Overview
Seculyze 4.0.0 removes the manual work from monthly reporting. Branded security reports are generated and delivered on the schedule you set, using your own template if you have one. Analysts also get precedent on every incident, and Calibrate can now apply published alert rule updates on its own.
Detailed Description
Three things drive this release. Monthly reporting is now automated end-to-end: data gathering, commentary, branding, and delivery. Incident triage gains precedence, showing how the same detection was closed before and how strongly the cases actually match. And Calibrate can keep detection rules current without a click per rule.
Release Highlights
📄 Automated Monthly Reporting — Scheduled, branded security reports using your own template
🔍 Similar Incidents — See how the same detection was closed before, ranked by real overlap
⚙️ Alert Rule Auto-Update — Optional automatic application of published detection updates
Changes
🏗️ Added Functionality — All Customers
Monthly Reporting
Introduced automated monthly security reports, delivered on the day of the month you choose
Added a designed 20-slide default report: executive summary, incident trends, MITRE coverage, threat landscape, Secure Score, risky users, devices, and log source budget
Added custom template upload — your own PowerPoint deck replaces the standard design
Added company name and logo branding on the cover slide and every footer
Added slide exclusion by slide number
Added Microsoft Secure Score: current score, movement over the period, and open improvement actions
Added the top five Secure Score improvement actions, ranked by value for effort
Added device count and user/device change counts from Defender
Added a threat landscape briefing from security news feeds, with references
Added AI-written slide commentary, generated so the narrative matches the figures
Added on-demand report generation and a sample deck preview
Added delivery by email or ITSM channel, via a one-time download link
Added a permission pre-flight check with a link to the setup guide
Incidents
Added the Similar Incidents panel: past incidents from the same detection, with closure verdict, entity overlap, shared threat intel and match strength
Added row expansion showing the entities two incidents share
Added comments and Sentinel live status to the incident sidebar
Edit on an incident row now opens the incident directly in edit mode
Calibrate
Added Alert Rule Auto-Update: an optional setting that applies published template updates during the hourly calibrate run
Auto-applied updates produce the same changelog entry as a manual update
🏗️ Added Functionality — Multi Tenancy
Added a save confirmation naming the client count, since each config is written to that client's own tenant
Multi Tenancy can now manage their shared report template without first selecting a client
Channel selection now skips clients that cannot use it and names them
Added a per-client permission check, flagging clients that still need consent
Moved the Clients filter into the Client column as a header filter on incidents
Added auto-update rollout across clients, with per-client results
📊 Improved Features
Only connected ITSM integrations now appear in ticket creation, notification channels, Automated Reporting, and threshold pickers
Moved the client registry to the bottom of the navigation
Descending sort on Action now surfaces partially enabled tuning rules first
Custom tags are now prefilled in the noise reduction modal when already set
Threat intel now reads high/medium/low severity across summaries and graphs
The six-month incident trend now ends on the month being reported on
Added a confirmation before reverting to the default report template
Improved parsing of specific alert types and entities
🛠️ Bug Fixes — All Customers
Fixed MITRE filter pagination and close-all pagination
Fixed a manually generated report covering a different period than the scheduled one
Fixed truncated numbers in the executive summary
Fixed a fully spent log source budget showing a dash instead of 0
🛠️ Bug Fixes — Multi Tenancy
Fixed alert sorting returning a scrambled page when orphaned incidents were included
Fixed alert severity sorting alphabetically instead of by severity rank
Fixed sorting alerts by owner having no effect
Fixed client registry name sorting, and pagination repeating or skipping clients
Fixed the Clients filter chip appearing when nothing was filtered
Fixed the client delivery table stopping at 100 clients
Fixed switching client showing the previous client's template status

