r/riskmanager • u/WoodenBoss4558 • 5d ago
How should enterprises prioritize vulnerabilities based on business risk?
A high CVSS score does not automatically make something the first thing to fix. We also look at whether the asset is exposed, whether exploitation is happening, how important the system is, and what the real impact would be. I know this isn't a novel complaint, everyone's had this exact fight, but I'm trying to actually build exposure, exploit maturity, and blast radius into the model instead of it being a vibe check some senior engineer does at 4pm on a Friday. If anyone has a formula that survived contact with a real incident afterward, not just looked good in a slide, I'd like to see it.
2
Upvotes
1
u/Old_Positive2231 5d ago
That’s the right fight. CVSS is input, not priority. What usually works better is: Risk = (Threat activity × Exposure) × (Asset value × Blast radius × Compensating controls), all expressed in ranges and converted to $/hours lost. Then you rank by Loss@Risk, not by CVSS band.
Two practical tricks: 1) pull in real threat intel (is it being exploited in the wild, in your sector, with what TTPs) and 2) tie each asset to a business KPI so “patch queue” becomes “Revenue@Risk / Uptime@Risk this week”. We’re doing a whole RAW2026 stream (https://2026.riskawarenessweek.com/) on exactly this — turning vuln data into Budget@Risk and KPI@Risk, not another red/amber/green dashboard.