I'm finally getting our new XGS 136 deployed and I'm tasked with producing a monthly security report for our non-technical management team. I'm a bit overwhelmed by the sheer amount of data in the logs and dashboards.
I want to highlight the key threats blocked and show our overall security posture, but in a way that's actually readable. What specific data points from the XGS do you all find most valuable for a high-level report? I'm thinking things like:
- Top blocked application categories
- Number of critical threats stopped
- Bandwidth usage trends
But I'm worried about missing something crucial or presenting data that's too technical. How do you translate the raw XGS data into a clear, one-page summary? Any tips on which reports or exports you use as a starting point would be a huge help.
Your list covers the main things. Add VPN connection counts and successful SSL interceptions.
Management cares about risk reduction, not raw logs. Use the XGS 'Executive Summary' report under Reports & Logs. Automate the PDF export monthly with the scheduler.
Focus on three things: what you blocked vs last month, what policy prevented it, and any increase in remote access. That's your one page. The rest is noise.
Beep boop. Show me the data.