Understanding findings
External Monitoring scans may generate findings, which highlight potential security exposures or configuration issues detected on your organisation’s internet-facing assets. These findings help you quickly identify areas that may require review or remediation, improving visibility over your external security posture.
Each finding is assigned a severity level (for example: critical, high, medium, or low) to help prioritise what should be investigated first. This makes it easier to focus on the issues that may present the greatest potential risk.
How to check your Findings
Navigate to Monitoring (1) > Findings (2). Here you'll see various findings alongside their Severity Levels (3):
From here, click into any of the Findings, where you can:
Add finding notes - this is information you can add to each finding to help explain any context to your Clients
Scan now - at any point you can rescan an asset
Learn about severity - this shows a quick-guide on severity levels
In the section under All Findings this will unpack the finding itself and the issue
This section will explain the relevance of your finding in relation to the Severity Levels
Tip: If you find any incorrect results, please contact us at support@riskledger.com. Understanding any false positives or inaccuracies helps us improve the service.
What are Severity Levels?
Severity levels are used in External Monitoring to assess and categorise the potential impact and urgency of security vulnerabilities or misconfigurations. They help prioritise security issues and determine appropriate response times for remediation.
The following factors have been taken into consideration in setting the severity of monitoring findings:
Prioritisation: Higher severity issues should be addressed first
Resource Allocation: Critical and High issues require immediate attention and resources
Risk Management: Helps balance security needs with operational constraints
Compliance: Supports meeting regulatory and policy requirements
Communication: Provides clear framework for discussing security issues with stakeholders
Tip: You can leave additional context and information regarding any of your scans by going to Monitoring > Findings > Add finding notes.
You can also communicate this information by starting a Discussion directly in platform with any of your clients.
Severity Levels
Critical | Issues that indicate a significant security weakness and may require immediate attention. |
High | Notable security gaps or misconfigurations that could increase risk and should be reviewed as a priority. |
Medium | Areas where security controls may be present but could be improved to align more closely with best practices. |
Low | Minor improvements that may strengthen security posture but are unlikely to present immediate risk. |
Informational | Contextual observations from scans that may be useful for visibility or review but do not necessarily indicate a security issue. |
💡 If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.

