A finding doesn't always mean active compromise, but it does mean the configuration diverges from current best practice. Review exposure across:
Legacy protocol support (SSLv2/SSLv3, TLS 1.0/1.1)
Self-signed or expired certificates
Missing OCSP stapling or revocation checks
Weak signature algorithms or short RSA keys
Missing SANs or hostname mismatches