68
Conditional

fireeye.com

Security posture assessment · Scanned February 15, 2026

Findings
4 · 2 · 0
Checks
8 passive

fireeye.com scored 68/100, meeting baseline requirements but with 2 findings that require attention. The vendor can proceed with a remediation timeline agreement.

Positive signals: TLS Configuration, DNS Configuration, Known Breaches all passed.

2 action items identified, including 0 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.

Ordered by priority · 2 items
1
Strengthen email authentication configuration
Effort: 2–4 hours   Owner: IT / DNS administrator
high
Email authentication is partially configured for fireeye.com but has gaps. Actions needed: add SPF record. Until DMARC enforcement is active, spoofed emails may still reach recipients.
Compliance Impact
NIST CSFPR.AC-7
Email authentication is a required access control
Remediation Steps
1
Add SPF record if missing: v=spf1 include:_spf.google.com -all
2
Verify with: nslookup -type=txt _dmarc.fireeye.com
2
Review certificate configuration
Effort: 1–2 hours   Owner: Infrastructure / DevOps
low
Certificate issues found for fireeye.com: wildcard certificate in use. Wildcard certificates have a broader blast radius if compromised. These are operational hygiene items, not immediate security risks.
Remediation Steps
1
Consider replacing wildcard cert with individual certs for critical subdomains
2
Consolidate certificate issuance to 1–2 trusted CAs
DMARC / Email Security
Warning
Certificate Hygiene
Warning
HSTS Header
Error
Security Headers
Error
TLS Configuration
Healthy
DNS Configuration
Healthy
Known Breaches
Healthy
CVE Exposure
Healthy