Designing a Threat-Informed Vulnerability Program
From static severity scores to real-world exploitability-driven remediation — a masterclass guide for security leaders navigating the modern vulnerability crisis.
Thank you. Your eBook is downloading now. If it does not start automatically, use the button below.
Download the eBook PDFA copy will also be sent to your email shortly.
Enterprise security teams are caught in a classic red-queen race — running faster than ever, spending more human capital, and exhausting infrastructure teams to patch software, yet the corporate attack surface is not becoming demonstrably safer.
Following a massive 46.3% spike in mid-year disclosures, FIRST revised its full-year projection to approximately 66,000 new CVEs. For a standard enterprise, this translates to evaluating, routing, and remediating roughly 180 new vulnerabilities every single day.
Filtering by high technical severity alone flags roughly 57% of an enterprise's entire asset footprint as an emergency — triggering intense alert fatigue, severe patch burnout, and unnecessary operational downtime.
Crucially, the percentage of vulnerabilities experiencing real-world exploitation remains flat. Attackers don't look at static spreadsheets — they look for the path of least resistance: exploitability, convenience, and reachability.
A threat-informed vulnerability program overlays three complementary data sources to filter operational noise and surface the vulnerabilities that actually threaten the business.
CVSS provides the theoretical blast radius of a vulnerability — the maximum potential damage if exploited. It is a necessary foundation but an insufficient standalone prioritization signal. The framework treats CVSS as Axis 01: Technical Impact from 0.0 to 10.0.
Severity BaselineManaged by FIRST, EPSS uses a machine learning model to estimate the mathematical probability (0–100%) that a newly disclosed CVE will be exploited within its first 30 days. EPSS analyzes honeypot activity, deep web discussions, PoC releases, and active attack framework metadata.
Predictive Threat SignalWhere EPSS is predictive, the CISA Known Exploited Vulnerabilities catalog is reactive — tracking CVEs already confirmed to be exploited in the wild. Any vulnerability on the KEV list represents a non-negotiable emergency regardless of its CVSS score. This is ground truth from the US government's threat intelligence apparatus.
Confirmed Active ExploitationThe final and most important component. A vulnerability's threat profile changes based on the value, exposure, and role of the underlying host. Three dimensions matter: perimeter exposure (internet-facing?), data tier access (production databases, PII?), and identity and control value (domain controllers, jump boxes?).
Internal Business ContextCritical note: Do not simply multiply CVSS × EPSS scores. Because EPSS scores typically cluster near the low end, simple multiplication artificially depresses the risk profile of dangerous vulnerabilities. Instead, plot them on a coordinate matrix — two separate axes that must intersect to trigger a patch action.
Every discovered vulnerability must automatically route into one of four operational tiers. These tiers dictate the strict remediation workflows for infrastructure teams — eliminating the endless backlog of undifferentiated emergencies.
High or medium CVSS scores confirmed to be actively exploited via the CISA KEV catalog, residing on a public internet-facing asset. Non-negotiable emergency — standard maintenance windows are bypassed and remediation begins immediately.
High technical severity with an EPSS score greater than 0.50, located on critical internal production networks. Not yet on the KEV list, but mathematical indicators suggest an exploit is imminent. Scheduled for the next rapid deployment cycle.
CVSS critical (9.0–10.0) but with low real-world threat indicators — EPSS below 0.10 and absent from the CISA KEV catalog. High theoretical blast radius but no active exploit path. Handled during standard monthly or quarterly maintenance windows.
Low or medium severity vulnerabilities with negligible threat indicators residing on isolated test environments, sandboxes, or non-production assets. Security operations logs these flaws, accepts the current risk, and monitors for future threat changes.
Technical depth and strategic clarity for CISOs, vulnerability management teams, and security engineers ready to move beyond the legacy CVSS checklist.
Why CVSS-only prioritization causes structural gridlock, the 66K disclosure projection, and the mathematical breakdown of daily CVE burden facing security operations teams.
Chapter 1How EPSS machine learning models achieve 85–90% threat coverage with under 20% of the remediation effort, compared to the large wasted footprint of CVSS-only patching programs.
Chapter 2How the Known Exploited Vulnerabilities catalog functions as the reactive complement to EPSS's predictive model, and why KEV membership overrides CVSS severity in every triage decision.
Chapter 3How to map vulnerability discoveries to a strict host criticality hierarchy across perimeter exposure, data tier access, and identity and control value — the internal business context layer.
Chapter 4Designing the coordinate model that plots technical severity against threat probability to separate high-impact actively-targeted vulnerabilities from high-impact unweaponized ones.
Chapter 5How the combined framework narrows 57% asset emergency footprint down to the critical 3% representing true business risk — reducing alert fatigue and building a predictable remediation pipeline.
Chapter 6Transitioning from a legacy severity checklist to a threat-informed vulnerability program represents a fundamental shift in corporate defense. When an enterprise filters its daily scan telemetry through the combined lens of CISA KEV, EPSS probability, and asset reachability, the operational noise drops immediately.
Instead of forcing IT infrastructure teams to struggle with an unmanageable backlog flagging over half the company's assets as emergencies, this model narrows focus to the critical 3% of vulnerabilities that pose a real-world threat.
This targeted approach dramatically reduces alert fatigue, eliminates friction between security and IT teams, and ensures that limited engineering hours are spent where they will have the greatest impact on protecting the business.
A modern vulnerability program is not measured by the sheer volume of patches applied or the number of compliance checkboxes cleared. It is measured by the speed and efficiency with which an organisation can neutralize active, weaponized threats.
Download the complete eBook and get the framework, methodology, and prioritization matrix your security team needs to move beyond CVSS and focus on the vulnerabilities that truly threaten the business.