Skip to content
Security at DepthLeadership grounded in engineering
InsightsTopicsExploreLessonsAbout

Search the publication

Find an insight

InsightsTopicsExploreLessonsAboutRSS feed
← All tags

#Risk

  • Govern & InvestExecutive BriefApr 2, 2025 6 min

    What Executives Should Demand from Vulnerability Prioritization

    A credible program must explain why an exposure matters, who owns the response, what uncertainty remains, and whether the decision reduced material risk.

    Vulnerability ManagementRiskLeadership
    ↗
  • Defend & DetectPerspectiveMar 20, 2025 5 min

    Operationalizing EPSS Without Turning Probability into Policy by Accident

    EPSS becomes useful when thresholds reflect risk appetite, remediation capacity, and business context—and when the program measures what those thresholds actually capture.

    Vulnerability ManagementEPSSCVSS
    ↗
  • Govern & InvestPerspectiveFeb 15, 2025 5 min

    Vulnerability Management Is a Decision System, Not a Patch Queue

    CVSS can describe severity, EPSS can estimate exploitation likelihood, and SSVC can structure response. Leadership still has to connect those signals to business exposure and accountable action.

    Vulnerability ManagementEPSSSSVC
    ↗
Security at Depth

Independent insights connecting security decisions to the systems and teams that carry them out.

Explore

InsightsTopicsExploreLessonsAboutFeaturedAll tags

Connect

LinkedInGitHubRSS feed

© 2026 Security at Depth. Views are the author's own.

Privacy-first by default. No advertising or behavioral tracking.