Severity Levels Explained
What Severity Means
Severity indicates how important a finding is based on its potential impact and likelihood of exploitation.
It helps you prioritize which issues to address first.
Severity Levels
Steel Security assigns each finding a severity level:
High
High severity findings represent significant security risks.
These issues:
- may expose sensitive data
- may allow unauthorized access or execution
- are more likely to be targeted or exploited
Recommended Action:
Address these findings as soon as possible.
Medium
Medium severity findings represent moderate risks.
These issues:
- may increase your site's attack surface
- may contribute to larger vulnerabilities
- are important but not immediately critical
Recommended Action:
Review and resolve these findings in a timely manner.
Low
Low severity findings represent lower-risk issues.
These issues:
- may involve minor exposure or best-practice gaps
- are less likely to be exploited directly
- still contribute to overall security posture
Recommended Action:
Address these as part of routine maintenance.
How Severity Is Determined
Severity is based on a combination of factors, including:
- potential impact if exploited
- likelihood of exploitation
- level of exposure
- common attack patterns
Severity provides guidance, but does not replace judgment.
Severity Is Not Everything
While severity is important, it should not be the only factor in decision-making.
Consider:
- your specific environment
- whether the behavior is intentional
- how the finding relates to other risks
Some lower severity findings may still be important in your context.
How to Prioritize Findings
A practical approach:
- address high severity findings first
- review medium severity findings next
- resolve low severity findings over time
Also consider grouping related findings for more efficient fixes.
Avoid Overreaction
Not every finding requires immediate action.
Steel Security is designed to surface risks, not create urgency where it is not needed.
Take a measured and informed approach.
Key Principle
Severity helps guide your decisions, but effective security comes from applying multiple protections over time.