Contextualization of Third-Party Cloud Security Findings
Organizations: Sola Security, Tel Aviv, Israel
Abstract
Finding severity is the main driver of how security teams prioritize remediation. For third-party cloud security findings, that severity is static: the rule that raised the finding assigns it before the rule meets any environment, so it reflects the risk of the condition in general rather than the risk the finding poses to the concrete environment where it lives. Scoring standards define where environment-specific context belongs. How far that context changes finding severities in production, where the deciding evidence lies, and whether it holds against the live environment have not been measured. We address this gap with contextualization, re-deriving each finding's severity from evidence in the environment where the finding lives. A deep research agent over a precomputed cross-signal asset graph investigates each finding against the resource's state, its graph neighborhood, and other products' signals, and returns an adjusted severity with an evidence trace. We evaluate it in a production field study of 9,967 vendor HIGH findings from two commercial cloud security platforms across eight real production environments, on three criteria: the faithfulness of the facts behind each verdict to the live environment, the dependence of each decision on context beyond the flagged resource, and the regularity of the reasoning. Three in four findings are re-graded, mostly downward, and the same rule often moves in opposite directions inside a single environment. About half of the decisive evidence lies beyond the flagged resource, and read-only probes of live infrastructure confirm the decisive fact for 99.4% of decided findings.
Figures & tables
| Grade | Count | Share | A | B | Move |
|---|---|---|---|---|---|
| MEDIUM | 3,148 | 66.0% | 47.8% | 74.6% | down |
| CRITICAL | 950 | 19.9% | 26.9% | 16.6% | up |
| LOW | 555 | 11.6% | 19.1% | 8.1% | down |
| INFO | 119 | 2.5% | 6.2% | 0.7% | down |
| Criterion | Measure | Value |
| Faithfulness | Confirmed live, | 99.4% [99.1, 99.6] |
| inclusive, | 97.3% [96.7, 97.7] | |
| lower bound, | 81.8% [80.7, 82.8] | |
| Context dependence | Beyond the flagged resource, | 49.0% |
| graph neighborhood | 29.8% | |
| other products | 19.2% |