Prioritise by combining what is affected, whether it is exposed, whether exploitation is known or likely, the vulnerability’s technical severity, the business consequence of compromise, available mitigations, remediation effort and accountable ownership. No single score should substitute for the organisation’s environment and consequence context.
External reference
CISA recommends KEV as an input to vulnerability-management prioritisation. FIRST documents EPSS as a 30-day exploitation-probability signal and CVSS v4.0 as a vulnerability-severity framework. NIST SP 800-40 Rev. 4 frames patch management as identifying, prioritising, applying and verifying updates within an enterprise strategy.
Primary source →Practical workflow
Establish asset and service context
Identify the affected asset, business service, owner, internet exposure, privilege, data sensitivity and recovery importance before ranking the finding.
Add exploitation evidence
Give explicit weight to known exploitation, credible exploitation evidence and current threat context. Treat CISA KEV as a strong prioritisation input where applicable.
Add exploit likelihood
Use EPSS as one time-sensitive probability signal for likely exploitation, not as a complete risk score or proof that exploitation will occur.
Interpret technical severity
Use CVSS to communicate technical characteristics and severity, then apply environmental and business context rather than treating a Base score as the entire risk decision.
Assign treatment and validate closure
Record the chosen treatment, accountable owner, due date, exception or compensating control, and verify that remediation or mitigation actually changed the exposure.
Relevant Cybatar sources
Claim boundary
Cybatar can structure vulnerability, asset, exposure, threat-context, ownership and remediation records. It does not guarantee that every vulnerability is discovered, that a score predicts exploitation, or that a remediation action removes every attack path.
These pages are Cybatar-authored exposure-management and vulnerability-prioritisation guidance. CISA, FIRST and NIST are external sources. References do not create certification, endorsement, guaranteed exploit prediction, guaranteed remediation outcomes or proof that a vulnerability affects a specific environment.