Cyver Core transitions your team from disconnected, messy spreadsheets to a smart, digital vulnerability management system.
Follow this onboarding flow to set up your vulnerability management operations: Templates & Libraries > Client Enablement > Finding Management > Remediation, Insights & Delivery > Reporting.
1. Preparing Your Templates & Libraries
Establishing a strong foundation before importing data ensures your team isn't wasting time writing repetitive vulnerability descriptions or manually formatting documents. By pre-configuring your libraries and templates, you create a standardized, automated environment for all future findings.
- Build your Finding Library: Save your most common findings to effortlessly reuse data, including detailed descriptions, remediation advice, and default severities.
- Prepare your Report Template & Pentest Template: Configure your Report Template and Pentest Template to create a standardized container for your structured vulnerability data.
To learn how to build your organization's knowledge base and manage reusable vulnerabilities, explore our guide on Finding Libraries and Findings Templates.
For a complete walkthrough on styling, Markdown, and using tokens, read our detailed guide on Customizing Report Templates.
To learn more about bundling these settings, read our article on Customizing Pentest Templates.
2. Client Enablement & Integrations
Effective vulnerability management requires getting the right data to the right people. Setting up the client workspace and connecting it to their native ticketing systems ensures that remediation teams can act on vulnerabilities immediately without disrupting their existing workflows.
Add your Client: Navigate to the Clients tab to create a secure workspace and carefully onboard their specific users.
Ticketing Integrations: Connect the workspace directly to Jira, Azure DevOps, or ServiceNow so clients can seamlessly push vulnerability tickets into their developers' native backlogs.
Explore our guides on ServiceNow Integration, Jira Integration, and Azure DevOps Integration to learn more.
3. Project Setup & Finding Management
This phase transforms raw scan data into organized, actionable intelligence. By importing, automatically merging, and scoring your findings centrally, you eliminate duplicate entries and provide your clients with a clear, prioritized list of risks.
Start the Project: Click "+ New Pentest" using your prepared templates to initialize the live container for your data.
-
Import Findings: Pull data directly from scanners like Burp Suite or Nessus. Cyver Core keeps your finding list clean by automatically merging duplicates, and it auto-fills missing details based on matching rules from your templates.
To learn how to combine duplicate issues during an import, read our guide on Auto-merge findings with existing findings.
To learn how to automatically pull descriptions and remediation data from your library using Exact Text or Regex rules, check out Auto-merge findings with Library Templates.
Actionable Tickets: Deliver every vulnerability as an actionable ticket containing the description, proof-of-concept, and vital replication data.
Risk Assignment: Use the integrated CVSS calculator to accurately assign risk per finding so clients know exactly what to prioritize.
4. Remediation, Insights & Delivery
Once vulnerabilities are identified, the focus shifts to tracking progress and facilitating communication. The platform provides real-time metrics and secure channels to help clients manage patching and request retests effortlessly.
- Client Dashboards (Insights): Instruct your clients to check their Insights tab. They will see at-a-glance Visual Metrics, breaking down open findings per pentest, per asset, or by severity rating.
Finding Activity & Messages: Communicate securely with all history linked directly to the specific finding ticket.
Finding Retest Request: When a client fixes an issue, they can click "Request Retest" on the ticket to instantly notify your team. To learn how clients trigger these specific checks, read our guide on Request Findings to be retested.
Status Notifications: Automatically send client notifications when vulnerabilities are discovered, updated, re-tested, or when a severity rating changes.
5. Reporting
While live ticketing provides continuous updates, executive stakeholders often require a formal, point-in-time snapshot of the organization's security posture. Cyver Core allows you to generate these comprehensive summaries with just a few clicks.
- Automated Summaries: Even in a continuous or ticket-based workflow, management occasionally needs a formal summary. Navigate to the Report tab to instantly generate a branded PDF summarizing the current state of all managed vulnerabilities.
- For advanced reporting features and token management, explore our article on Generating, Changing, and Duplicating Report Templates.