Security Insights is a cross-domain operational dashboard in Cisco Secure Access that unifies security posture, data protection, AI governance, application risk, identity risk, and threat activity into a single investigation surface.
About Security Insights
Security Insights is a dashboard in Secure Access for security teams that need to understand risk across users, applications, data, and threats without starting from separate reports. The dashboard presents operational insights from Secure Access controls, Cisco Identity Intelligence, Data Loss Prevention, App Discovery, and threat reporting.
It brings together insights that have historically lived in separate reports and workspaces, including:
- Threat enforcement outcomes (allowed and blocked)
- Data Loss Prevention (DLP) violations across web, SaaS API, email, endpoint, and private app channels
- Generative AI application discovery and AI Guardrail violations
- Application risk, including third-party app authorizations
- User trust levels from Continuous Identity Intelligence (CII)
- User and Entity Behavior Analytics (UEBA) detections
- Connection type distribution (VPN versus ZTNA)
Requesting access
Security Insights is available on request. To enable Security Insights for your organization, contact Cisco Support. For contact information, refer to Welcome to Cisco Secure Access.
Opening Security Insights
After the feature is enabled for your organization, open Security Insights from the Secure Access left navigation menu.
Tabs in Security Insights
The dashboard is organized into six tabs. Each tab uses a consistent layout: a top row of summary cards that scope the tab's subject matter, followed by visualizations and tables that support investigation. Most panels link to existing reports and policy pages where you can perform deeper analysis or take action.
| Tab | Focus |
|---|---|
| Security Overview | Cross-domain summary of traffic, threat outcomes, and security enforcement |
| Data Security | DLP violations by channel, classification, user, rule, and destination |
| AI Governance | GenAI app discovery, AI Guardrail violations, and sensitive data sent to AI |
| Applications | Allowed, not-allowed, unreviewed, and third-party risk apps |
| Users | User trust levels, top risky users, UEBA detections, and connection types |
| Threat | Blocked and allowed threats, rule efficacy, trends, and risky destinations |
How to use the dashboard
- Start with Security Overview. Use it as your landing page to confirm whether anything requires immediate attention.
- Pivot by clicking. Summary cards, Sankey nodes, table rows, and panel titles link to the corresponding tab, report, or policy page.
- Use time-range controls. Most panels honor the dashboard period switcher (24 hours, 7 days, 30 days, 60 days). Some panels have fixed intervals, which are noted in the panel description.