Q Companion

CISO command center for security, compliance, field safety, and AI-guided response

Detroit incident active
Priority: Detroit ransomware response is in containment, 47 case workers remain overdue on HIPAA training, and DOL grant evidence has 34 days remaining.
Security Score
72/100
Elevated
Open Incidents
3
1 critical
MFA Coverage
81%
Volunteers at 54%
Grant Compliance
81%
HHS, DOL, HIPAA mix
Threat and Incident Trend
Exposure Mix
Executive Signals
Detroit ransomware attemptCritical
DOL grant review in 34 daysAudit
Volunteer MFA gapAccess
Morning Actions
Now
Authorize HHS breach notification assessment
Today
Deploy HIPAA training to overdue case workers
This week
Close DOL access-control evidence gaps
Sources
Deep Dive Workspace
Morning brief
Detroit response is time-sensitive. HIPAA training and DOL evidence closure remain the next strongest risk reducers.
I can synthesize incidents, compliance gaps, field safety exposure, and board-ready summaries from your security data.
Risk Register
RiskOwnerAppetiteStatusNext Action
R-007 Detroit RansomwareCISOAboveCriticalHHS notification assessment
R-003 Volunteer MFA GapIT AdminAboveElevatedMFA enforcement campaign
R-012 DOL Access Control EvidenceCompliance MgrAboveElevatedComplete evidence package
Overdue Check-ins
7
2 remote service sites
Travel Flags
3
1 risk score 82
Safety Coverage
89%
Location pulse active
Data Protection Snapshot
Beneficiary records on affected server847
Case worker notes protection74%
Outstanding DPIAs4
Compliance by Framework
HHS (2 CFR 200)84%
DOL (FISMA)76%
HIPAA79%
Incident Command
IncidentPhaseOwnerClockStatus
INC-2026-0089 Detroit RansomwareContainingAmir Patel6h into 72h windowCritical
Mobile device compromise investigationAnalyzingSecurity Officer12hOpen
Backup integrity alertMitigatingIT Admin1dStable
Access Governance
Dormant accounts47
MFA enabled81%
Volunteer MFA54%
Training Compliance
Overall compliance78%
HIPAA overdue learners47
CISA phishing training92%
Threat Intelligence Feed
CISA nonprofit ransomware campaignMatched
Critical CVEs pending2
Case management software advisoryWatch
Audit & Evidence
ArtifactFrameworkStatusNext Step
Post-Incident Review — DetroitHIPAA / HHSDraftedReview and approve
DOL Access Control EvidenceDOLGapUpload 9 items
Business Continuity Test EvidenceNISTOutdatedSchedule DR test
Beneficiary Records Protected
124K
Grant Value Protected
$13M
Security ROI
$10.8x
Tab Visibility & Order
InsightsLocked / Visible
Deep DiveVisible
ImpactVisible
Alert Thresholds & Escalation Rules
P1 IncidentImmediate to CISO + ED
Staff overdue check-in1h delay, 4h escalate
Connected Systems
Microsoft TeamsConnected
Google WorkspaceConnected
SIEM IntegrationEnterprise plan
Roles & Permissions
CISO (Admin)Full access
Compliance ManagerCompliance + Audit
Field DirectorField Safety
Recent Setting Changes
Alert Threshold — Risk Score80 → 85
P1 Escalation Delay1h → 30m
Agent Q
Security Intelligence Assistant
Good morning Marcus. The Detroit office ransomware attempt is contained, but your highest funding risk this week is still the HIPAA training gap.
What is your first priority this morning?