Cyver Core transitions your team from point-in-time assessments to automated, continuous vulnerability management.
Follow this onboarding flow to set up your CTEM operations: Templates > Scoping & Client Enablement > Discovery & Validation > Remediation, Insights & Delivery.
1. Preparing Your Templates
Setting up your core templates ensures your continuous scanning engine runs smoothly, handling data aggregation and automated reporting without manual intervention.
A. Create Your Report Template
Define the visual and structural output for your continuous assessment reports.
For a complete walkthrough on styling, Markdown, and using tokens, read our detailed guide on Customizing Report Templates.
B. Create Your Continuous Assessment Template
Bundle your reporting and automation logic into a repeatable template.
-
Configure Runs:
Set the Use case (Run-based or Real-time).
Data Updating Rules: On Run Complete, choose whether to Keep existing finding fields data or Override fields data with the new matched finding.
Finding Closure Rules: Define when to automatically close a finding (e.g., There is no matching Finding, or There is no matching Finding and Assets are up, but there are other Findings for the same Assets).
Enable Automatically generate report to keep stakeholders updated seamlessly.
-
Configure the Vulnerability Scanner: Select your integrated scanning tool and specify the Scan Engine.
For setup, target matching, and configuration of reNgine, read our guide on Integrated Vulnerability Scanner (reNgine).
To learn how to link your Tenable API keys and execute pre-configured scans, explore our guides on Integrated Vulnerability Scanner (Tenable Web App Scanning) and Integrated Vulnerability Scanner (Tenable Vulnerability Management).
Set the Default Finding Status: Determine where new vulnerabilities land (e.g., Draft, To Review, or Pending Fix).
Enable Weekly Scan: Toggle this on for true continuous coverage.
For a deeper dive into how the platform handles periodic scanning cycles versus live ongoing scenarios, read our guide on Continuous Projects.
2. Scoping & Client Enablement
Continuous management requires a clearly defined attack surface and the right stakeholders ready to receive alerts.
- Add Client: Navigate to Clients to create the dedicated workspace.
- Add Users: Invite the specific client stakeholders who need access to the reports and findings.
- Add Assets: Define the scope by adding the target URLs, IPs, or networks that will be tested.
For step-by-step instructions, refer to our Onboarding Clients article.
3. Discovery & Validation
This phase replaces static testing with an always-on scanning and validation engine.
A. Start a Continuous Assessment
Create a new project by selecting the Client and the Continuous Assessment Template you prepared.
B. Execute Discovery & Scanning
Integrated Scanners (reNgine & Tenable): Trigger on-demand scans manually from the Runs tab, or rely on the configured weekly schedule to run automatically.
Bring Your Own Scanner: If you use external tooling, you can easily import findings from your existing scanners directly into the project.
4. Remediation, Insights & Delivery
Transform raw, continuous data into actionable tickets and real-time metrics for your clients.
A. Streamlined Remediation & Ticketing
-
Ticketing Integrations: Push vulnerabilities directly to your work management platforms, ensuring developers can track and fix issues without leaving their native workflows. Cyver Core supports seamless workflows, including status and comment syncing, with major platforms:
To set up a one-way sync for client workflows, read our guide on ServiceNow Integration.
To configure two-way status and comment syncing via webhooks, explore our guides on Jira Integration (Client Portal) or Jira Integration (Pentester Portal).
To push findings and track remediation within Microsoft environments, check out our article on Azure DevOps Integration.
B. Monitor the Live Insights Dashboard
Instruct your clients to open the Insights tab within their continuous project. They can interact with real-time tracking data, including:
Summary: View open findings by severity (Pie Chart) and Vulnerability Type.
Runs: Analyze visualizations of Findings per run.
New vs Fixed: Track remediation progress and velocity across different runs.
Assets: View Open Findings distributed per asset.
Time to fix: A matrix tracking finding severity against total open days (aging).
Risk Summary: A heat map correlating the Severity of Business Impact with the Likelihood of Occurrence.
C. Real-Time Reporting
Automated Distribution: Reports automatically generate and distribute based on your Run settings, keeping clients informed and audit-ready with zero manual effort.