Digital Risk Monitoring (DRM) scans a vendor's internet-facing infrastructure and shows you what an attacker could see from outside. It is the objective counterpart to the questionnaire: the questionnaire is what the vendor tells you, DRM is what their public footprint actually shows.
DRM runs off the vendor's primary domain, so a vendor with no domain on file has nothing to scan.
vendor:digital:view)Navigation: Sidebar → Vendors → [select a vendor] → Digital Risk
While this tab is open, a scan indicator appears in the tab bar alongside the vendor's onboarding status. It reads Scan Queued, Scan In Progress, Scan Completed or Scan Failed, and hovering it shows the scan's progress. If the scan is not currently running and you have the add-target permission, a restart control lets you kick off a fresh scan (you are asked to confirm first).
The top of the page is a band called Risk Overview & Metrics with four cards:
| Card | What it shows |
|---|---|
| Risk Score | The calculated risk level for the vendor's assets, based on vulnerability severity, impact and likelihood of exploitation, with a severity label |
| Likelihood of Exploitation | The estimated probability of the discovered vulnerabilities being exploited |
| Assets Inventory | The list of discovered internet-facing assets, including how many are WAF protected versus exposed |
| Findings by Severity | A doughnut chart of findings, with the Total Findings count in the centre |
If no risk score can be produced, the card tells you why: either no assets have been added yet, or no risk was detected on the assets that were found.
Below the metrics band are six tabs.
| Tab | What it shows |
|---|---|
| Overall Sections | Four summary cards — Exposed Ports, Technology Stack, Lookalike Domains and Exposed Cloud Findings — plus a Deep Risk Correlations panel |
| Asset Wise Risk Breakdown | The discovered assets listed individually with their risk |
| Exposed Secrets Found | Credentials and secrets detected in the vendor's public footprint |
| Threat & Breach Intel | Threat and breach intelligence gathered for the vendor |
| All Security Findings | Every finding, grouped by category, with the affected hosts |
| Graph Analysis | A visual graph of the vendor's assets and how they relate to one another |
Click any of the four cards — Exposed Ports, Technology Stack, Lookalike Domains or Exposed Cloud Findings — to open a side panel. The panel repeats a short description of what the category means and then lists the detail behind the number.
On the All Security Findings tab, each finding row has an Add Risk button.
The finding becomes a risk on the vendor's Manage Risk tab, with Risk Source shown as DRM. From there it goes through the same lifecycle as any other vendor risk — you can assign it, set a due date, track it through Pending → Planning → In Progress → Completed, and send it to the vendor for evaluation.
| Assessment type | Data source | Strength |
|---|---|---|
| Questionnaires | Vendor self-reported | Detailed internal controls and process information |
| Digital Risk (DRM) | External scanning | Objective view of the vendor's public exposure |
Use DRM to sanity-check questionnaire answers. If a vendor reports strong patching and DRM shows critical findings on their public estate, that gap is worth raising in the assessment review.
The Digital Risk tab shows a "not authorised" screen → Three things gate this tab. You need the vendor:digital:view permission, the vendor must have a primary domain on their profile, and DRM is not available on on-premises deployments. Check the vendor's profile for a domain first, then ask your administrator about the permission.
There is no data on the page → Confirm the vendor's primary domain is correct and publicly resolvable, then check the scan indicator in the tab bar. A queued or in-progress scan has nothing to show yet.
The scan indicator says Scan Failed → Restart the scan from the indicator if you have permission to do so. If it fails again, contact support with the vendor's domain.
A tab is empty even though other tabs have data → Each tab is fed by a different kind of check. A vendor can genuinely have, for example, no exposed secrets while still having security findings.
I clicked Add Risk but cannot see the risk → Open the vendor's Manage Risk tab. New risks arrive with status Pending; if a status filter card is selected at the top of that tab, click All to clear it.
The risk score looks different from the questionnaire compliance score → They measure different things. The risk score comes from externally observed vulnerabilities; compliance comes from the vendor's assessment responses.
Need more help? Contact support@zeron.one