When a security event affects vendors in your portfolio, you can investigate the impact and coordinate follow-up directly from the event details page.
Investigating an event means reviewing which vendors are linked and why, assessing portfolio-wide impact, and reaching out to vendors for confirmation until the event is resolved.
Event status
On the My Network > Events page, the status badge shows one of: Active (ongoing), Investigating (under review), Reopened (a previously closed event has been reactivated), Closed (resolved), Archived (no longer actively tracked), or Retracted (withdrawn).
Investigate a security event
Selecting an event from the feed opens the event details page, consolidating external reporting, mapped vendor relationships, and investigation progress in one place.
Key sections include:
- Description: A summary of the event based on available sources, including details about the vulnerability, attack, or breach being reported.
- Impact summary: A portfolio-level view of how the event affects your vendors, with three subsections:
- Vendor impact translation: The number of vendors with confirmed exposure (red triangle) and potential exposure (circle) linked to the event.
- Response progress: A progress bar showing how many vendors have responded, have a pending response, or have not yet been contacted, along with the last activity date.
- Impact result: A donut chart breaking down vendors by outcome (Not impacted, Impacted, Potentially impacted).
- Timeline: When the event was first detected and when new sources or intelligence were added.
- Sources: The external articles, advisories, or intelligence used to identify and validate the event.
- Vendor overview table: A list of vendors potentially affected by the event, including the reasoning for the link, the vendor's last engagement date, and the outcome of the impact analysis.
Vendor overview panel
Selecting a vendor row opens a side panel with more detail about that vendor's connection to the event.
The Overview tab summarizes:
- Impact reasoning: Victim entity and Named victim mean the vendor was directly named in the source; Detected connection means the vendor was surfaced through a detected relationship, such as a fourth-party connection.
- Impact result: Potential (default, unconfirmed), Impacted, or Not impacted.
- Last activity: The most recent triage action taken on this vendor: Flag, Unflag, Initial request, or Follow-up request. Shows No activity if nothing has happened yet.
- Last engagement: The date of that most recent activity.
The panel also includes a Note section for internal team notes (not visible to the vendor), and an Impact evidence section listing sources the vendor was named in, plus any 4th-party connections. Each connection lists a detection method (HTTP Request, Detected Library, DNS, Breach, Products detected, TLS, or X.509), the specific evidence found, and when it was last detected.
Taking action on a vendor
In the Vendor overview table, select a vendor's Row actions icon (…):
- Request response is always available. It becomes Send follow-up once you've already sent a request to that vendor.
- Flag is available only for vendors with no logged activity yet. Once a vendor has any activity, Flag no longer appears in this menu.
To flag or unflag several vendors at once, including vendors that no longer show Flag in their row menu, select their rows using the checkboxes and use the bulk actions toolbar that appears above the table.
Escalating and reporting
At the top of the event page, Escalate to incident opens a dialog to record a reason, optional details, and evidence, and formally escalates the event's incident state. Download report exports the impact report.