---
title: "Main Dashboard"
canonical: "https://kb.cynergy.app/space/GS/719159352/Main%20Dashboard"
format: markdown
---
## his main dashboard page is designed to explain Cynergy’s main dashboard.  


On the top of the platform, you will see:

**“DOMAINS” **-  you can select and see the data related to this domain

** “PERIOD”**- you can select and see the data related to this time range.

### On the top of the dashboard, you will see your [Exposure Risk Score ](https://cynergy.atlassian.net/wiki/pages/resumedraft.action?draftId=719159352)defined by Letters from A-F

💡 *The risk score is based on the Common Vulnerability Scoring System Version 3.1 Calculator*

![image](media://df87715a-a29a-47ba-b570-e104c5f5b2d0)


### **“Prioritization”**

![image](media://e520c9e7-fa84-4e77-8b5e-5441cf71c596)


**Advisories are key actions that the client must take so that his organization will be safe. The advisories are based on several parameters:**

- *The organization size*
- *Number of employees*
- *Industry*
- *Regulatory needs*
- *Risk level and its impact*
- *The likelihood of being attacked*
- *Recent activity of hackers against the industry and the tactics they have used in order to breach the organization.*



| <u>**Advisory Examples**</u> | <u>**Reason**</u> |
| --- | --- |
| Conduct a Web Application Penetration Testing | Your website might be at risk due to:<br>- Threat Actors targeted attacks against E-Commerce websites is on the rise due to Coviud-19
- Risky E-Commerce functionalities
- Input field vulnerabilities
- Content Management System (CMS) may be prone to vulnerabilities<br>1. Consider doing the following:<br>- Conduct a Web Application Test on the website once a year.
- The set continues monitoring on the website |
| Set continues monitoring on your main websites | Your website might be at risk due to:<br>- Threat Actors targeted attacks against E-Commerce websites is on the rise due to Covid-19
- Content Management System (CMS) may be prone to vulnerabilities<br>Consider doing the following:<br>- Conduct a Web Application Test on the website once a year.
- Conduct continues monitoring on the website |
| Test you cloud environment for misconfiguration | Your cloud environment might be at risk due to:<br>- Misconfigured or privileged access to IAM
- A leak of secret keys
- Misconfiguration of your S3-Buckets. EC2 Instances<br>Consider doing the following:<br>- Conduct a monthly review of your cloud environment configuration
- Use generated report to identify the gaps in your environment
- Assign your DevOps to fix identified gaps |
| Test your infrastructure against vulnerabilities | Your infrastructure might be at risk due to:<br>- Open sensitive ports and services
- Misconfigured subdomains
- Old and vulnerable servers
- Misconfigured security controls<br>Consider doing the following:<br>- Constantly monitor your infrastructure by running an external and internal credentialed vulnerability assessment
- Conduct an external penetration test against your infrastructure assets once a year to identify gaps
- Conduct an internal penetration test against your infrastructure assets and domain once a year to identify gaps |
| Conduct an External Infrastructure Penetration Test | Your external infrastructure might be at risk due to:<br>- Open sensitive ports and services
- Misconfigured subdomains
- Old and vulnerable servers
- Misconfigured security controls<br>Consider doing the following:<br>- Conduct an external penetration test against your infrastructure assets once a year
- Constantly monitor your infrastructure by running an external and internal credentialed vulnerability assessment
- Conduct an internal penetration test against your infrastructure assets and domain once a year |
| Close publicly exposed S3 Bucket/s | Your client data might be at risk due to:<br>- An exposed S3 bucket with read and write permissions was identified.<br>Consider doing the following:<br>- Contact your DevOps to
- **Audit your security settings in AWS**
- Conduct an internal penetration test against your infrastructure assets and domain once a year |


### **Inventory**

![image](media://6eee29ce-1536-4b50-8919-4478eceebebd)


The inventory includes statistical information regarding your account. 

- TLD AMOUNT - The number of Top Level Domains associated with your account
- SUBDOMAIN DATA - The number of Live (Resolved) and Total subdomains identified for the selected domain/s
- WEB AND MOBILE APPS -The number of Web applications and Mobile applications identified for the selected domain/s
- CLOUD STORAGE - The number of exposed cloud storage instances identified vs the total number of cloud storage instances identified (e.g S3 buckets, GCP, and Azure blobs)
- CLOUD INSTANCE DATA - The number of exposed cloud instances identified vs the total number of cloud instances identified (Database instances, etc.)
- EMPLOYEES - The number of employee emails discovered, number of employees' leaked credentials identified, and clear text passwords for employees identified.
- ORGANIZATION - Data leaks and sensitive data leaks graph.