Overview
Upload penetration test reports, quarterly assessments, or raw spreadsheets from other security tools exactly as they are—no reformatting required. This guide covers how the AI-assisted import workflow operates, how it improves upon the classic CSV import, and how CYE AI automatically enriches your data with asset mapping, business context, and remediation steps.
Prerequisite
Admin permissions — Only admin users can access the import flow.
CYE AI import license — Required for the AI flow. Without it, you can still use the classic CSV import.
A supported file — PDF, Excel, or CSV, within the size limits (details in Step 1). Convert or split the file first if needed; remove any password protection.
Steps
1. Upload your file
Go to the Findings page.
Click Import with CYE AI. A default Engagement will be created for the imported findings...
Select your file and upload it.
2. Automatic extraction and field mapping
Extracted data is mapped to the corresponding Cye platform fields.
CYE AI automatically fills missing mandatory fields using internal knowledge and matching logic.
3. The Validation Table
Following the upload, the platform displays the Validation Table. Data is not committed to the system until the Import action is triggered.
AI-Driven Enrichment Suggestions
When fields are missing or require optimization, CYE AI provides automated recommendations based on:
Internal mapping to the Cye Platform Findings Database
NIST ID correlations
MITRE ATT&CK mappings
Mitigation recommendations
Business impact estimation
The table distinguishes between two types of automated suggestions:
New Values: Populated when the source field was empty.
Replacement Suggestions: Recommended modifications to optimize existing data.
Interface Controls
AI Suggestion Icon (🪄): Hovering over this icon displays a comparison between the original value, the CYE AI recommendation, and the underlying rationale.
Apply All: Applies all system suggestions across the entire dataset simultaneously. ⚠️ This action cannot be undone in a single action, but you will still be able to edit individual cells afterward.
Inline Editing: Cells can be modified directly within the table, and individual rows can be deleted to exclude them from the final import.
What will happen to each imported finding
Each finding in your file is checked against the findings already in the platform and labeled with the import's result:
New: The entry represents a completely new finding.
Update: The entry modifies an existing finding within the platform.
Excluded: The entry cannot be imported. This occurs due to duplicates, format errors, or restricted access (e.g., the existing finding is in Restricted Share Mode and the current user lacks the necessary permissions).
Note: Hovering over a flagged row displays the specific transition reason (e.g., original value "Medium" adjusted to "Low").
4. Finalizing the Import
⚠️ Critical: Data commit actions are permanent. The Cye Platform cannot roll back or undo findings once the import process is finalized. Verify all data within the Validation Table before execution.
To complete the process, click Import. Upon completion, the platform displays an import summary detailing the following metrics:
New: The number of completely unique findings added to the platform.
Updated: The number of pre-existing findings that were modified or enriched.
Skipped: The number of entries excluded due to format errors, duplicate data, or restricted access permissions.
Imported findings are automatically mapped to the Findings page and can be isolated using the designated import filter.
Wrap-up / Next Steps
Review the new findings on the Findings page and prioritize remediation.
Imported findings automatically populate the platform's Exposure and Cybersecurity Maturity metrics, directly updating all dependent dashboards and reports.




