Overview
In the Cye Exposure Management Platform, technologies such as EDR or SIEM can be linked to NIST subcategories to reflect the organization's security tooling. These linked technologies contribute positively to the maturity score — as long as they genuinely enhance coverage. This article explains how linked technologies are scored, how to add them, and when to create a finding instead.
How Technologies Affect Maturity Scores
Linked technologies are assigned a default maturity level of 3
This value is editable
The Cye platform incorporates this score only if it increases the subcategory's existing score
Example: If a subcategory score is 2.5, a linked technology with a value of 3 will raise it
If the subcategory score is already above 3, the technology will be ignored to avoid lowering the score
Changing a technology's maturity level updates all subcategories it's linked to
When to Use a Finding Instead
If a technology provides only partial coverage or needs to be supplemented with additional tools:
Create a finding to represent the shortfall
This helps reflect the gap accurately and ensures the maturity score isn't overestimated
Once the gap is resolved and the finding is marked fixed, the technology's full positive impact on the maturity score is restored
Adding Technology Assets
Option 2: From the Maturity Screen
Asset creation can also be started directly from a subcategory, instead of from the Assets page:
In the Linked Technologies section of a subcategory, click the + button to start the asset creation process:
Option 1: From the Assets Page
Go to the Assets page
Add a Suggested Technology
Complete the Asset Form
Fill out required fields, including:
Technology type (e.g., SIEM) — see the full list of supported types below
Tool name
Engagement (choose one or use a dedicated one for separation)
Function, Category, Subcategory (under the primary framework only)
Click Create
Note: One technology asset can be applied to multiple subcategories if relevant. Only one asset can be created at a time — repeat as needed.
Using a technology that isn't in the predefined list?
Using a technology that isn't in the predefined list?
If your organization uses a security tool that isn't listed among the predefined technology types on the Assets page, it can still be represented and contribute to maturity scoring:
Select Security Technology as the asset type — this flags it as a custom technology for maturity scoring
Enter a tool name (e.g., "Internal Threat Analytics")
Choose an engagement, and assign the asset to a NIST subcategory under the primary framework, the same as above
Click Create — the custom technology will appear as a linked technology on the maturity assessment screen for the selected subcategory
Full List of Technology Asset Types
API Security
Asset Management
Backup and Recovery Systems
BAS (Breach and Attack Simulation)
BMS (Building Management System)
CASB (Cloud Access Security Broker)
CDR (Content Disarm and Reconstruction)
CNAPP (Cloud Native Application Protection Platform)
CRQ (Cyber Risk Quantification)
CSPM (Cloud Security Posture Management)
DAST (Dynamic Application Security Testing)
Data Flow Mapping Tool
Database Firewall
Database Web Application Firewall
Deception Tools
Digital Forensic Software
DLP (Data Loss Prevention)
DNS Security Tools
EDR or XDR (Endpoint Detection and Response)
EFSS (Enterprise File Sync and Share)
Email Security
Firewall
Firewall Analyzer
GRC (Governance, Risk & Compliance)
IDP or IAM (Identity and Access Management)
IDS or IPS (Intrusion Detection and Prevention System)
KMS (Key Management Service)
MDM (Mobile Device Management)
MDR (Managed Detection and Response)
NAC (Network Access Control)
PAM (Privileged Access Management)
Password Management Vault
Patch Management
Reverse Proxy
Safe Browsing
SAST (Static Application Security Testing)
Secure Web Gateway
SIEM (Security Information and Event Management)
SOAR System (Security Orchestration, Automation and Response) & Automated Playbooks
SSO (Single Sign On)
TIP (Threat Intelligence Platform)
URL Filtering
Vendor Management
VM (Vulnerability Management)
Vulnerability Assessment and Network Scanning
WAF (Web Application Firewall)
Zero Trust Network Access (ZTNA)
Important Notes
Technology assets directly influence maturity scoring in Cye
Cye itself is automatically added as a CRQ (Cyber Risk Quantification) technology asset:
You can edit or remove NIST subcategory assignments later if needed
Wrap-up / Next Steps
Linking technologies is a smart way to show investment in protective tools and improve the maturity score — but only when the tools are meaningful and mapped correctly. Review assets regularly and make sure they reflect the real state of the security posture.
For the full list of technologies Cye supports and their NIST mappings, see the Appendix: Supported Mitigations and Their NIST Mapping.











