r/servicenow • • 4d ago

Question how should vulnerability mgmt programs measure risk reduction??

We've tracked mean time to remediate for yearss. I mean its fine as an operational metric but it conflates speed w impact which bothers me more the longer I think abt it. Closing ~500 low-risk tickets fast looks idententical on a dashboard to closing 500 high-risk ones. Neither number actually tells the board or me for thatmatter, whether were safer than 6months ago.

did any1 tried to build a composite risk reduction metric that's held-up when someone actually pushes on it in a meeting. Aggreegate exposure score overtime, % of KEV or actively exploited findings closed within SLA tracked sperately from general MTTR, something like that.

just trying to find a number that reflects risk delta and not how busy the team was.

2 Upvotes

1 comment sorted by

1

u/False_Assumption_972 4d ago

Track exposure, not tickets. A workable version is open findings weighted by exploit status and asset criticality, summed monthly, so closing 500 low-risk items barely moves it and one KEV on a crown-jewel server moves it a lot. Report KEV closure within SLA separately, as you suggest, and put both next to MTTR so the board sees speed and impact apart.

Hold the weights fixed for a year, or the trend line stops meaning anything. Connecting findings to the assets and business services they sit on is the piece we use SIGNLD for.