Skip to main content

Finding Distribution

Understand how your organization’s findings are distributed by severity and status.

Updated over 5 months ago

Overview

This article explains the Finding Distribution section in Hyver, which provides a snapshot of how vulnerabilities are spread across different severity levels and remediation statuses.
It helps you assess the overall state of your cyber risk and track how issues are progressing.


The Finding Distribution view shows the percentage of findings categorized by:

  • Severity: Critical, High, Medium, Low, or Informative

  • Status: Open, To Do, In Progress, Reopen, and Fixed

Each percentage reflects the proportion of findings within a given severity that are in each status:


How severity levels are defined

Hyver uses a customized version of the CVSS 3.1 risk rating system to classify each finding based on business impact:

  • Critical – Immediate risk to core operations or essential business functions

  • High – Indirect risk to main operations, or direct risk to secondary processes

  • Medium – Partial or indirect risk to operations

  • Low – No immediate danger, but could be leveraged alongside other exposures

  • Informative – Not currently a risk, but recommended for remediation as a best practice

Note:
Informative findings appear in the Findings List, but are not shown in the Finding Distribution dashboard.


Wrap-up / Next Steps

The Finding Distribution view helps you quickly spot where your risk is concentrated — and where action is lagging. Use it to prioritize, communicate status, or drive remediation forward.

Did this answer your question?