Skip to main content

User Knowledge Base

Incident Data

  • Finding Summary - Information about the identified cyber risk detected in a specified client footprint

  • Case Status - If the incident is resolved and closed by the ROC team or if it is open

  • Escalation Status:

    • In Review – The ROC reviews the finding before escalation.

    • Escalated to Client – The ROC escalated the finding to you.

    • Waiting for Third Party Response – The ROC expects a response from the company to support further investigation and remediation actions.

    • Overdue – The ROC did not get a response in the configured time.

    • In Dispute – The third party responds to an escalation with “No Plans to Resolve”, which they may do for a bad footprint, a finding that cannot be reproduced, a false-positive finding, or a finding that is not a priority for them.

    • Pending – The escalation response is “Will Resolve” or “Have Already Resolved”, and the escalation requires further action. If the third party responded with “Have Already Resolved”, the escalation is Pending until the ROC validates the remediation.

    • Risk Accepted – The escalation response is that remediation actions are scheduled.

    • Escalation Resolved – The finding is resolved but Open until the platform refreshes.

  • Time to Resolution - For each closed escalation, the time between the first escalation and the action to mark the escalation as resolved

  • First Escalated Timestamp - Date and time of first escalation

  • Escalation Resolved Timestamp - Date and time when the incident was marked as resolved

  • Case Number/ID - Unique identifier for each escalated incident

  • Portfolio – Portfolio of the monitored companies that have the incident

  • Attributes – Attributes of the monitored companies that have the incident

  • Company Name – Monitored company name

  • Company ID – Unique BlueVoyant entity ID