Overview
The Remediation dashboard shows how valid vulnerabilities move from discovery to verified fix, and your unresolved backlog costs risk. Use it to prove remediation is keeping pace with discovery, track Mean Time to Remediation (MTTR) against your history and peers, and see where open exposure carries the most estimated financial risk.
To learn more about the features and functionality available on all dashboards, such as filters, segments, downloads, point labels, Explore, benchmarks, and data tables, see the Dashboards documentation.
To find the Remediation dashboard, click Analytics in the left navigation, then click Remediation.
Summary
The Summary section at the top of the dashboard gives you a high-level snapshot of remediation performance and open exposure. It highlights four metrics:
Carrying cost of exposure debt (current) - The total estimated annual cost of your unresolved valid vulnerabilities, in USD, with a year-on-year comparison. The estimate covers reports in the Triaged, Pending Program Review, and Retesting substates, calculated using Annual Loss Expectancy (ALE). It is not affected by the date selector on the dashboard. This puts a dollar figure on risk that is still open, so you can frame the backlog for finance and leadership in terms they can act on.
Days to zero backlog (current) - The number of days to clear your current backlog at your current pace, with a separate figure for High and Critical reports. Based on your discovery and remediation rates over the past 90 days, assuming no change. It is not affected by the date selector on the dashboard. This turns your current pace into a clear timeline. Use it to set realistic remediation commitments and to make the case for additional capacity when the High and Critical figures run long.
Remediation rate - How many reports you remediated compared with how many newly entered the Open: Triaged state, with a month-on-month comparison. The break-even point is where remediation matches new intake. Above it, you are closing issues faster than they arrive. Below it, vulnerabilities are being added faster than you can remediate them. Track the month-on-month movement to catch a growing backlog early.
Mean time to remediation - The mean time from report submission to close as resolved, in days, with a year-on-year comparison. This is the headline speed metric for your program. Use the comparison to confirm remediation is getting faster over time.
Findings flow
How do findings flow into remediation, and how severe are they?
The Findings flow chart traces valid vulnerabilities through each stage, from all findings, to new, to valid or invalid, to a remediation plan created, to remediated. Nodes and flows are colored by severity so you can see where the most serious issues sit in the pipeline.
Use it to spot where valid findings stall between triage and a remediation plan, and to confirm that serious issues reach remediation rather than stall.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
MTTR
Is our Mean Time to Remediation improving over the selected timeframe?
MTTR shows the mean time from when a valid report is submitted to when it is closed as resolved, plotted over your selected timeframe. The chart includes three lines:
Your average - Your MTTR for the selected timeframe.
Previous year - Your MTTR over the same timeframe in the previous year.
Platform benchmark - The median (50th percentile) across all HackerOne organizations, after grouping by organization.
MTTR counts reports in the Closed state with a substate of Resolved.
This is your core remediation speed trend. Compare your average against the previous year and the platform benchmark to see whether you are improving and how you compare with peers. Treat a rising line as a prompt to investigate process delays. You can also build your own custom benchmark to measure MTTR against a peer cohort of your choice.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Create a custom benchmark - Build and save a benchmark using filters, so you can compare your MTTR against a focused peer cohort or a group you aim to align with.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
MTTR by Severity
How quickly are important issues remediated?
MTTR by severity breaks your Mean Time to Remediation into Critical, High, Medium, and Low and plots them over your selected timeframe.
Use it to confirm your most serious issues are fixed fastest. Check the bars against your severity-based expectations.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
Discovery to Remediation trend
Is remediation keeping pace with valid vulnerability discovery?
This chart compares two lines over your selected timeframe:
Valid open - Reports that entered the Open: Triaged state during the interval.
Remediated - Reports that entered the Closed: Resolved state during the interval.
Use it to see whether your team is keeping up with incoming valid findings. A widening gap between Valid open and Remediated signals a growing backlog and supports a case for more capacity. A closing gap shows your program pulling ahead.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
Vulnerabilities by age (current)
For your current backlog, how old are unremediated valid vulnerabilities, and how severe are they?
This chart groups your open valid vulnerabilities into age bands, from 0 to 7 days through to 250 days and over, and stacks each band by severity. Age is calculated from the report submission date. Only reports currently in Open: Triaged are included. A report leaves the chart once it moves to Closed: Resolved.
This chart shows a point-in-time view of your current backlog and is not affected by the date selector on the dashboard.
Use it to surface ageing risk. Old, high-severity findings are your greatest exposure.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
Carrying cost of exposure debt
How much financial risk is tied to your current backlog of unresolved validated vulnerabilities?
Carrying cost of exposure debt is the counterpart to Return on Mitigation, and the two read as a pair. Return on Mitigation shows the estimated dollar value of risk you have mitigated by resolving vulnerabilities. The carrying cost of exposure debt represents the estimated dollar value of risk that remains unresolved in your backlog. Both use the same Annual Loss Expectancy (ALE) model: Return on Mitigation applies it to what you have fixed, and carrying cost applies it to what remains open.
This chart plots the estimated annual cost of your open valid vulnerabilities over your selected timeframe, with two lines:
All severities - The full estimated annual cost.
Critical only - The estimated annual cost from Critical reports.
The dollar value is a rate per year, not a running balance. You carry this cost for as long as the vulnerabilities stay open, so a rising line means risk is accruing, and a falling line means you are paying it down.
Security leaders are increasingly expected to state risk in financial terms rather than vulnerability counts. This chart gives you that figure for your open backlog and tracks it over time, so you can show the board and finance whether remediation is reducing the money you have at risk. Read it alongside MTTR and Remediation rate, which explain why the cost is moving.
Organization Admins can update your org settings used in this calculation in Settings > Return On Mitigation.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
Carrying cost of exposure debt by severity (current)
For your current backlog, which severity levels carry the most financial risk?
This chart shows the estimated annual cost of your unresolved valid vulnerabilities, broken down by severity. The estimate covers reports in the Triaged, Pending Program Review, and Retesting substates, calculated using Annual Loss Expectancy (ALE).
This chart shows a point-in-time view of your current backlog and is not affected by the date selector on the dashboard.
Use it to focus remediation where the estimated cost is highest, not only where report volume is highest. A small number of Critical findings can outweigh a large volume of low-severity ones.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
Carrying cost of exposure debt by age (current)
For your current backlog, where should remediation focus based on age and estimated financial risk?
This chart maps the estimated annual cost of your open valid vulnerabilities across age bands, from 0 to 7 days through to 250 days and over.
The dollar value is a rate per year, not a running balance. This chart shows a point-in-time view of your current backlog and is not affected by the date selector on the dashboard.
Use it to identify findings that are both old and expensive, then sequence remediation to achieve the largest reduction in risk. Weigh age and cost together rather than treating them separately.
On this chart, you can:
Explore - Deep dive into the data to see where to focus.
Show the data in table format - Switch between the chart and table views.
More - Export the data and view it in full-screen mode.
Frequently Asked Questions
Do I need a specific product to use this dashboard?
No. The Remediation dashboard works across reports from Bug Bounty, Challenge, and VDP.
What counts as a valid vulnerability?
A report in the Open state with a substate of Triaged.
What counts as remediated?
A report in the Closed state with a substate of Resolved.
What is the difference between Mean Time to Remediation and Time to Close?
Mean Time to Remediation counts valid reports only, measured from submission to close as resolved. Time to Close on the Response Efficiency dashboard counts all reports, regardless of outcome. The two answer different questions, so expect different values.
Why do some charts ignore the date selector?
Backlog and current-cost views show a point-in-time snapshot of what is open right now. A date range does not apply to a snapshot, so those charts stay fixed while you change the selector.
How is carrying cost of exposure calculated?
The estimate uses Annual Loss Expectancy (ALE), the standard method for putting an annual dollar figure on risk. ALE multiplies Single Loss Expectancy (SLE), the cost of one incident, by Annual Rate of Occurrence (ARO), how often that incident is expected in a year.
The Remediation dashboard applies this model to your open valid vulnerabilities, so it is the mirror image of Return on Mitigation, which applies the same model to vulnerabilities you have already fixed. Both draw on the same SLE and ARO inputs. Set or tailor them through the Return on Mitigation setup. Organization Admins can update your org settings used in this calculation in Settings -> Return On Mitigation.
