> ## Documentation Index
> Fetch the complete documentation index at: https://syteca.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# How to identify high-risk endpoints

> Identify endpoints with critical health scores, review the risk factors contributing to their condition, and access remediation guidance to improve endpoint and overall system security posture.

## Procedure

1. Navigate to the [Dashboard](/docs/espm/dashboards-page) page.
2. Identify endpoints with a **Critical Health** rating:
   * If more than ten endpoints have critical health, click the **Critical Endpoints** card in the **System Security Posture** widget, or click the **D** section of the **Endpoints Health** widget. The **Endpoints** page opens with a health filter applied, displaying only endpoints with the lowest health scores.
   * If fewer than ten endpoints have critical health, use the **Top 10 Lowest Health Endpoints** widget to quickly identify affected endpoints.
3. Select the endpoint you want to investigate.
4. On the  [Endpoint details](/docs/espm/endpoints/endpoint-details)  page, review the **Risk Factors** grid to see all active risk factors affecting the endpoint.
5. Sort the grid by the **Risk Score** column to identify the most critical risks first.
6. Expand individual risk factors to review available technical details and determine the underlying cause of the issue.
7. To view detailed remediation guidance, click the risk factor to open the [Risk factor details](/docs/espm/riskfactors/risk-factors-details) page.
8. [Remediate](/docs/espm/riskfactors/recommend-and-remedy) the identified issues on the endpoint.
9. After the endpoint reports updated probe results, the platform automatically recalculates:
   * Endpoint Health Score
   * Policy Health Scores
   * Control Health Scores
   * Overall System Health Score

## Key Considerations

* Prioritize risk factors with the highest **Risk Score**, as they typically have the greatest impact on endpoint health.
* Health scores are updated only after the platform receives new probe results from the endpoint.
* If the endpoint is offline, health scores remain unchanged until it reconnects and synchronizes its latest data.

## Related

<CardGroup cols={2}>
  <Card title="How to benchmark organizational security posture" icon="workflow" href="/docs/espm/howto/how-to-benchmark-security-posture">
    Use dashboard widgets to compare security posture across endpoint groups, identify organizational security trends, and prioritize remediation efforts based on health scores, active risks, and policy compliance.
  </Card>

  <Card title="How to assess and improve policy compliance" icon="workflow" href="/docs/espm/howto/how-to-check-and-improve-policy-compliance">
    Review policy compliance across your environment, identify non-compliant endpoints and risk factors.
  </Card>
</CardGroup>
