Understanding findings
Severity, confidence, evidence and rationale: how to read a Verisight finding.
A finding is a specific security problem Verisight observed, such as "TLS certificate on shop.example.com expires in 9 days" or "IAM user deploy has console access without MFA".
Evidence first
Every finding is produced by a deterministic rule from collected evidence. The same evidence always gives the same finding, and every finding links to the evidence behind it. Verisight does not report problems it can't show you.
What's on a finding
| Field | Meaning |
|---|---|
| Severity | Critical, High, Medium, Low or Info: how bad it would be if exploited. |
| Confidence | How sure the rule is that the problem is real. Lower confidence usually means the evidence is indirect. |
| Asset | The domain, host, cloud resource or package affected. |
| Rationale | Why the rule concluded this, in plain language. |
| Evidence | The raw observations, with collection time and source. |
| Remediation | How to fix it and how to check the fix worked. |
| Framework mappings | Related controls (NIST CSF 2.0, CIS, ISO 27001, Cyber Essentials, PCI DSS, GDPR, HIPAA) where they apply. |
Severity guide
| Severity | Suggested response |
|---|---|
| Critical | Act today, for example a known-malicious package or an attack path to admin. |
| High | Fix this week. |
| Medium | Fix this month. |
| Low | Plan it in. |
| Info | Context only, no direct risk. |
Severity comes from the rule, and is fixed for each rule version, so the same problem always has the same severity.
"Scan incomplete" findings
If part of a collection could not finish (a timeout, a missing permission, an advisory feed outage), Verisight reports a low-severity incomplete finding. Silence is never treated as safety. An incomplete scan is never shown as a clean bill of health, and it never improves your posture score.
Compliance mappings are not certification
A mapping means a finding is relevant to a control. Having no findings on a control does not prove the control is in place.