How to Monitor Digital Risk (DRM)

How to Monitor Digital Risk (DRM)

Overview

Digital Risk Monitoring (DRM) scans a vendor's internet-facing infrastructure and shows you what an attacker could see from outside. It is the objective counterpart to the questionnaire: the questionnaire is what the vendor tells you, DRM is what their public footprint actually shows.

DRM runs off the vendor's primary domain, so a vendor with no domain on file has nothing to scan.


Prerequisites

  • A vendor whose profile has a primary domain set
  • The Digital Risk permission (vendor:digital:view)
  • A cloud (SaaS) deployment — the Digital Risk tab is not available on on-premises installations

Opening Digital Risk

Navigation: Sidebar → Vendors → [select a vendor] → Digital Risk

  1. Click Vendors in the sidebar.
  2. Click the vendor you want to look at.
  3. Open the Digital Risk tab.

While this tab is open, a scan indicator appears in the tab bar alongside the vendor's onboarding status. It reads Scan Queued, Scan In Progress, Scan Completed or Scan Failed, and hovering it shows the scan's progress. If the scan is not currently running and you have the add-target permission, a restart control lets you kick off a fresh scan (you are asked to confirm first).


Risk Overview & Metrics

The top of the page is a band called Risk Overview & Metrics with four cards:

CardWhat it shows
Risk ScoreThe calculated risk level for the vendor's assets, based on vulnerability severity, impact and likelihood of exploitation, with a severity label
Likelihood of ExploitationThe estimated probability of the discovered vulnerabilities being exploited
Assets InventoryThe list of discovered internet-facing assets, including how many are WAF protected versus exposed
Findings by SeverityA doughnut chart of findings, with the Total Findings count in the centre

If no risk score can be produced, the card tells you why: either no assets have been added yet, or no risk was detected on the assets that were found.


The Six Analysis Tabs

Below the metrics band are six tabs.

TabWhat it shows
Overall SectionsFour summary cards — Exposed Ports, Technology Stack, Lookalike Domains and Exposed Cloud Findings — plus a Deep Risk Correlations panel
Asset Wise Risk BreakdownThe discovered assets listed individually with their risk
Exposed Secrets FoundCredentials and secrets detected in the vendor's public footprint
Threat & Breach IntelThreat and breach intelligence gathered for the vendor
All Security FindingsEvery finding, grouped by category, with the affected hosts
Graph AnalysisA visual graph of the vendor's assets and how they relate to one another

Working with the Overall Sections cards

Click any of the four cards — Exposed Ports, Technology Stack, Lookalike Domains or Exposed Cloud Findings — to open a side panel. The panel repeats a short description of what the category means and then lists the detail behind the number.


Turning a Finding Into a Tracked Risk

On the All Security Findings tab, each finding row has an Add Risk button.

  1. Find the issue you want to act on.
  2. Click Add Risk on that row.

The finding becomes a risk on the vendor's Manage Risk tab, with Risk Source shown as DRM. From there it goes through the same lifecycle as any other vendor risk — you can assign it, set a due date, track it through Pending → Planning → In Progress → Completed, and send it to the vendor for evaluation.


How DRM Complements Questionnaires

Assessment typeData sourceStrength
QuestionnairesVendor self-reportedDetailed internal controls and process information
Digital Risk (DRM)External scanningObjective view of the vendor's public exposure

Use DRM to sanity-check questionnaire answers. If a vendor reports strong patching and DRM shows critical findings on their public estate, that gap is worth raising in the assessment review.


Troubleshooting

The Digital Risk tab shows a "not authorised" screen → Three things gate this tab. You need the vendor:digital:view permission, the vendor must have a primary domain on their profile, and DRM is not available on on-premises deployments. Check the vendor's profile for a domain first, then ask your administrator about the permission.

There is no data on the page → Confirm the vendor's primary domain is correct and publicly resolvable, then check the scan indicator in the tab bar. A queued or in-progress scan has nothing to show yet.

The scan indicator says Scan Failed → Restart the scan from the indicator if you have permission to do so. If it fails again, contact support with the vendor's domain.

A tab is empty even though other tabs have data → Each tab is fed by a different kind of check. A vendor can genuinely have, for example, no exposed secrets while still having security findings.

I clicked Add Risk but cannot see the risk → Open the vendor's Manage Risk tab. New risks arrive with status Pending; if a status filter card is selected at the top of that tab, click All to clear it.

The risk score looks different from the questionnaire compliance score → They measure different things. The risk score comes from externally observed vulnerabilities; compliance comes from the vendor's assessment responses.


Need more help? Contact support@zeron.one

    • Related Articles

    • How to Review Vendor Risk Scores

      Overview Vendor Pulse shows vendor risk in three places, each answering a different question: Where Question it answers Profile tab on a vendor How risky is this vendor overall? Manage Risk tab on a vendor What specific risks are open, and who is ...
    • How to Send Risk Assessments to Vendors

      Overview Separately from questionnaire assessments, Vendor Pulse lets you send specific identified risks to a vendor and ask them to respond. The vendor logs in to a portal, describes how they will handle each risk, uploads supporting evidence, and ...
    • How to Generate Vendor Risk Reports

      Overview Vendor Pulse produces two kinds of report, and both are generated per vendor: Report Format How it is produced Executive PDF You add a remark and optional recipients, then generate Detailed Excel workbook Generated immediately, no extra ...
    • How to Manage the Vendor Risk Lifecycle

      Overview Every vendor has a Manage Risk tab where you record the risks that vendor represents and work each one through four stages, from initiation to closure. Prerequisites At least one vendor in the platform vendor:risk:view to open the tab; ...
    • Vendor Pulse: Frequently Asked Questions (FAQ)

      Overview Answers to the questions we hear most often about Vendor Pulse, Zeron's third-party risk management (TPRM) product. Prerequisites A Vendor Pulse account For anything involving permissions, an administrator who can change your group Getting ...