Vulnerability BI — sidebar hides with the toggle

Priority Action Matrix

Prioritise: one Priority Score sorts every CVE into an action bucket with its own SLA — so teams triage by workflow, not by scrolling a list.

0 CVEs in scope

Patch now

0

Investigate urgently

0

Monitor closely

0

Low priority

0
How this works — definitions, thresholds, and what to doShow

Priority Score = 35% Severity (CVSS) + 25% Exploitability (EPSS/KEV) + 20% CIA impact + 20% Operational reachability (network vector, no auth, no UI).

  • Patch now (score ≥ 0.75) — SLA 72h. Owner: patch team. Break-glass change control.
  • Investigate urgently (0.55–0.74) — SLA 7 days. Owner: security + product owner. Confirm exposure, then patch or mitigate.
  • Monitor closely (0.35–0.54) — SLA 30 days. Owner: platform team. Include in next patch window.
  • Low priority (< 0.35) — SLA quarterly. Review during hardening sprints only.
Help