White Paper

Evidence-based Early Warning vs. Industry Benchmarks and Catalogs

In the digital landscape, vulnerabilities are akin to weak points in a system that hackers can exploit. Over time, the number of these known vulnerabilities has been increasing. Organizations find it challenging to fix these vulnerabilities, as patching has operational impacts due to their sheer volume and the constant emergence of new ones. This situation can be likened to a boat with numerous leaks; it’s impractical to plug them all simultaneously. Therefore, organizations need to prioritize which vulnerabilities to address first.

Vulnerabilities include Common Vulnerability Scoring System (CVSS) scores, Exploit Prediction Scoring System (EPSS), and CISA Known Exploited Vulnerabilities (CISA KEV) ratings, which many organizations worldwide use today as a proxy for risk scores. CVSS quantifies the severity of software vulnerabilities, aiding in prioritization. EPSS predicts the likelihood of a vulnerability being exploited in the wild. CISA KEV identifies vulnerabilities known to be actively exploited. Together, these metrics allow organizations to assess vulnerabilities based on severity, exploitability, and active exploitation risk, enabling informed prioritization and mitigation strategies.

However, relying solely on CISA KEV, CVSS, and EPSS can be limiting. CISA KEV focuses only on known exploited vulnerabilities, potentially overlooking emerging threats. CVSS may not always accurately reflect the real-world impact or context of a vulnerability. EPSS, while predictive, can lack precision due to its reliance on historical data trends, which may not account for rapidly evolving threat landscapes.

In reality, threat actors don’t care about scores and ratings; they can easily exploit a medium or low score just as much as critical ones. The best way to mitigate risk is to focus on threat actor behaviors or the vulnerabilities that threat actors are actively exploiting in the wild or are likely about to weaponize.

This white paper compares the effectiveness of evidence-based, timely, and accurate early warning intelligence against CVSS Scores, EPSS and CISA KEV, aiming to demonstrate the differentiators of early warning systems but also confirming that enriching intelligence with all four options may be the best approach.

Get the White Paper