Best practices
15 articles.
When CVSS (and EPSS / KEV) still belong in the room
Breach risk isn't a CVSS average — but CVE context still earns a seat once a path is real. Here's how to use CVSS, EPSS, and KEV without letting them run the whole program.
So HIPAA is on your plate — here's where to start
A healthcare customer or product decision just made HIPAA your problem. Clarify whether you're a covered entity or business associate, what PHI you actually touch, and how to spend the next 30 days without guessing regulatory details.
So you're being asked for ISO 27001 — here's where to start
An international customer asked for ISO 27001. Before you buy a binder or book a stage audit, clarify whether they want certification, a statement of applicability story, or 'aligned' — then follow this 30-day start plan.
Talk to clients about breach risk without scaring them
A BreachRisk Score in a QBR should build trust, not theater. Here's how service providers can present outside-in findings — calm, ranked, and actionable — so clients lean in instead of tuning out.
So you have to do PCI DSS — here's where to start
Card data or a payment flow just made PCI DSS your problem. Before you memorize requirements, clarify scope, who is assessing you, and what 'done' means for your business — then use this 30-day starter map.
How to brief the board on breach risk without fear-mongering
Scare decks burn credibility. A calm BreachRisk briefing — score, trend, top verified paths, progress, one ask — builds it. Here's a pattern you can reuse every quarter.
Likelihood × impact — the risk language boards already understand
Boards don't need a CVE tutorial. They need breach risk in the same shape as every other enterprise risk: how likely, how bad, what we're doing. Here's how to use that frame without drowning them in formula.
Identified vs verified vs safe — why the middle word matters
Scanners identify maybes. Ratings estimate from signals. Proof starts when a finding is verified the way an attacker would care about it. 'Safe' is a state you earn — not a slide.
Tenants, not tickets: running many customers in one console
You can't hire three pen testers for every book of business. Multi-tenant delivery lets service providers run continuous assessments across clients — separate data, shared ops — without building an exploit shop.
Pack continuous assessment into an MSP offer
Monitoring and tickets keep the lights on. A continuous, attacker-grade risk assessment — delivered under your brand — is a reason clients stay, expand, and come to you before they go shopping for a pen-test firm.
So you have to align to NIST 800-53 — here's where to start
A government-adjacent customer or RFP just said NIST SP 800-53. Before you drown in control IDs, decode whether this is a contractual baseline, a gap assessment ask, or 'be FedRAMP-ish' — then use this 30-day orientation.
What a BreachRisk Score is (and isn't)
One number leaders can trend — built from assessed surface and verified exposure. Here's what the BreachRisk Score measures, what it deliberately isn't, and how to talk about it without overselling.
Turn assessments into recurring revenue — without becoming a pen-test firm
Annual point-in-time testing is a project. Continuous assessment is a retainer. How service providers position renewal, quarterly reviews, and expansion — while the platform does the attacker-grade work.
So you have to get SOC 2 — here's where to start
Sales just told you enterprise buyers need SOC 2. Before you hire anyone or buy a binder of policies, clarify what was actually asked for — and use this as your first-30-days map.
Critical CVE ≠ your breach risk
A CVSS 9.8 on something attackers can't reach is a different problem than a moderate finding on a live internet path. Severity labels aren't organizational breach risk — stop letting them set the whole queue.