Skip to content
Avanet

Prioritize critical assets in Sophos Managed Risk

Use Critical Assets to identify systems whose failure or compromise would have a particularly serious impact on the organization. This designation gives the Managed Risk team additional business context for vulnerability reports and recommendations. In HTML reports, you can then display only the vulnerabilities affecting these assets.

Sophos allows a maximum of 25 Critical Assets. They are added one at a time and must already have been detected in an earlier Vulnerability Scan. This feature therefore replaces neither an up-to-date scan nor the technical assessment of a vulnerability.

Add a Critical Asset

Before adding an entry, identify the asset owner and its purpose. The description should clearly distinguish the system, for example Customer portal – Production – Owner Web team, rather than simply Server. Do not enter credentials or other secrets.

  1. Have the asset’s IP address or hostname ready.
  2. Go to My Products > Managed Risk > Settings > Critical Assets.
  3. Select Add Critical Asset.
  4. In the Configure Critical Asset Details side panel, enter the IP address or hostname under Search.
  5. Select the appropriate asset from the search results.
  6. Enter a meaningful description under Description.
  7. Select Save.

The new entry must then appear on the Critical Assets tab. Add further assets in the same way, one after another; multiple selection is not documented.

Change the description or remove the designation

Under My Products > Managed Risk > Settings > Critical Assets, the three-dot icon in the Actions column opens the available actions:

  • Edit changes only the Description. It does not let you replace the selected asset. To designate a different host as critical, delete the existing entry and add the correct one separately.
  • Delete removes the asset from the Critical Assets list. The documented operation does not delete the asset itself or change any scan configuration.

Before selecting Delete, confirm that the system is genuinely no longer business-critical or has been replaced. Then verify that the entry no longer appears in the list.

Review critical assets in the HTML report

The Critical Asset designation is visible in an HTML report. The display and filter functions below are not documented for CSV and PDF reports.

  1. Under My Products > Managed Risk > Report History, download the required Vulnerability Report in HTML format.
  2. Open the report.
  3. In the Assets list on the left, move the pointer over the asset name.
  4. In the popover, look for the Critical Asset label and the Critical Asset Description.

To view only affected critical systems, enable the Show critical assets only filter below the Assets list. The widgets at the top of the report then show the number of vulnerabilities on critical assets and the number of affected assets. This lets you assess the technical risk level together with the business context; the label alone does not indicate how to remediate a vulnerability.

Search shows only assets that have already been detected by a Vulnerability Scan. If the expected result is missing:

  1. Check the spelling, full hostname, and IP address, and try each search variant separately.
  2. Confirm that the appropriate external or internal Vulnerability Scan completed successfully and that this exact asset was included in the scan target.
  3. After a successful scan, search again under Settings > Critical Assets > Add Critical Asset.

Do not mark a similarly named host as a substitute. If the asset remains unavailable despite a confirmed scan, provide the scan target, scan result, and the IP address or hostname used for further investigation.

Maintain the list regularly

The 25 slots should reflect current business priorities. Review the list after systems are replaced or responsibilities change, as well as during the regular vulnerability review. For every entry, check that:

  • the asset still exists and continues to be covered by scans;
  • it is still business-critical;
  • the Description clearly identifies its purpose, environment, and responsible owner;
  • the designation appears as expected in the current HTML report.

This keeps the list focused and meaningful without replacing technical risk ratings or a complete review of all scan results.