Risk quantification
7 articles.
When CVSS (and EPSS / KEV) still belong in the room
Breach risk isn't a CVSS average — but CVE context still earns a seat once a path is real. Here's how to use CVSS, EPSS, and KEV without letting them run the whole program.
How to brief the board on breach risk without fear-mongering
Scare decks burn credibility. A calm BreachRisk briefing — score, trend, top verified paths, progress, one ask — builds it. Here's a pattern you can reuse every quarter.
Likelihood × impact — the risk language boards already understand
Boards don't need a CVE tutorial. They need breach risk in the same shape as every other enterprise risk: how likely, how bad, what we're doing. Here's how to use that frame without drowning them in formula.
Identified vs verified vs safe — why the middle word matters
Scanners identify maybes. Ratings estimate from signals. Proof starts when a finding is verified the way an attacker would care about it. 'Safe' is a state you earn — not a slide.
What a BreachRisk Score is (and isn't)
One number leaders can trend — built from assessed surface and verified exposure. Here's what the BreachRisk Score measures, what it deliberately isn't, and how to talk about it without overselling.
Ratings estimate risk. Attackers exploit paths.
Outside-in letter grades are easy to consume — and easy to pad with findings that aren't material to a breach or a claim. Underwriting needs verified break-in paths, not another estimate built from soft perimeter signals.
Critical CVE ≠ your breach risk
A CVSS 9.8 on something attackers can't reach is a different problem than a moderate finding on a live internet path. Severity labels aren't organizational breach risk — stop letting them set the whole queue.