Credential Exposure
Leaked passwords, API keys, and identity data found in breach databases, paste sites, and dark web sources — the most direct path to account takeover.
Misconfigured Services
Exposed admin panels, public cloud storage, overly permissive APIs, and development interfaces left accessible to the public internet.
Open Ports & Services
Internet-facing ports and services that should not be publicly accessible — RDP, databases, management APIs, and legacy protocols.
Certificate Issues
Expired, misconfigured, and rogue TLS certificates that undermine trust, enable interception, and signal unauthorized infrastructure changes.
Attack Surface Overview
Return to the full external attack surface map — how all findings connect to your organization’s digital footprint.
Severity Levels
Every finding across all five categories is assigned one of four severity levels. Severity directly determines ALE, dashboard priority, and SLA for remediation guidance. The table below defines each level and its associated business impact range.
ALE figures represent the statistically expected annual financial loss if the exposure is left unaddressed. These figures account for both the probability of exploitation and the estimated impact of a successful breach, adjusted for your organization’s asset criticality and industry sector.
How Findings Are Scored
Leverage Cyber does not rely on a single metric to assign severity. Each finding is scored using a composite model that weighs five inputs:- CVSS Base Score — the technical severity of the underlying vulnerability, independent of your environment
- EPSS (Exploit Prediction Scoring System) — a machine-learning probability score indicating how likely a vulnerability is to be exploited in the wild within the next 30 days
- KEV (CISA Known Exploited Vulnerabilities) — whether the vulnerability appears on CISA’s authoritative list of actively exploited CVEs, which automatically elevates severity
- Asset Criticality — the business importance of the affected asset, determined during onboarding and refined through continuous monitoring
- Business Context — industry vertical, regulatory exposure, and prior incident history, which adjust the financial weight of each finding
Finding Lifecycle
Every finding moves through a defined set of states from initial detection to closure. These states are tracked in the Leverage Cyber dashboard and each transition updates your organization’s aggregate ALE in real time.
State transitions are logged with timestamps and optional notes, creating an audit trail for compliance reporting. When a finding moves to Resolved, Leverage Cyber re-checks the asset against its passive data sources to confirm the exposure is gone before removing its ALE contribution from your dashboard totals. Risk-accepted findings remain visible in the Closed state and contribute a discounted ALE value to reflect the residual risk.
Findings across different categories can be correlated into compound risk chains. A low-severity credential exposure finding — for example, a hashed password from an older breach — may appear manageable in isolation. Combined with an open RDP port on the same domain and a missing MFA policy, that same finding becomes part of a complete ransomware entry path and should be treated as Critical. Leverage Cyber surfaces these correlations automatically in the Risk Chains view of your dashboard.