Cybatar Security Hub
Resources / Exposure Management
Exposure management

Prioritise exploitable exposure, then prove the treatment changed it

Connect vulnerability findings to affected assets, observed exploitation, exploit probability, technical severity, business consequence, accountable remediation and validation evidence.

Decision architecture

Five exposure-management decisions that should be explainable

A useful programme separates severity, threat evidence, likelihood, asset context and remediation proof rather than collapsing them into one number.

Exposure guide

Risk-based prioritisation

Prioritise by combining what is affected, whether it is exposed, whether exploitation is known or likely, the vulnerability’s technical severity, the business consequence of compromise, available mitigations, remediation effort and accountable ownership. No single score should substitute for the organisation’s environment and consequence context.

Open guide →
Exposure guide

CISA KEV prioritisation

If a vulnerability that affects your environment appears in CISA KEV, treat the known-exploitation evidence as a strong reason to accelerate review and remediation. First confirm affected assets and versions, then consider exposure, business consequence, available vendor action, compensating controls and remediation validation.

Open guide →
Exposure guide

EPSS prioritisation

EPSS estimates the probability that a published CVE will be exploited in the wild in the next 30 days. Use it to help rank remediation effort, especially when combined with known exploitation, technical severity and asset context. Do not treat EPSS as a complete risk score or as a prediction about a specific asset.

Open guide →
Exposure guide

CVSS v4.0 interpretation

No. CVSS v4.0 is designed to communicate vulnerability characteristics and severity. Use Base metrics for intrinsic characteristics, then consider Threat and Environmental information where available and combine the result with affected assets, exposure, exploitation evidence and business consequence.

Open guide →
Exposure guide

Remediation validation

Keep the original finding and affected asset context, the approved treatment, change or patch evidence, implementation time, exceptions or compensating controls, post-change validation, remaining exposure and reviewer/owner. Closing a work item is not the same as proving the vulnerability condition changed.

Open guide →
Evidence

Exposure Evidence Library

See the records that should explain prioritisation and prove remediation or mitigation was validated.

Explore evidence
Methodology

Keep KEV, EPSS and CVSS in their proper roles

Read the Cybatar rules for separating exploitation evidence, exploit probability, technical severity and organisational risk.

Read methodology
Platform

Exposure & Vulnerability Management

Review the Cybatar capability surface for asset, vulnerability, exposure, ownership and remediation workflows.

Platform capability