Skip to main content

Findings and Maturity Levels

Learn how findings influence subcategory maturity scores and how Hyver calculates their impact.

Updated over 5 months ago

Overview

In Hyver, findings linked to NIST subcategories contribute directly to maturity scoring. This article explains how severity, status, and type of finding affect the calculated maturity level — and what happens when findings are fixed, reopened, or updated.


How Findings Affect Maturity Scores

When a finding is linked to a subcategory, Hyver automatically incorporates it into the maturity calculation, but the specific impact depends on multiple factors:

Severity-Based Scoring

  • Critical or High severity → Maturity level 1

  • Medium or Low severity → Maturity level 2

  • Fixed findings

    • Manual fix: Default score 3 (editable)

    • Automatically fixed by Hyver: Default score 2

Note: Only findings of type Vulnerability are considered in maturity calculations.
Pre-open or Not Relevant findings are excluded from scoring.


Behavior of Linked Findings

  • The lowest maturity level among all linked findings is used for the subcategory score

  • If a finding is mapped to multiple subcategories, it affects all of them

  • When a finding is reopened, its maturity score resets based on severity

  • Permissions determine which findings appear in the Linked findings section


Updating and Managing Findings

You can modify the influence of a finding in several ways:

  • Fix a finding → maturity improves

  • Reopen a finding → score recalculates based on new severity

  • Change the maturity level manually after fixing

  • Delete, unmap, or mark as Not Relevant → finding is removed from scoring

All changes — including edits, status updates, and type conversions — trigger a recalculation of maturity scores and are tracked in the History tab.


Creating or Linking Findings

  • Findings can be linked to subcategories during creation or later via the Findings page

  • Only findings created via the maturity assessment screen are added to the Maturity Assessment engagement

  • You can only delete Hyver-generated findings if you have Finding & Graph Initiator permission


Wrap-up / Next Steps

Findings provide measurable input into your maturity model. By understanding how they're factored, you can better manage your score and create a more accurate reflection of your cybersecurity posture.

Did this answer your question?