>> All posts

When CVSS (and EPSS / KEV) still belong in the room

If you've followed this series, you might hear a false conclusion: BreachBits thinks CVSS is useless.

We don't. We think CVSS is not organizational breach risk — and that confusing the two is how queues and board decks go wrong. Used in the right lane, CVE context is still one of the best tools in the kit.

Three signals, three jobs

CVSS — shared severity for a vulnerability in the abstract. Great for comparing flaws and communicating "this class of bug is nasty."

EPSS — estimate of how likely a vulnerability is to be exploited in the wild in a near window. Useful probability context — still not "will we get hit via this asset."

CISA KEV — catalog of vulnerabilities known to be exploited. A strong "pay attention" flag when it intersects something you actually run and expose.

None of these replace: is this on our surface, is the path verified, and what does impact look like for our business?

Where they belong

On a verified finding — once you know a path is real, CVSS / EPSS / KEV help you explain urgency and pick fix order among real items. That's especially natural in application and API testing, where findings often carry that CVE context.

In patch and vuln-ops workflows — enterprise patching still needs a common severity language. Keep it.

In auditor / customer packets — when someone asks how you prioritize, "verified exposure first, then CVE context" is a grown-up answer.

Where they don't belong

As the master sort for breach risk — averaging CVSS or sorting only by Critical recreates the "Critical ≠ our risk" failure mode.

As a substitute for verification — a high EPSS on something you don't expose is a research footnote, not a fire drill.

As the board's only slide — leadership needs likelihood × impact on your paths, not a CVE tutorial.

A simple operating rule

  1. Discover and assess what you expose
  2. Verify what an attacker can use
  3. Rank with breach risk (likelihood × impact for the organization)
  4. Use CVSS / EPSS / KEV as context inside that ranked set
  5. Trend the BreachRisk Score so the program has a north star that isn't "count the Criticals"

Bottom line

We are not anti-CVSS. We are anti-category error.

CVE signals help you understand a flaw. Breach risk tells you whether that flaw is your problem worth the next dollar and the next board minute. Keep both — in the right order — and the room gets smarter instead of louder.

See your cyber risk, proven.