Organize Complex Security Findings with Finding Relations & Parent/Sub-Finding Hierarchy
Large penetration tests often uncover dozens—or even hundreds—of related issues. Managing these findings individually can make reports harder to navigate and reduce the clarity of the overall security story.
With Finding Relations and Parent/Sub-Finding Hierarchy, Cyver gives security teams a flexible way to organize findings into meaningful structures that mirror how real assessments are performed.
Whether you're grouping related vulnerabilities or breaking down a complex issue into multiple technical observations, your reports can now reflect that structure automatically.
Build Reports That Match Your Testing Methodology
Different engagements require different reporting styles.
Some assessments benefit from grouping related findings together—for example, several authentication weaknesses that contribute to the same attack path. Others require a hierarchical structure where a primary finding contains multiple technical sub-findings.
Cyver now supports both approaches:
- Finding Relations connect findings on the same level.
- Parent/Sub-Finding Hierarchy creates structured findings with nested child findings.
This allows your team to model vulnerabilities exactly as they are discovered during testing.

Group Related Findings
Many vulnerabilities are closely connected but should remain independent findings.
Finding Relations allow you to link these findings together, making it easier for consultants to understand dependencies and maintain consistency throughout the assessment.
Typical examples include:
- Multiple weaknesses contributing to the same attack scenario
- Related configuration issues across different systems
- Similar vulnerabilities affecting multiple applications
- Findings that share remediation recommendations
The relationships remain available throughout the engagement while keeping each finding individually manageable.

Create Structured Parent and Sub-Findings
For more advanced engagements, findings can now be organized into hierarchies.
A parent finding provides the overall security issue, while sub-findings document the individual technical observations that support it.
This is particularly valuable for:
- Complex attack chains
- Multi-step exploitation scenarios
- Infrastructure-wide security issues
- Large application assessments with multiple affected components
Instead of producing long flat lists of findings, reports become significantly easier to read while preserving all technical detail.
Automatically Generate Structured Reports
One of the biggest advantages of the new hierarchy is its integration with Cyver's reporting engine.
The complete finding structure can be mapped directly to report tokens, allowing report templates to automatically generate the desired layout.
This means:
- Parent findings appear with their associated sub-findings
- Related information is presented consistently
- No manual report editing is required
- Every generated report follows your organization's preferred structure
Consultants spend less time formatting reports and more time delivering valuable security insights.
Designed for Complex Assessments
Finding Relations and Parent/Sub-Finding Hierarchy are especially useful for:
- Enterprise penetration tests
- Red team engagements
- Multi-application assessments
- Infrastructure security reviews
- Long-term security projects with numerous findings
As engagements grow in complexity, your findings remain organized, traceable, and easy to communicate.
Why You'll Love It
- Organize findings in a way that reflects real-world testing
- Group related vulnerabilities without losing individual tracking
- Create parent and sub-finding hierarchies for complex issues
- Automatically generate structured reports using report tokens
- Reduce manual report editing and improve consistency
- Deliver clearer reports for both technical and executive audiences
See It in Action
Finding Relations and Parent/Sub-Finding Hierarchy help security teams transform large, complex assessments into clear, structured reports that are easier to understand, review, and act upon.
Ready to simplify complex penetration testing reports?

