# Track organization-wide security risk in one dashboard

DevFeed: [Track organization-wide security risk in one dashboard](<https://devfeed.tech/articles/track-organization-wide-security-risk-in-one-dashboard-77050.md>)

Original publisher: [Read original article](<https://about.gitlab.com/blog/security-risk-in-one-dashboard/>)

Author: Alisa Ho

Published: 2026-10-08T00:00:00Z

Content type: release

Language: en

Sources: [GitLab](<https://devfeed.tech/sources/gitlab.md>)

Topics: [known exploitable vulnerabilities](<https://devfeed.tech/topics/known-exploitable-vulnerabilities.md>), [alert triage](<https://devfeed.tech/topics/alert-triage.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [dashboard](<https://devfeed.tech/tags/dashboard.md>), [features](<https://devfeed.tech/tags/features.md>), [reports](<https://devfeed.tech/tags/reports.md>), [risk](<https://devfeed.tech/tags/risk.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

GitLab 19.4 adds a beta organization-level security dashboard for GitLab.com Ultimate users. It consolidates application security findings across top-level groups and scanners, with a risk score based on vulnerability severity, age, KEV listing, and EPSS score. Teams can review trends, vulnerability age and severity, and recurring CWEs, and filter results by project or report type. Third-party scanners that provide SARIF reports can contribute findings.

## Source excerpt

If you run application security across more than one top-level group, getting a single organization-wide view of your risk has meant manually pulling together data. That is operational work rebuilt in spreadsheets and one-off scripts every time someone asks. This manual work is easy to get wrong, and is often out of date the moment it is published. Every hour spent assembling that view is an hour your security team is not spending on strategic work to drive down risk. With GitLab 19.4, the security dashboard now gives you a consolidated view of risk at the organization level. Across every top-level group and every scanner your teams run, you can see how your whole application security program is doing, find where the real risk is concentrated, and act on it, without stitching anything together by hand. Your team spends its time remediating vulnerabilities instead of assembling reports, and when leadership or an auditor asks where the organization stands, you have a current, defensible answer on one screen. The organizational level security dashboard is available in beta for GitLab.com users. See total risk, then triage down to the project The risk score quantifies the risk level across the entire organization. This score is calculated based on the severity and age of your open vulnerabilities, whether each one appears on the Known Exploited Vulnerabilities (KEV) list, and its Exploit Prediction Scoring System (EPSS) score. The risk score helps security leaders prioritize what area of the organization is most susceptible to threats, rather than a raw count that treats every finding as equal. The charts around the risk score also proactively answer follow-up questions. The Vulnerabilities over time view shows whether risk is trending up or down across the organization over 30, 60, or 90 days. Vulnerabilities by age shows what is going stale and slipping past your remediation targets. Open vulnerabilities by severity and the top 10 Common Weakness Enumeration (CWE) sho