Skip to content
Cyber loss exposureDecision comparison

CVSS Tells You Severity. It Won't Tell You What to Fix First.

Combine vulnerability severity with business evidence, action costs and a budget objective. Learn why a reduction-per-dollar ranking alone can select the wrong plan.

A severity score helps a team understand a vulnerability. Funding a remediation plan also requires business scope, evidence of exposure, action costs, obligations and a decision objective. The question is which feasible work the company should authorize with the budget and capacity it has.

FIRST's CVSS v4.0 specification separates Base, Threat, Environmental and Supplemental metrics. It supports context-sensitive severity assessment. It is not a monetary loss model or an investment-allocation rule. Keep its technical information and add the business decision inputs.

Check the asset and the path before assigning dollars

A critical finding on an apparently isolated test service and a lower-severity finding on a production service can deserve different priorities. Do not assume the test service has no value or no path to production: verify identity trust, data access, dependencies and actual reachability first.

For each material finding, record the source, observation date, affected resource and business service. Describe the event that could cause loss and the consequences in that scope. A finding count, an exploit attempt and a business loss event are different objects.

The finding-to-decision guide explains the handoff. Missing business context should become an evidence task, not an invented financial figure.

Compare one financial object consistently

Agree whether the immediate objective is lower mean annual loss, a selected tail-loss metric or another documented outcome. Use the same currency, scope and cost horizon across the alternatives. Required work may consume budget without receiving modeled benefit.

The FAIR worked example uses one fictional company and 50,000 simulated annual outcomes. It reports gross annual loss before insurance; the figures are not EBITDA adjustments, customer savings or an externally calibrated forecast.

Its $100,000 first-year budget can fund either a $70,000 access-hardening plan or a $90,000 recovery plan. Both include the required $15,000 tabletop. Access has the lower modeled mean annual loss; recovery has the lower P95. A claim that one is simply “the best investment” would omit the decision objective.

Treat a ratio as an input to the choice

Modeled reduction divided by action cost can help inspect an alternative. First define which reduction is being divided: mean loss and P95 are different metrics, and a P95 difference is not expected savings or an economic return.

A ratio does not incorporate every budget constraint. Two actions may share a prerequisite, compete for the same implementation team, or address the same loss event. Their independent modeled benefits may overlap. An inexpensive action can rank well by ratio while a different affordable combination better meets the chosen objective.

Compare feasible combinations directly, including required work, recurring costs, dependencies and the evidence for control effectiveness. Urgent incidents and applicable obligations need their own handling; a weak modeled ratio is not authorization to ignore them.

Test the assumptions that could reverse the order

Keep a source and owner for frequency, severity, control effect and implementation cost. Distinguish observed company evidence from a public prior or analyst estimate.

In the shared example, weaker assumed recovery effectiveness reverses the P95 choice. That result tells the approver which evidence to request before funding. It does not establish that the real company would experience the modeled reduction.

The input checklist helps expose missing evidence. Hold an unpriced option visibly when it cannot yet be compared, with an owner and next review date.

Evaluate the supported workflow

Valty's funding workflow can start with findings from the tools a company already uses. Confirm the supported collection/import, permissions and coverage using the integration guide; this workflow does not require replacing the detection stack.

Then inspect how the chosen action retains its owner, approval and required verification. A closed ticket or absent scanner record is not enough to establish effective remediation. Request fresh evidence for the affected asset after the action, and keep stale, failed and inconclusive results visible.

The board report template carries the choice into an approval discussion. Report actual spend, observed control state and recomputed modeled loss separately. The objective is a defensible decision, not a claim that every closed finding recovered a dollar of earnings.

Inspect the fictional sample decision memo, or request a platform demo to explore the supported workflow with illustrative data. Company scope, evidence handling, access, onboarding and commercial terms are agreed separately before evaluation.

Product context Real application capture · illustrative data
CVSS Tells You Severity. It Won't Tell You What to Fix First. product viewOpen full-size product view ↗
Back to blogBrowse category

Related

More in Cyber loss exposure.