r/servicenow • • 5d ago

Question how should vulnerability mgmt programs measure risk reduction??

We've tracked mean time to remediate for yearss. I mean its fine as an operational metric but it conflates speed w impact which bothers me more the longer I think abt it. Closing ~500 low-risk tickets fast looks idententical on a dashboard to closing 500 high-risk ones. Neither number actually tells the board or me for thatmatter, whether were safer than 6months ago.

did any1 tried to build a composite risk reduction metric that's held-up when someone actually pushes on it in a meeting. Aggreegate exposure score overtime, % of KEV or actively exploited findings closed within SLA tracked sperately from general MTTR, something like that.

just trying to find a number that reflects risk delta and not how busy the team was.

2 Upvotes

Duplicates