Skip to main content

Assess your risks

Use the EASM dashboard to assess your organization's external attack surface and cyber hygiene posture. The dashboard aggregates real-time scan data and historical trends, giving you actionable insights to identify and prioritize security risks across your environment.

Dashboard widgets help you understand your security posture, track remediation progress, and focus efforts on the highest-priority findings.

Prerequisites

  • You must have a UI user account with the Security Lead or Reviewer role.

Get access to the Dashboard

The Dashboard presents visual and contextual insights to support faster, data-driven decisions.

To complete this task:

  1. Sign in to the Veracode Platform.
  2. Select Scans and Analysis > EASM.
  3. From the top-left corner of the screen, select the project you want to review.
  4. Select the Dashboard or the dashboard icon dashboard_easm.png.

Filter search results in the Dashboard

Use filters to narrow the search results.

Filter results by business unit

Filter the search results to view department-specific or client-specific insights, such as those related to teams, subsidiaries, or clients.

To complete this task:

  1. Open the Dashboard.
  2. Select Project Scope.
  3. For Business Unit, select the required business unit.

Filter results by location

Filter the search results to view geographical distribution of assets and risks.

To complete this task:

  1. Open the Dashboard.
  2. Select Project Scope.
  3. For My things locations, select the required country.

Check application hygiene status

The Dashboard widgets color-code applications based on hygiene indicators.

  • Green: healthy (no findings detected)
  • Red: requires attention (findings detected)

Understand risk rating criteria

The following table outlines the risk rating criteria used to assess application cyber hygiene, ranging from A to F, based on the application security posture.

GradeLabelDescription
ASafeMaintains robust cyber hygiene with no outstanding findings. Follows industry best practices in web security.
BLowDemonstrates good security posture with minor areas for improvement. Actively manages risks, though some vulnerabilities may remain.
CMediumMeets basic security requirements but requires significant improvement. May use outdated software and could be vulnerable to advanced threats.
DHighLacks adequate security controls, resulting in multiple cyber hygiene findings. The environment is non-compliant and at elevated risk.
FCriticalFails to implement basic security measures. Uses outdated or insecure systems. Highly exposed and urgently requires a security overhaul.

Assess your organization's cyber hygiene posture in the Cyber Hygiene Resilience widget

Use the Cyber Hygiene Resilience widget to view your current hygiene grade, compare your grade across your last three scans, and track whether your security posture is improving using risk grades.

To complete this task:

  1. Open the Dashboard.
  2. In the Cyber Hygiene Resilience widget at the top-left of the Dashboard, review your organization's current hygiene grade and compare it against previous scans shown in the timeline at the bottom of the widget.
  3. Use the grade trends to identify whether your security posture is improving over time.

Prioritize findings by severity in the Findings by Severity widget

Use the Findings by Severity widget to identify the number of findings at each severity level, monitor total findings and track trends over time, and prioritize remediation efforts by risk level.

To complete this task:

  1. Open the Dashboard.
  2. In the Findings by Severity widget in the Dashboard, review the count of findings for each severity level.
  3. Review the total findings count and the trend indicator to understand whether findings have increased or decreased.
  4. Select View all findings to navigate to the Findings for detailed analysis and remediation recommendations.

Review asset inventory metrics in the Things Inventory widget

Use the Things Inventory widget to view the total count of each asset type, understand the composition of your external attack surface, and identify asset categories that require attention.

To complete this task:

  1. Open the Dashboard.
  2. In the Things Inventory widget on the Dashboard, review the asset counts for each asset type, including web applications, API endpoints, domains, mobile apps, and other infrastructure components.
  3. Select View all things to navigate to the Inventory for detailed information about specific assets.

Act on priority findings in the Priority Actions widget

Use the Priority Actions widget to identify findings requiring immediate action, view the affected asset and impact scope for each priority level (Fix now, Fix soon, Monitor, or Track), and access detailed findings and remediation steps.

To complete this task:

  1. Open the Dashboard.
  2. In the Priority Actions widget, review priority categories at the top and their finding counts.
  3. In the table, review each row to see the affected asset, type, and impacted thing count.
  4. Select a thing to open the inventory view with findings and remediation guidance.

Understand findings by category in the Findings by Category widget

Use the Findings by Category widget to identify high-impact risk categories in your environment, view finding counts by category, and understand your security concerns by risk type (Header Risk, SSL Service Risk, Domain Risk, and Certificate Risk).

To complete this task:

  1. Open the Dashboard.
  2. In the Findings by Category widget on the dashboard, review the risk categories and their finding counts using risk grades.
  3. Select a category to open the Findings view with affected assets and remediation guidance.

Track remediation progress in the Priority Trend widget

Use the Priority Trend widget to track trends in priority actions across scans, monitor remediation effectiveness, and assess changes in your security posture.

To complete this task:

  1. Open the Dashboard.
  2. In the Priority Trend widget on the Dashboard, review the stacked area chart showing the count of findings at each priority level over time.
  3. Use the trend to identify whether your remediation efforts are effectively reducing high-priority findings.

Assess email authentication in the Email Security Posture widget

Use the Email Security Posture widget to monitor authentication coverage across protocols (SPF, DKIM, DMARC), identify domains with incomplete or failing configurations, and assess resilience to email spoofing attacks.

To complete this task:

  1. Open the Dashboard.
  2. In the Email Security Posture widget on the Dashboard, review the compliance status for each protocol: SPF, DKIM, and DMARC.
  3. For any protocol showing partial or failing status, select it to open the Findings view with affected domains and remediation steps.

View global asset distribution in the Asset Locations widget

Use the Asset Locations widget to visualize asset distribution globally, identify high-risk regions at a glance, and access detailed country-level statistics including the number of impacted things, IP addresses, and remediation metrics.

The map uses bubble sizing to represent the concentration of impacted things in each region, so you can quickly identify geographic hotspots for security attention.

To complete this task:

  1. Open the Dashboard.
  2. To open the Asset Locations widget, from the Dashboard, locate the Asset Locations widget.
  3. Review the map visualization to understand global asset distribution. Bubble sizes represent the concentration of impacted things in each region.
  4. Expand the widget to view country-level IP addresses, impacted assets, and remediation metrics.

View findings by risk in the Heatmap widget

The Heatmap widget shows the security posture of discovered assets, grouped by asset type and graded based on externally observed risk.

To complete this task:

  1. Open the Dashboard.
  2. In the Heatmap widget, use the Thing type dropdown to select the asset type you want to review. Review the assets in the Heatmap. The Heatmap displays discovered assets for the selected type and assigns each asset a risk grade. Assets are sorted from the lowest grade to the highest grade, so you can identify assets with higher observed risk.
  3. To view more information about an asset, select its card. The asset inventory opens with the corresponding asset filtered.
  4. To view all assets of the selected type, select View all domains.