Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

CVE counts and exposure risk: what security teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: CVE counts and CVSS scores can make vulnerability programs look effective while leaving real attack paths untouched, because severity scoring does not measure reachability, exploitability, or access to critical assets, according to XM Cyber. Continuous Exposure Management shifts the metric from how many findings are closed to how many viable paths to crown-jewel systems remain.

NHIMG editorial — based on content published by XM Cyber: Why CVE Counts Fail as a Risk Metric

By the numbers:

Questions worth separating out

Q: How should security teams prioritise vulnerabilities when business impact matters more than severity scores?

A: Prioritise by combining exploitability, asset criticality, compensating controls, and process ownership.

Q: Why do CVE counts and CVSS scores fail as board risk metrics?

A: They fail because they describe technical severity, not business loss.

Q: What do vulnerability programmes get wrong about severity-based SLAs?

A: Severity-based SLAs assume that higher scores always deserve faster remediation, but that ignores asset context and attacker behaviour.

Practitioner guidance

  • Replace CVE-only prioritisation with attack-path scoring Classify findings by whether they are actually reachable, whether the affected system is internet-facing, and whether a known route exists to critical assets.
  • Tie vulnerability triage to identity and privilege data Join scanner output with service account scope, cached credentials, third-party access, and network exposure so that a moderate flaw on a privileged path outranks a critical flaw in an isolated segment.
  • Measure closed attack paths, not closed tickets Report how many validated routes to crown-jewel assets were removed each quarter and how many remain.

What's in the full article

XM Cyber's full blog covers the operational detail this post intentionally leaves for the source:

  • How the vendor maps validated attack paths into remediation prioritisation workflows for real environments
  • Examples of how environmental context changes the ranking of high-CVSS and lower-CVSS findings
  • Practical guidance for tying exposure metrics to leadership reporting and remediation SLAs
  • Discussion of the control gaps that vulnerability scanners do not capture, including misconfigurations and identity paths

👉 Read XM Cyber's analysis of why CVE counts miss real exposure →

CVE counts and exposure risk: what security teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

CVSS-driven remediation creates severity theatre. When teams optimise for scores, they can produce cleaner dashboards without reducing exposure. CVSS was never designed to answer whether a flaw is reachable, chained, or connected to privileged access. The result is a governance model that rewards ticket volume and SLA compliance while leaving the actual attack surface intact. For practitioners, the decisive question is whether remediation changes attacker options.

A question worth separating out:

Q: How do organisations know remediation is actually reducing exposure?

A: They should measure time to closure, percentage of issues resolved within SLA, escalation rates, and the share of findings that require security-led fallback. If findings are assigned but remain open, the programme is reporting activity rather than reducing risk. Closure evidence matters as much as detection volume.

👉 Read our full editorial: CVE counts miss exposure: why attack-path risk matters more



   
ReplyQuote
Share: