Verisight Help Center Support ticket Open portal

Understanding findings

Severity, confidence, evidence and rationale: how to read a Verisight finding.

A finding is a specific security problem Verisight observed, such as "TLS certificate on shop.example.com expires in 9 days" or "IAM user deploy has console access without MFA".

Evidence first

Every finding is produced by a deterministic rule from collected evidence. The same evidence always gives the same finding, and every finding links to the evidence behind it. Verisight does not report problems it can't show you.

What's on a finding

Field Meaning
Severity Critical, High, Medium, Low or Info: how bad it would be if exploited.
Confidence How sure the rule is that the problem is real. Lower confidence usually means the evidence is indirect.
Asset The domain, host, cloud resource or package affected.
Rationale Why the rule concluded this, in plain language.
Evidence The raw observations, with collection time and source.
Remediation How to fix it and how to check the fix worked.
Framework mappings Related controls (NIST CSF 2.0, CIS, ISO 27001, Cyber Essentials, PCI DSS, GDPR, HIPAA) where they apply.

Severity guide

Severity Suggested response
Critical Act today, for example a known-malicious package or an attack path to admin.
High Fix this week.
Medium Fix this month.
Low Plan it in.
Info Context only, no direct risk.

Severity comes from the rule, and is fixed for each rule version, so the same problem always has the same severity.

"Scan incomplete" findings

If part of a collection could not finish (a timeout, a missing permission, an advisory feed outage), Verisight reports a low-severity incomplete finding. Silence is never treated as safety. An incomplete scan is never shown as a clean bill of health, and it never improves your posture score.

Compliance mappings are not certification

A mapping means a finding is relevant to a control. Having no findings on a control does not prove the control is in place.