>> All posts

Identified vs verified vs safe — why the middle word matters

Most security noise comes from treating three different states as the same word: found.

Something can be on a scan report, on a ratings feed, and on a pen-test slide — and mean three different levels of "should we drop everything?" If you don't separate those states, every list feels equally loud and the program drowns.

Three states, plain language

Identified — we can see this exposure from the outside (or from a scanner / inventory). It's on the map. It might matter. It might not. Identification is necessary. It is not proof.

Verified — we've confirmed it matters the way an attacker would care: reachable, exploitable in a meaningful sense, worth ranking against other real paths. Verification is where maybes become decisions.

Safe (or remediated / accepted) — you've closed the path, mitigated it so it no longer drives breach risk the same way, or formally accepted residual risk with eyes open. "Safe" is earned. It is not the default because a ticket was filed.

Where teams get stuck

HabitWhat it produces
Treat every identification as an emergencyAlert fatigue; nothing is urgent
Skip verification and "prioritize by CVSS"Queues that ignore live doors
Call something safe when it's only assignedFalse calm on the board deck
Live forever in identifiedEndless vuln lists, no breach-risk story

The middle word — verified — is the hinge. Without it, you're either guessing or drowning.

Why verification changes the score (and the meeting)

A BreachRisk Score that rolls up unverified noise will either cry wolf or lull you. Scoring from verified exposure keeps attention on paths that can actually contribute to a breach — which is also how you keep an industry-low false-positive posture without pretending false positives don't exist.

For leadership, the briefing gets simpler:

  • Here's what we identified this period (breadth)
  • Here's what we verified (the decision set)
  • Here's what moved to safe / accepted (progress)

That rhythm beats a 40-page dump of every CVE that matched a banner.

Continuous, or the middle word dies

Verification on an annual PDF ages out. Surfaces move. New doors open. The identified pile grows again while last year's "verified" list goes stale. Continuous outside-in assessment exists so verified stays current — not so you can print a thicker appendix.

Identified starts the work. Verified focuses it. Safe finishes a chapter. Don't let your tools collapse all three into one red badge.

See your cyber risk, proven.