>> All posts>> Topic

Risk quantification

7 articles.

July 10, 2026Risk quantificationBest practices

When CVSS (and EPSS / KEV) still belong in the room

Breach risk isn't a CVSS average — but CVE context still earns a seat once a path is real. Here's how to use CVSS, EPSS, and KEV without letting them run the whole program.

May 5, 2026Risk quantificationBest practices

How to brief the board on breach risk without fear-mongering

Scare decks burn credibility. A calm BreachRisk briefing — score, trend, top verified paths, progress, one ask — builds it. Here's a pattern you can reuse every quarter.

February 19, 2026Risk quantificationBest practices

Likelihood × impact — the risk language boards already understand

Boards don't need a CVE tutorial. They need breach risk in the same shape as every other enterprise risk: how likely, how bad, what we're doing. Here's how to use that frame without drowning them in formula.

December 13, 2025Risk quantificationBest practices

Identified vs verified vs safe — why the middle word matters

Scanners identify maybes. Ratings estimate from signals. Proof starts when a finding is verified the way an attacker would care about it. 'Safe' is a state you earn — not a slide.

September 30, 2025Risk quantificationBest practices

What a BreachRisk Score is (and isn't)

One number leaders can trend — built from assessed surface and verified exposure. Here's what the BreachRisk Score measures, what it deliberately isn't, and how to talk about it without overselling.

September 13, 2025Cyber insuranceRisk quantification

Ratings estimate risk. Attackers exploit paths.

Outside-in letter grades are easy to consume — and easy to pad with findings that aren't material to a breach or a claim. Underwriting needs verified break-in paths, not another estimate built from soft perimeter signals.

August 5, 2025Risk quantificationBest practices

Critical CVE ≠ your breach risk

A CVSS 9.8 on something attackers can't reach is a different problem than a moderate finding on a live internet path. Severity labels aren't organizational breach risk — stop letting them set the whole queue.