SPM Alerts Overview Jessica Without automated processes to help you along the way, managing and monitoring the security trends of a growing ecosystem can be time-consuming and costly. Alerts allow your organization to automate how you monitor rating changes and changes to risk vector grades. You can subscribe to receive email alerts. Edit and enable alerts from the Configured Alerts page [ Alerts ➔ Configured Alerts.Alert GenerationThe alert generation process can take up to 2 days. Alerts are generated from changes in data. Though ratings and the underlying analytics data are updated daily, there’s a 1 to 2-day lag.Available Alert TypesBitsight Rating Bitsight Rating alerts notify you when a company’s security rating changes by a specified number of points. Configuration Options: You can select to be notified for a point increase, a point decrease, or both, then specify the point change to notify you of. Exposed CredentialsExposed Credentials alerts notify you when we find new Exposed Credential findings for your chosen company.Infrastructure Changes Infrastructure Changes alerts allow you to specify criteria and receive alerts when new CIDRs/IP addresses or domains are observed that meet it. This alert type is only available with the EASM Enhanced Module. Not available for Shell companies because they don’t have any attribution, so there won’t be any alerts to show. Configuration Options: You can select the asset type (IP Address or Domain) and the type of infrastructure change (Addition, Removal, Expiration, or Renewal) included in the alert. Alert content: Each alert lists infrastructure changes grouped by Subsidiary and change type. If there were no changes in the previous day, this section will not appear in the email. New Findings New Findings alerts allow you to specify criteria and receive alerts when new findings are observed that meet it. This alert type is only available with the EASM Enhanced Module. Configuration Options: You can use quick settings and filters to configure alerts for specific kinds of new findings. A sample of findings that meet your criteria are shown in the Matching Findings table. Public Disclosures Public Disclosures alerts notify you when Public Disclosure events related to your company occur, including the following: Breach Security Incidents: Serious events that usually result in a successful cyberattack and/or data compromise by unauthorized individuals. These are ratings-impacting. General Security Incidents: Other kinds of security events that may still affect security ratings. These are considered more severe than Other Disclosures. Some of these incident types are ratings-impacting, while others are informational only and do not impact the rating. Other Disclosures: Other kinds of publicly disclosed incidents. It’s considered to be the least severe among the Public Disclosures incident categories. Its impact to business continuity is minimal if they were to occur. Therefore, these are informational and do not currently affect Bitsight Security Ratings. Configuration Options: Select which event types to include in the alert. You can choose to include breach security incidents, general security incidents, or other disclosures. Vulnerabilities & Infections Vulnerabilities & Infections alerts notify you when new vulnerabilities are detected for the Open Ports and Critical Vulnerability Management risk vectors or when infections are found for Compromised Systems risk vectors. Only confirmed vulnerabilities can trigger alerts. Risk Vector Grades Risk Vector Grades alerts notify you when specific risk vector grades change. Configuration Options: You can specify which risk vectors to include in your alert and whether you want to be notified in the event of a grade increase, a grade decrease, or both. Related articles Alerts: Configured Alerts Quick Setting for New Findings Alerts Finding Behavior Request a Rescan in the SPM App TLS/SSL Finding Remediation & Remediation Verification Feedback 0 comments Please sign in to leave a comment.