TL;DR: Horizon3.ai’s whitepaper argues that SOC and ITSM teams clash because they are measured against different outcomes, and recommends using attacker-validated evidence to prioritise exploitable attack paths, integrate findings into service workflows, and confirm that remediation removes risk. That framing shifts security programmes from score-chasing to evidence-driven resilience.
NHIMG editorial — based on content published by Horizons.ai: A Leadership Guide to Evidence-Driven Cyber Risk Management
Questions worth separating out
Q: How should security teams prioritise vulnerabilities when SOC and ITSM disagree?
A: Prioritise by whether there is evidence of a reachable attack path and by the service impact of remediation.
Q: What breaks when organisations rely on CVSS alone for remediation decisions?
A: CVSS alone creates a backlog of scores, not a backlog of risk.
Q: How do you know if recovery is actually reducing cyber risk?
A: Recovery is working only if restored systems return without the original weakness, with validation proving the flaw is closed and the exposure path is gone.
Practitioner guidance
- Define a shared exploitability threshold Use one criterion for moving an issue from backlog to remediation: evidence that an attacker can reach the affected asset or identity path.
- Embed security findings into ITSM records Link each finding to the affected service, business owner, likely attack path, and required verification step.
- Require verification before closure Do not close a remediation item until post-fix checks confirm the attack path is gone and the service remains stable.
What's in the full article
Horizons.ai's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The whitepaper's evidence-driven prioritisation model for separating exploitable attack paths from noise.
- The practical workflow for moving security findings into ITSM without losing service ownership or remediation context.
- The Schrödinger's Monkey framing used to assess when an issue should be treated as both cyber and service risk.
- The guide's outcome-driven metrics for judging whether fixes actually remove exposure rather than only closing tickets.
👉 Read Horizons.ai's whitepaper on unifying SOC and ITSM around evidence-driven risk →
SOC and ITSM alignment: what attacker-validated evidence changes?
Explore further
Evidence-driven risk management is the real governance issue here. When security and operations teams use different scoring systems, they optimise for different outcomes and create avoidable friction. Shared prioritisation only works when the organisation can prove that an issue is exploitable and materially relevant to service delivery. The practitioner conclusion is straightforward: align on evidence, not on inherited team metrics.
A question worth separating out:
Q: Who should own risk decisions when security fixes affect service stability?
A: Ownership should be shared, but decision criteria must be explicit. SOC should establish whether the issue is exploitable, ITSM should assess service impact, and governance should require both views before priority is set. That prevents either team from overruling the other with incomplete context.
👉 Read our full editorial: Evidence-driven cyber risk management for SOC and ITSM alignment