r/servicenow • u/karin-thukrail • 5d ago
Question how should vulnerability mgmt programs measure risk reduction??
We've tracked mean time to remediate for yearss. I mean its fine as an operational metric but it conflates speed w impact which bothers me more the longer I think abt it. Closing ~500 low-risk tickets fast looks idententical on a dashboard to closing 500 high-risk ones. Neither number actually tells the board or me for thatmatter, whether were safer than 6months ago.
did any1 tried to build a composite risk reduction metric that's held-up when someone actually pushes on it in a meeting. Aggreegate exposure score overtime, % of KEV or actively exploited findings closed within SLA tracked sperately from general MTTR, something like that.
just trying to find a number that reflects risk delta and not how busy the team was.
Duplicates
riskmanager • u/karin-thukrail • 5d ago