Prioritise exploitable exposure, then prove the treatment changed it
Connect vulnerability findings to affected assets, observed exploitation, exploit probability, technical severity, business consequence, accountable remediation and validation evidence.
Five exposure-management decisions that should be explainable
A useful programme separates severity, threat evidence, likelihood, asset context and remediation proof rather than collapsing them into one number.
Risk-based prioritisation
Prioritise by combining what is affected, whether it is exposed, whether exploitation is known or likely, the vulnerability’s technical severity, the business consequence of compromise, available mitigations, remediation effort and accountable ownership. No single score should substitute for the organisation’s environment and consequence context.
Open guide →Exposure guideCISA KEV prioritisation
If a vulnerability that affects your environment appears in CISA KEV, treat the known-exploitation evidence as a strong reason to accelerate review and remediation. First confirm affected assets and versions, then consider exposure, business consequence, available vendor action, compensating controls and remediation validation.
Open guide →Exposure guideEPSS prioritisation
EPSS estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Use it to help rank remediation effort, especially when combined with known exploitation, technical severity and asset context. Do not treat EPSS as a complete risk score or as a prediction about a specific asset.
Open guide →Exposure guideCVSS v4.0 interpretation
No. CVSS v4.0 is designed to communicate vulnerability characteristics and severity. Use Base metrics for intrinsic characteristics, then consider Threat and Environmental information where available and combine the result with affected assets, exposure, exploitation evidence and business consequence.
Open guide →Exposure guideRemediation validation
Keep the original finding and affected asset context, the approved treatment, change or patch evidence, implementation time, exceptions or compensating controls, post-change validation, remaining exposure and reviewer/owner. Closing a work item is not the same as proving the vulnerability condition changed.
Open guide →Exposure Evidence Library
See the records that should explain prioritisation and prove remediation or mitigation was validated.
Explore evidenceKeep KEV, EPSS and CVSS in their proper roles
Read the Cybatar rules for separating exploitation evidence, exploit probability, technical severity and organisational risk.
Read methodologyExposure & Vulnerability Management
Review the Cybatar capability surface for asset, vulnerability, exposure, ownership and remediation workflows.
Platform capability