and schedule migration.
CryptographyMediumCertificate expires <90dKubernetes-Platform-00017EngineeringSchedule rotation.
CryptographyHighHNDL exposureKubernetes-Platform-00019Data & AnalyticsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Platform-00019Data & AnalyticsSelect approved hybrid target and schedule migration.
CryptographyMediumMissing asset ownerCertificate-Service-00020EngineeringAssign an owner and establish review cadence.
CryptographyMediumWeak RSA keyKubernetes-Platform-00022EngineeringMove to approved stronger or hybrid profile during lifecycle work.
CryptographyMediumThird-party dependencyAnalytics-Lake-00024Cloud PlatformObtain vendor roadmap and migration compatibility statement.
CryptographyMediumCertificate expires <90dCI/CD-Platform-00027Digital ProductsSchedule rotation.
CryptographyHighHNDL exposureCustomer-Portal-00031Data & AnalyticsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredCustomer-Portal-00031Data & AnalyticsSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dBackup-Platform-00033Corporate ITRotate certificate and validate dependent chains.
CryptographyHighHNDL exposureData-Platform-00038FinancePrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredData-Platform-00038FinanceSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dCertificate-Service-00039FinanceRotate certificate and validate dependent chains.
CryptographyHighHNDL exposureAnalytics-Lake-00041Shared ServicesPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredAnalytics-Lake-00041Shared ServicesSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dAnalytics-Lake-00041Shared ServicesRotate certificate and validate dependent chains.
CryptographyMediumCertificate expires <90dAPI-Platform-00043Cloud PlatformSchedule rotation.
CryptographyHighKey rotation overdueAPI-Platform-00043Cloud PlatformRotate key and capture evidence.
CryptographyMediumMissing asset ownerCustomer-Portal-00045FinanceAssign an owner and establish review cadence.
CryptographyHighSHA-1 usageData-Platform-00046Digital ProductsReplace primitive and validate dependent applications.
CryptographyHighKey rotation overdueCI/CD-Platform-00047SecurityRotate key and capture evidence.
CryptographyCriticalHNDL exposureDatabase-00049Digital ProductsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredDatabase-00049Digital ProductsSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureKubernetes-Platform-00052Shared ServicesPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Platform-00052Shared ServicesSelect approved hybrid target and schedule migration.
CryptographyMediumCertificate expires <90dKubernetes-Platform-00055Customer OperationsSchedule rotation.
CryptographyMediumWeak RSA keyIdentity-Service-00060EngineeringMove to approved stronger or hybrid profile during lifecycle work.
CryptographyMediumMissing evidenceCI/CD-Platform-00062Shared ServicesCollect and seal evidence snapshot.
CryptographyHighHNDL exposureKubernetes-Platform-00065Data & AnalyticsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Platform-00065Data & AnalyticsSelect approved hybrid target and schedule migration.
CryptographyHighCertificate expires <30dCustomer-Portal-00066Digital ProductsRotate certificate and validate dependent chains.
CryptographyCriticalHNDL exposureKubernetes-Platform-00067Digital ProductsPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredKubernetes-Platform-00067Digital ProductsSelect approved hybrid target and schedule migration.
CryptographyMediumWeak RSA keyKubernetes-Platform-00067Digital ProductsMove to approved stronger or hybrid profile during lifecycle work.
CryptographyHighCertificate expires <30dKubernetes-Platform-00067Digital ProductsRotate certificate and validate dependent chains.
CryptographyHighCertificate expires <30dIdentity-Service-00068Supply ChainRotate certificate and validate dependent chains.
CryptographyMediumMissing asset ownerDatabase-00073Customer OperationsAssign an owner and establish review cadence.
CryptographyHighHNDL exposureData-Platform-00075Corporate ITPrioritize hybrid/PQC migration and protect retained ciphertext.
CryptographyHighPQC migration requiredData-Platform-00075Corporate ITSelect approved hybrid target and schedule migration.
CryptographyHighHNDL exposureCertificate-Service-00081Shared ServicesPrioritize hybrid/PQC migration and protect retained ciphertext.

How to read this report

Executives can start with posture, concentration of critical/high findings, HNDL exposure and migration blockers. Executives can then click through the unified Finding Explorer — filter by domain, business unit, system, or signal, expand a row to see the remediation context and evidence, and export the filtered list as evidence-backed work items.

Evidence model

begin → collect → seal → consume
Synthetic evidence is generated deterministically across accounts, organizational units, regions, systems and AI/LLM signals. The same normalization and assessment logic is exercised; no live cloud mutations occur.

Enterprise Scale Validation · Synthetic only · Full-population metrics with capped interactive drill-down · Generated locally