Cisco Secure Access Help

PDF

Cisco Secure Access Help

Security Insights Dashboard

Want to summarize with AI?

Log in

Security Insights is a cross-domain operational dashboard in Cisco Secure Access that unifies security posture, data protection, AI governance, application risk, identity risk, and threat activity into a single investigation surface.


About Security Insights

Security Insights is a dashboard in Secure Access for security teams that need to understand risk across users, applications, data, and threats without starting from separate reports. The dashboard presents operational insights from Secure Access controls, Cisco Identity Intelligence, Data Loss Prevention, App Discovery, and threat reporting.

It brings together insights that have historically lived in separate reports and workspaces, including:

  • Threat enforcement outcomes (allowed and blocked)
  • Data Loss Prevention (DLP) violations across web, SaaS API, email, endpoint, and private app channels
  • Generative AI application discovery and AI Guardrail violations
  • Application risk, including third-party app authorizations
  • User trust levels from Continuous Identity Intelligence (CII)
  • User and Entity Behavior Analytics (UEBA) detections
  • Connection type distribution (VPN versus ZTNA)

Requesting access

Security Insights is available on request. To enable Security Insights for your organization, contact Cisco Support. For contact information, refer to Welcome to Cisco Secure Access.

Opening Security Insights

After the feature is enabled for your organization, open Security Insights from the Secure Access left navigation menu.

Tabs in Security Insights

The dashboard is organized into six tabs. Each tab uses a consistent layout: a top row of summary cards that scope the tab's subject matter, followed by visualizations and tables that support investigation. Most panels link to existing reports and policy pages where you can perform deeper analysis or take action.

The Security Insights 01 interface.
Tab Focus
Security Overview Cross-domain summary of traffic, threat outcomes, and security enforcement
Data Security DLP violations by channel, classification, user, rule, and destination
AI Governance GenAI app discovery, AI Guardrail violations, and sensitive data sent to AI
Applications Allowed, not-allowed, unreviewed, and third-party risk apps
Users User trust levels, top risky users, UEBA detections, and connection types
Threat Blocked and allowed threats, rule efficacy, trends, and risky destinations

How to use the dashboard

  • Start with Security Overview. Use it as your landing page to confirm whether anything requires immediate attention.
  • Pivot by clicking. Summary cards, Sankey nodes, table rows, and panel titles link to the corresponding tab, report, or policy page.
  • Use time-range controls. Most panels honor the dashboard period switcher (24 hours, 7 days, 30 days, 60 days). Some panels have fixed intervals, which are noted in the panel description.

Related information


Security Overview Tab

The Security Overview tab of the Security Insights dashboard is the landing page for cross-domain security status. It summarizes what generated traffic, whether Secure Access allowed or blocked threats, and which enforcement controls acted on the traffic. Use the Security overview tab to understand overall security posture, traffic flow, threat outcomes, and enforcement activity across Secure Access.

Summary cards

Shows a quick health snapshot for the other dashboard tabs and lets you move to the tab that matches the question you have.

The Security Insights 01 interface.

Security traffic flow

A diagram that maps traffic from SourcesThreat outcomeSecurity enforcement. Shows which users, locations, sites, or devices generated traffic, whether threats were allowed or blocked, and which controls enforced the traffic. Use the period switcher (24 hours, 7 days, 30 days, 60 days) at the top right.

The Security Insights 02 interface.
Column Nodes Where to learn more
Sources Users, Locations, Devices
Threat outcome Threats allowed, Threats blocked Events Report
Security enforcement DNS security, URL filtering, Threat prevention, DLP / Inspection

Hover over a card to highlight the related flows. Click a card to open a detail drawer.

Below the diagram:

  • Top Rules Allowing Threats — Click a rule name to open the rule in the Access Policy.

  • 30-day trend line — Threats allowed versus blocked (fixed 30-day interval).

Security posture

  • Enforcement summary — 30-day view of enforcement activity.

  • Active threat feed — Blocked threats by severity and type over the last 24 hours, including malware, command-and-control, phishing, grayware, and cryptomining.

The Security Insights 03 interface.

Data Security Tab

The Data Security tab of the Security Insights dashboard provides visibility into Data Loss Prevention (DLP) violations across channels and data classifications. Use this tab when you need to understand where sensitive data is moving, which rules are triggered, and who or what is responsible for violations. Use this tab with the Data Loss Prevention Report when you need the underlying events and filters.

Summary cards

See total Data Loss Prevention violations, enforced violations, and high-severity violations for the current period.

The Security Insights 04 interface.
Card What it shows
DLP Violations Total DLP policy matches across web, SaaS API, email, endpoint, and private apps (last 7 days), with delta versus previous 7 days
Violations Blocked Violations blocked or quarantined before data left the organization
High Severity Violations classified as Critical or High

Click any card to open the Data Loss Prevention Report.

DLP violations by channel and classification

The Security Insights 05 interface.
  • Data Loss Prevention Violations by Channel — Breakdown or trend view across Web, SaaS API, Email, Endpoint, Private Apps, and Other.
  • Data Loss Prevention Violations by Classification — PII, Financial, HIPAA, Intellectual Property, and Other.

Top Data Loss Prevention Violations by User

Users with the most policy violations over the last 30 days, including channel, violation count, and classification. Click View all violators to open the Data Loss Prevention Report.

Top DLP Rules Triggered and Apps Receiving Sensitive Data

  • Top Data Loss Prevention Rules Triggered — By hit count over the last 30 days.
  • Applications Accessing Sensitive Data — Destinations with DLP violations, with a breakdown or trend view.

Top Data Flows

Violation patterns across channels, data types, and exit points.

The Security Insights 06 interface.

AI Governance Tab

The AI Governance tab of the Security Insights dashboard provides visibility into Generative AI application usage, AI Guardrail violations, and sensitive data sent to GenAI destinations. Use this tab when you want to review generative AI adoption and decide whether you need an app-centric investigation, a rule review, or a data protection review. Use the App Discovery Report for app-centric investigation and the Data Loss Prevention Report for content- and rule-centric investigation.

Summary cards

Shows the number of discovered GenAI applications, AI guardrail violations, and blocked AI requests.

The Security Insights 07 interface.
Card What it shows Opens
GenAI Apps Discovered GenAI apps found in App Discovery, across conversational AI, code assistants, image generation, developer tools, and data analysis App Discovery Report
AI Guardrail Violations DLP events scoped to AI Guardrail rules, including prompt injection, sensitive data in prompts, jailbreak attempts, and unauthorized model access Data Loss Prevention Report
Blocked AI Requests AI requests blocked by DLP, guardrail, and access policies AI Activity view (not sure what this is?)

GenAI Application Map

A network diagram centered on GenAI apps, with nodes for the highest-volume and most-used sub-categories, plus developer tools, image generation, and data analysis. Each node shows apps, traffic volume, and identity counts. Includes a 30-day web traffic trend.

The Security Insights 08 interface.

AI Guardrail Violations

Table of violations by type (Prompt Injection Attempt, Sensitive Data in Prompt, Jailbreak Attempt, Unauthorized Model Access, Ethical Violation), count, severity, and 30-day trend. Click a row to open the

Click View in DLP Events to open the Data Loss Prevention Report.

For more information, refer to Add an AI Guardrails Rule to the Data Loss Prevention Policy and Manage AI Guardrails Data Classifications.

DLP Violations for GenAI and Sensitive Data Sent to GenAI

  • DLP Violations for GenAI — By data classification, last 30 days.

  • Sensitive Data Sent to GenAI — By classification, detection type, and destination.

Click View in DLP Events to open the Data Loss Prevention Report.


Applications Tab

The Applications tab of the Security Insights dashboard helps you understand application use and third-party application risk before you open detailed application reports. Use this tab when you want to review application adoption and decide where to allow, block, or investigate an application. Use this tab together with your Access Policy when you need to move from observed application use to policy changes.

Summary cards

Shows how many applications are allowed, not allowed, unreviewed, or identified as third-party risk.

The Security Insights 09 interface.
Card What it shows
Allowed Apps Apps permitted by policy. Click to open the App Discovery Report.
Not Allowed Apps Apps blocked by policy. Click to open the Events Report.
Unreviewed Apps Apps discovered but not yet categorized by policy. Click to open the App Discovery Report.
Third-Party Risk Apps Third-party cloud apps authorized to access sanctioned tenant apps. Click to open the Third-Party Apps Report.

Top Apps by Usage

App usage alongside DNS request counts. Click View in App Discovery to open the App Discovery Report.

The Security Insights 10 interface.

Not Allowed Apps and Top Risky Apps

  • Not Allowed Apps — Apps that users are attempting to access despite policy restrictions. Click View not allowed in Events to open the Events Report.

  • Top Risky Apps — Discovered apps with a risk score greater than 7.0. Click View in App Discovery to open the App Discovery Report

High Risk Third-Party Apps and Top Users with Risky Third-Party Apps

  • High Risk Third-Party Apps — Sourced from the Third-Party Apps Report.

  • Top Users with Risky Third-Party Apps — Users with the most high-risk app permissions. For more information, refer to View User Details

Click View in Third-Party Apps to open the Third-Party Apps Report.


Users Tab

The Users tab of the Security Insights dashboard provides visibility into user trust levels, top risky users, User and Entity Behavior Analytics (UEBA) detections, and connection type distribution, scored by Cisco Identity Intelligence (CII). Use this tab when you want an identity-first investigation path that starts with trust, recent detections, or how users connect. Trust level and behavior data are most useful when you pair this tab with Manage Behaviour Analytics Configuration.

Summary cards

Shows how many users are high risk, how many active users are scored, and what percentage of users are at Neutral or above trust.

The Security Insights 11 interface.
Card What it shows
High-Risk Users Users at Untrusted or Questionable trust level
Total Users Active users scored by CII
Trust Score (Neutral+) Percentage of users at Neutral trust or above

For more information, refer to View Users Provisioned in Secure Access and Integrate Cisco Identity Intelligence with Secure Access

User trust levels, Top 5 risky users and Recent UEBA detections

Distribution of users across trust levels, and a list of the highest-risk users in the environment.

Detections from User and Entity Behavior Analytics, including:

  • Impossible Travel — Identify events from geographically distant locations within unrealistic timeframes.
  • File Operations — Monitor file operation thresholds for downloads, uploads, and deletions within defined periods.
  • DLP Violation Spike — Detect unusual increase in DLP policy violations within a specified time period.
  • High-Risk Country File Activities — Monitor file uploads sent to and file downloads from countries you designate as high-risk.
  • Anomalous MCP Activity — Detect unusual Model Context Protocol (MCP) activity, including potential injection activity or a sudden increase in requests.
  • Unseen Location Activity — Monitor user activity from a city or source IP address that was not observed for that user during the previous 60 days.
  • Traffic Spike and Destination Monitoring — Detect unusual increase in requests to a specific destination or any TOR relay.

For more information, refer to View Users Provisioned in Secure Access and Integrate Cisco Identity Intelligence with Secure Access.

Risky behaviour breakdown

Distribution of UEBA-scored risky behaviors. For more information, refer to Add and Edit Alert Rules for Behavior Analytics.

The Security Insights 12 2 interface.

Connection types: VPN versus ZTNA

Distribution of VPN versus ZTNA sessions over the last 30 days, with a toggle between breakdown and trend views. Click View connection data to open the Events Report.


Threat Tab

The Threat tab of the Security Insights dashboard helps you identify where Secure Access blocks threats, where policy allows threats, and which rules, destinations, categories, or users require follow-up. Use this page when you need to separate detection coverage from policy gaps and decide whether to tune policy, investigate users, or review destinations. Use this page with the Events Report when you need to inspect the underlying detections.

Summary cards

Shows how many threats were blocked, how many were detected overall, how many were allowed, and how many distinct sources generated the activity.

The Security Insights 13 interface.
Card What it shows
Threats Blocked Threats blocked by DNS security, web security, firewall, and IPS policies
Total Threats Combined count of blocked and allowed threats
Threats Allowed Threats detected but not blocked — indicates enforcement gaps
Unique Sources Distinct source IPs or user identities generating threat traffic

Click a card to open the Events Report.

Blocked and allowed threats and Top rules allowing threats

  • Blocked and Allowed Threats — Shows which threat categories Secure Access blocked and which categories still reached users or destinations. By category: Command and Control, Malware, Grayware, Phishing, Cryptomining.
  • Top Rules Allowing Threats — Shows which rules permit traffic that later matched threat detections. Policies permitting threat traffic; review recommended.

Detection efficacy

  • Top Rules Blocked — Rules generating the most blocks.
  • Rules with 0 Hits — Rules that have never matched traffic; candidates for review or removal.
The Security Insights 15 interface.
  • Top Risky Destinations — Highest-risk destinations by threat volume.
  • Threats by Category — Detected volume by threat type over the last 30 days.
The Security Insights 16 interface.

Top blocked users

Users generating the most blocked threat traffic over the last 30 days. Click through to Manage Users, Groups, and Endpoint Devices.