Findings

Prev Next

Introduction

The Findings Center provides a centralized page for reviewing, investigating, and remediating cyber findings across your entire third-party portfolio.

Instead of reviewing findings separately within each third-party record, analysts can identify common findings affecting multiple third parties, understand the scale and severity of the exposure, review impacted assets, and create remediation issues directly from one place.

The Findings Center supports two sources of risk information:

  • Outside-In Findings: Findings identified through the external security assessment of third parties.

  • Questionnaire Findings: Findings generated from third-party questionnaire responses.

To access the Findings Center, navigate to:

  1. Third-Party Inventory > Findings

  2. Select the Outside-In or Questionnaire tab to switch between the two finding sources.

The information and actions available to you depend on your SAFE role and Third-Party module permissions.

Highlights

The Findings Center helps third-party risk teams:

  • Gain portfolio-wide visibility: Review findings affecting multiple third parties from one centralized page.

  • Identify systemic risks: Discover findings that are common across a large portion of the third-party portfolio.

  • Investigate findings faster: Review impacted third parties, affected assets, evidence, and recommended fixes without opening each vendor separately.

  • Reduce remediation time: Create issues for multiple impacted third parties in a single workflow.

  • Analyze questionnaire risk: Compare questionnaire responses across third parties and identify questions generating the most risk.

  • Build targeted dashboards: Create widgets that monitor specific findings, questionnaire responses, and third-party segments.

What the Findings Center Displays

Outside-In Findings

The Outside-In tab displays security findings identified through external assessments of your third parties.

Overview Metrics

The Overview section provides a summary of the Outside-In findings within the selected time period and active filter scope.

Metric

Description

Open Findings

Total number of findings currently active across the selected third parties.

High-Impact Findings

Findings assessed as having a higher potential impact.

New Findings

Findings first identified during the selected period.

With Issues

Findings that already have one or more linked remediation issues.

The metrics automatically update when you apply third-party or finding filters.

Outside-In Findings Table

Findings are grouped by normalized finding name. A single row can therefore represent the same finding across multiple impacted third parties.

The table displays the details of findings including, Findings Name, Security Domain, Severity, Impacted Third-Prties, Exposure Score, and other details.

Outside-In findings are grouped by Security Domain by default. You can change the grouping to Severity.

Questionnaire Findings

The Questionnaire tab converts third-party questionnaire responses into question-level findings that can be analyzed across the portfolio.

Questionnaire Overview

The Overview section displays:

Metric

Description

Total Questionnaires

Number of questionnaires represented in the Findings Center.

Total Questions

Total number of questionnaire questions available for analysis.

Questionnaire Findings Table

The table displays Questionnaire Findings details including questionaire name, questions name, and Impacted third-parties.

Column

Description

Questionnaire Name

Questionnaire containing the assessed question.

Question Name

Question used to evaluate the third-party response.

Impacted Third Parties

Number of third parties that failed or were impacted by the question.

% of Third Parties

Percentage of the filtered third-party population impacted by the question.

Create Issue

Opens the issue-creation workflow for the selected questionnaire finding.

Questionnaire Finding Status

  • Failed: Finding score is greater than 0

  • Passed: Finding score equals 0

Finding Details

Click a finding row to open the right-side detail drawer.

The drawer displays:

  • Finding Summary: The summary may include:

    • Finding description

    • Security domain

    • Severity

    • Exposure or finding score

    • Observation details

    • Available evidence

    • Current finding status

  • Impacted Third Parties: This section lists every third party affected by the selected finding. Expand a third party to review:

    • Impacted assets

    • Asset identifiers

    • Number of affected assets

    • Asset-level severity indicators

    • Other available asset context

  • Fixes: The Fixes section provides:

    • Recommended remediation actions

    • Suggested mitigation guidance

    • Available analyst notes

How to Search for a Finding

Outside-In Findings

  1. Navigate to Findings > Outside-In.

  2. Enter all or part of the finding name in the Search field.

  3. Review the matching findings.

  4. Clear the search field to return to the complete list.

Questionnaire Findings

  1. Use the available search to locate findings by questionnaire or question.

How to Group Outside-In Findings

  1. Navigate to Findings > Outside-In.

  2. Select the grouping control.

  3. Choose one of the following:

    1. Security Domain: Groups findings by their associated security category. This is the default selection.

    2. Severity: Groups findings according to their severity.

  4. Use Security Domain when analyzing the type of exposure. Use Severity when prioritizing findings based on urgency.

How to Investigate a Finding

  1. Locate the finding and click on it.

  2. Review the Finding Summary in the right-side drawer.

  3. Open the Impacted Third Parties section.

  4. Expand individual third parties to review impacted assets and identifiers.

  5. Review the Fixes section for recommended remediation guidance.

  6. Close the drawer to return to the complete findings list.

  7. Before creating issues, review the impacted third parties to confirm that the finding requires remediation for every affected vendor.