Reports
Reports turn what the CyberOptix CTEM Platform knows into something you can send to someone who does not log in - a board, an auditor, a client.
Three parts: the catalog of what can be produced, generated reports you have already run, and schedules that produce them on a recurring basis.
The catalog
The catalog lists the report types available to your role. It is filtered per user, so two people in the same organization can see different entries - a pentester sees assessment reporting that an engineer does not.
Report types span the product: penetration test results, executive summary, vulnerability management, attack surface, remediation progress, compliance, cloud posture, security operations, application security, and threat intelligence.
Each entry states the formats it supports. PDF is the common output; several also produce XLSX, and the penetration test report produces a Word document so it can be edited before it goes out.
The catalog is filtered by role, and what a given entry can produce depends on what data you have. A cloud posture report needs a connected cloud account; an application security report needs source control. If an entry produces less than you expected, the usual cause is that the underlying section has nothing in it yet.
Generating one
Governance → Report Catalog, pick a type, set its parameters, generate.
SCREENSHOT: the Report Catalog.
Generation is asynchronous - the request is queued and the report appears under Generated Reports when it is done. Large reports over a wide date range take longer; nothing is lost if you navigate away.
From Generated Reports you can download or delete. Reports are stored, so a report you ran last quarter is still there to compare against.
Scheduling
Governance → Schedules produces a report on a recurring basis and delivers it.
The two that earn their place:
- A recurring executive summary, because the value of trend reporting is the trend, and that requires the same report at the same interval rather than one pulled when somebody asks.
- A recurring compliance report, because the evidence an auditor wants is usually "this was true every month", not "this is true today".
Set the cadence to match what will actually be read. A weekly report nobody opens trains people to ignore the sender.
Scoping a report
Reports respect the same scoping as everything else. A report scoped to a business unit says something that unit can act on; an organization-wide report sent to eight teams is read by none of them.
See Organizations, business units, and zones.
API
Reports can be generated and downloaded programmatically with an API key carrying
reports:write and reports:read. That is how you drive reporting from your own
scheduler rather than this one, or push output into a document store.
The endpoints behind this section are in the API reference.
Next
- Business units - scoping reports to a team
- Remediation SLA policy - what progress reporting measures against
- API keys - generating reports programmatically