Skip to main content

Import Findings with CYE AI

Use AI to import findings from unstructured data sources like PDFs and Excel with automatic enrichment and field mapping.

Overview

CYE AI import turns the security files you already work with, such as maturity assessments and penetration test reports, into structured platform data, with no manual formatting or field mapping. From a single file, it extracts findings and the remediation assets linked to them, matches each finding to the Cye Platform Findings Database, and fills in missing details automatically. You confirm what is about to be imported, and the data flows into your Exposure and Cybersecurity Maturity metrics.

There is no editing step during import. To change a value, edit the source file before you upload it, or edit the finding on the Findings page after import.

Note: Some findings may not be imported

CYE AI imports only findings that match a recognized type in the Cye Platform Findings Database. Only recognized findings are imported and counted in your metrics. If no finding in your file is recognized, the import stops with an error (see If the import can't be completed, below).

The Findings Database grows over time, so re-importing the same file later may recognize more findings. You can also add findings manually from the Findings template library, by selecting a matching template or starting from scratch.


Prerequisite

  • Admin permissions — Only admin users can access the import flow.

  • CYE AI import license — Required for the AI flow. Without it, you can still use the classic CSV import.

  • A supported file — PDF, Excel, or CSV, within the size limits (details in Step 1). Convert or split the file first if needed; remove any password protection.


Steps

1. Upload your file

  • Open the import: On the Findings page, click Import with CYE AI.

  • Select the engagement: Choose the target Engagement for the imported findings.

  • Add the file: Drag and drop it, or click Choose a file. Supported formats are CSV, PDF, and XLSX, up to 50 MB.

  • Check the details: The File uploaded card shows the file name, type, size, and upload time. Click Next to continue, or replace file to choose a different one.

  • Processing

    The platform processes the file in the background after you click Next, and again after you execute the import.

    • What you see: A Processing screen with the file name, size, and upload date.

    • Keep working: You can leave this page. The status widget in the corner shows Import in progress, then a Review & confirm button when the step is done.

    • If processing fails: The widget shows Import failed with the reason. Click Replace file to return to the upload step.

    • Cancel at any step: Click Cancel. The file and everything extracted from it are discarded, and you return to the upload step.

  • What happens during processing

    • Extraction: CYE AI reads each item in your file and classifies it as a finding or a remediation asset.

    • Finding recognition: Each finding is matched to a recognized type in the Cye Platform Findings Database. Findings with no match are not imported (see Some findings may not be imported, below).

    • Enrichment: CYE AI fills empty fields and optimizes existing ones automatically, using the Findings Database and internal matching logic: NIST CSF mapping, MITRE ATT&CK, Security Domain, and remediation estimates. There is no manual step.

    • Fields that are never changed: Finding name, Severity, Summary, Description, Business impact, and Mitigation recommendations always keep the values in your file. If your file has no value for one of them, the matched Findings Database entry is used; if that has none either, the field stays empty.

  • Remediation assets

    • What is extracted: Each asset includes a name, type, unique identifier, and any additional fields from your file.

    • Asset type: Assets are classified to one of your company's existing asset types. If none matches, a new type is created automatically.

    • Linking: An asset is linked only to findings from the same file. If a finding already exists in the platform, the asset is added to that existing finding.

    • Existing assets: If an asset already exists in the platform, the import updates it in place. It is not duplicated.

    • Unrecognized findings: If a finding is not imported because it has no Findings Database match, its assets are not imported either, unless they are also linked to a finding that is.

    • Not preserved: Relationships between assets, such as a device mapped to a user.

2. Review & confirm

  • Counts per entity: The screen shows how many items are ready to import; for example Findings: 10 ready to import and Remediation assets (linked to findings): 7 ready to import. These are the items that can be imported, not everything found in the file.

  • Remediation assets toggle: Assets are included by default. Switch the toggle off to import findings only. Findings are always included.

  • No row-level review: This screen has no table, no editing, and no per-row status.

  • Execute: Click Execute Import. Processing runs again, and the status widget shows View summary when the import is done.

⚠️ Critical: Imports are permanent. The Cye platform cannot roll back findings or remediation assets once the import is executed. Check the counts and the toggle before you click Execute Import.

3. View summary

  • Results per entity: For findings and for remediation assets, the summary shows how many were imported (new and updated) and how many failed. Counts reflect the toggle you set on Review & confirm.

  • Fix failed rows: Click the download icon on the failed row to get a spreadsheet of the rows with errors. Correct them and upload that file again. You do not need to redo the whole import.

  • Open the results: Click the open icon on an imported row to see the Findings page filtered to this import.

  • Finish: Close returns you to the Findings page and ends the import session. Upload another file returns to the upload step.

  • Come back later: The summary stays available for about 30 hours, or until you click Close. Reopen it from the status widget (View summary) or by returning to Import.


How to identify Imported Findings in the findings page

  • Import tag: Every imported finding and remediation asset carries a tag made of the file name and the import date and time, in the format <file name> DDMMYY HHMM. Long file names are cut to fit; hover the tag to see the full name. For example, Acme-Pentest-Report-2026.pdf imported on 3 September 2026 at 08:40 gets the tag Acme-Pentest-Repor 030926 0840.

  • AI Import tag: Items imported with CYE AI also carry the tag AI Import. Filter by it to see everything that came through AI import, across all imports.

  • Filtering: On the Findings page, filter by either tag, by file name, or by import date. The Source field shows Import for both import methods.


If the import can't be completed


Processing stops and the platform shows This import couldn't be completed with the reason. Return to the upload step to try again with a corrected file. Common reasons:

  • No finding in the file matched a recognized finding type.

  • The file contains no security findings.

  • The file is password-protected or encrypted.

  • The file exceeds the row (500) or size (50mb) limit for a single import.


How existing findings are handled

  • Identity: A finding is identified by its name and its recognized type, within the engagement.

  • Identical finding exists: It is not imported again.

  • Finding exists with different values: It is updated with your file's values. The latest import always wins. The same rule applies to remediation assets.

  • Known limitation: When you re-import the same file, CYE AI may occasionally extract a finding name differently, which creates a duplicate. Delete duplicates from the Findings page.


Audit trail


Every import is recorded in the Events Audit log, tagged with an import ID that resolves to the file name, user, and time. Logged events:

  • Import started; processing completed or failed; import completed or failed

  • Each finding created or updated, with field-level before and after values

  • Each remediation asset created, updated, or linked to a finding

  • New asset types created during import

  • CYE AI enrichment applied, and any entities you excluded


Wrap-up / Next Steps

  • Review and edit: Open the Findings page filtered to your import tag, check the imported findings, and correct any value there.

  • Imported findings automatically populate the platform's Exposure and Cybersecurity Maturity metrics, directly updating all dependent dashboards and reports.

Did this answer your question?