TL;DR: Severity scores alone do not reflect real-world exploitation risk, according to Anomali’s whitepaper on threat-informed vulnerability prioritization. The paper argues that exploit intelligence, asset criticality, and campaign relevance should drive remediation decisions, not raw scores alone, because exposure reduction and executive reporting improve when patching is tied to business risk.
At a glance
What this is: This whitepaper argues that vulnerability prioritization should combine exploit intelligence, asset criticality, and campaign relevance rather than relying on severity scores alone.
Why it matters: That matters to IAM and security practitioners because remediation capacity is finite, and risk-based prioritization changes which assets, identities, and exposed services get attention first.
👉 Read Anomali's whitepaper on threat-informed vulnerability prioritization
Context
Threat-informed vulnerability management is the idea that patch queues should reflect how an issue is exploited in the wild, how critical the affected asset is, and whether it aligns with active campaigns. In practice, severity alone often overstates low-value issues and understates vulnerabilities that sit on privileged systems, exposed services, or identity-adjacent infrastructure.
For identity teams, the relevance is indirect but real. Vulnerability prioritization influences the systems that host authentication flows, secrets, tokens, service accounts, and administrative tooling, so better prioritization reduces the chance that a software flaw becomes an access-control failure or a privilege escalation path.
Key questions
Q: How should security teams prioritise vulnerabilities when remediation capacity is limited?
A: Prioritise by exposure, business criticality, and the identities attached to the affected asset. A remotely reachable flaw on a system with privileged access or sensitive data deserves earlier attention than a technically severe issue on an isolated low-value system. Tie severity scoring to ownership, exploitability, and blast radius so remediation decisions reflect real risk, not just scanner output.
Q: When should teams override CVSS-based remediation queues?
A: Override severity-based queues when threat intelligence shows active exploitation, when the vulnerable asset supports authentication or privilege pathways, or when the system has high business impact if compromised. Static scores describe potential harm, but they do not capture attacker momentum or asset adjacency to trust boundaries.
Q: What do security teams get wrong about vulnerability prioritisation?
A: Security teams often treat vulnerability scores as if they represent operational risk on their own. In practice, a score only matters when the asset can reach something important. Graph analysis corrects this by showing which weaknesses are connected to critical systems, where lateral movement is possible, and which routes attackers are most likely to use.
Q: How do organisations know threat-informed patching is working?
A: Look for a shorter time between exploit intelligence and remediation on the systems that matter most. If high-value assets, identity services, and exposed management planes are being fixed first, and executive reporting reflects reduced attacker-relevant exposure, the programme is working better than one measured only by ticket throughput.
Technical breakdown
How threat intelligence changes vulnerability scoring
Threat-informed prioritization adds external context to internal vulnerability data. A severity score tells you how bad a flaw could be in isolation, but exploit intelligence tells you whether attackers are using it, campaign relevance tells you whether your environment is likely to be targeted, and asset criticality tells you what the loss would mean operationally. This approach is less about replacing CVSS than about preventing it from being the only input. For teams that manage identity platforms, this matters because exposed management planes, directory services, and secrets stores often carry disproportionate blast radius.
Practical implication: enrich vulnerability queues with exploit and campaign data before assigning remediation SLA targets.
Why asset criticality should override generic severity
Asset criticality changes the meaning of the same vulnerability. A medium-severity flaw on an internet-facing jump host or in a system that brokers authentication can be more dangerous than a high-severity issue on an isolated workstation. Threat-informed models force teams to ask where the vulnerable asset sits in the trust chain, what it can reach, and whether compromise would expose credentials, tokens, or administrative pathways. That makes prioritization more operational and less abstract, especially in environments where identity and infrastructure controls are tightly coupled.
Practical implication: classify vulnerable systems by business role and identity adjacency, not just by technical severity.
How campaign relevance improves remediation decisions
Campaign relevance connects a vulnerability to the threat actor behaviour currently driving exploitation. If a vulnerability is being used in active campaigns, the remediation conversation changes from routine backlog management to exposure reduction. This is especially important for shared services and control-plane components, where even a short delay can expand an attacker’s ability to move laterally or harvest secrets. Threat-informed prioritization is therefore a governance model as much as a technical one, because it aligns patching with risk ownership and executive reporting.
Practical implication: use campaign-level threat intelligence to set escalation thresholds for vulnerabilities on high-value systems.
Threat narrative
Attacker objective: The attacker objective is to exploit the highest-value reachable vulnerability before defenders can triage it by risk rather than severity.
- Entry occurs when attackers focus on a vulnerability that has active exploit relevance rather than waiting for routine patch cycles to catch up.
- Escalation follows when the vulnerable asset is tied to critical services, allowing compromise to reach identity controls, secrets, or administrative paths.
- Impact is measured by exposure reduction failure, because delayed remediation leaves business-critical systems available to the attacker longer than necessary.
NHI Mgmt Group analysis
Threat-informed prioritization is a governance model, not just a triage model. Severity scoring is useful, but it is too static to reflect attacker behaviour, asset criticality, and business exposure at the same time. Organisations that treat patching as a score-ranking exercise miss the operational question of which flaws open the shortest path to compromise. The practitioner conclusion is simple: prioritisation must be tied to risk ownership, not just scanner output.
Identity infrastructure deserves special treatment inside vulnerability queues. Authentication services, directory layers, secrets stores, and privileged administration planes do not just support the environment, they shape who can reach what. When those systems are vulnerable, the issue is often not the flaw itself but the access paths it can unlock. Teams should treat identity-adjacent assets as high-blast-radius systems even when the raw severity score looks ordinary.
Campaign relevance creates the strongest signal for remediation urgency. A vulnerability becomes materially more dangerous when it is associated with active exploitation, known actor tooling, or broad attack automation. That is why threat intelligence should be folded into the same decision loop as asset criticality and patch feasibility. The practitioner conclusion is to move from backlog reduction to exposure reduction, especially on systems that hold credentials or mediate trust.
Exposure reduction is the more useful success metric than patch volume. Patch counts can rise while real risk stays unchanged if the wrong systems are being fixed first. A stronger model measures how quickly organisations remove attacker-relevant paths into critical assets, including identity services and privileged workflows. The practitioner conclusion is to report remediation in terms executives can act on, not just in terms of tickets closed.
What this signals
Threat-informed vulnerability management is becoming the more defensible operating model for teams that cannot patch everything at once. The practical shift is from seeing vulnerabilities as a flat queue to seeing them as paths into identity, data, and control-plane risk. For practitioners, the next maturity step is to make prioritisation decisions explainable to both security and operations leaders.
Exposure path management: this is the emerging discipline of ranking flaws by the paths they open into critical systems, not by scanner score alone. That framing matters because it aligns remediation with the assets attackers actually need to reach. Teams that can show fewer attacker-relevant paths into privileged and identity infrastructure will have a stronger risk story than teams that only show lower backlog counts.
For practitioners
- Rank vulnerabilities by exploitability and business context Combine exploit intelligence, asset criticality, and campaign relevance before setting remediation order. Use that combined view to move identity systems, internet-facing services, and privileged management paths ahead of low-impact issues.
- Tag identity-adjacent assets as high-blast-radius systems Label directory services, secrets stores, authentication gateways, and admin planes as assets whose compromise changes access paths across the environment. Give them shorter escalation thresholds than ordinary endpoint or application workloads.
- Separate risk reporting from patch volume reporting Report how many attacker-relevant exposure paths were removed, not just how many CVEs were closed. That gives leadership a clearer view of whether remediation is actually reducing access to critical systems.
- Use threat intelligence to override static SLA defaults When a vulnerability is tied to active exploitation or a current campaign, move it into an expedited path even if its numeric score would normally place it lower. This keeps finite patching capacity aligned with the most likely attack paths.
Key takeaways
- Severity scores are useful, but they are not enough to decide what gets fixed first.
- Threat intelligence, asset criticality, and campaign relevance together create a better remediation model than static scoring alone.
- Identity-adjacent systems should be treated as high-blast-radius assets because compromise there changes the access model for the whole environment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 , Initial Access; TA0004 , Privilege Escalation; TA0040 , Impact | The article is about exploitation risk and attack prioritisation across realistic attacker paths. |
| NIST CSF 2.0 | ID.RA-1 | Threat-informed prioritisation is a risk-assessment problem grounded in current threat information. |
| NIST SP 800-53 Rev 5 | RA-3 | RA-3 Risk Assessment supports prioritising weaknesses by impact and likelihood, not score alone. |
| CIS Controls v8 | CIS-7 , Continuous Vulnerability Management | The article focuses directly on prioritising and managing vulnerabilities continuously. |
Map high-priority vulnerabilities to likely ATT&CK stages and remediate the paths attackers can use fastest.
Key terms
- Threat and vulnerability management: Threat and vulnerability management is the continuous process of finding weaknesses, understanding which threats can exploit them, and deciding what to fix first. It is not just scanning or patching. The discipline joins exposure discovery, prioritisation, remediation, and monitoring into one risk loop.
- Campaign relevance: The degree to which a vulnerability matches current attacker behaviour, active exploitation, or a known threat actor workflow. When campaign relevance is high, the finding deserves faster remediation because it is more likely to be used in real attacks.
- Asset criticality: A measure of how important a system is to business operations, control functions, or trust boundaries. In vulnerability management, criticality matters because the same flaw can have very different consequences depending on whether it affects a low-value host or a privileged control plane.
- Exposure Reduction: Exposure reduction is the measurable decline in unprotected or overly accessible sensitive data over time. It is the most practical indicator that discovery, access control, and remediation are working together, because it tracks whether the programme is shrinking risk rather than just identifying it.
What's in the full article
Anomali's full whitepaper covers the operational detail this post intentionally leaves for the source:
- How the threat-informed prioritisation model is applied inside the Agentic SOC Platform across security and IT workflows
- The practical way exploit intelligence is combined with asset criticality and campaign relevance when remediation queues are built
- Operational examples of how to align patching decisions with executive risk reporting and exposure reduction goals
- The whitepaper's framing for organisations trying to shift from generic severity scoring to risk-driven remediation
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps identity and security practitioners connect access control decisions to broader operational risk.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org