I've fixed a risk, why has it not been resolved?
Hexiosec ASM implements various bespoke methods in the enumeration of attack surfaces and identification of risks. In addition, Hexiosec ASM uses some external sources for scan data.
Because some data is sourced externally, results may not yet reflect the change you have applied. In certain cases, Hexiosec ASM will remove results once they haven't been observed for a specified period. If this is the case it will be indicated in Hexiosec ASM.
For example, Hexiosec ASM may rely on an external service to determine whether an insecure protocol, such as FTP, is running on a discovered IP address and port. Hexiosec ASM represents IP address (or domain) and port pairs as a Service (e.g., 203.0.113.12:21). On the Service's Explore page you can see when it was last observed. If the protocol has since been disabled in your infrastructure, the page will also indicate when it is expected to be removed from your Hexiosec ASM scan results.