VYPR
advisoryPublished Aug 31, 2026· 1 source

Cohesity CISO Outlines Vulnerability Prioritization Strategy Amidst Conflicting Metrics

Dr. Joye Purser of Cohesity details a pragmatic approach to vulnerability management, balancing KEV, EPSS, and CVSS scores with real-world risk factors.

In the complex landscape of cybersecurity, organizations often grapple with a deluge of vulnerability data, each metric offering a different perspective on risk. Dr. Joye Purser, Global Field CISO at Cohesity, recently shared her insights on how to navigate these conflicting signals, emphasizing a strategy that prioritizes actively exploited vulnerabilities above all else.

Purser's approach moves beyond simply relying on a single scoring system like CVSS (Common Vulnerability Scoring System). Instead, it advocates for a layered prioritization framework. The highest priority is assigned to vulnerabilities already present in CISA's Known Exploited Vulnerabilities (KEV) catalog, signifying active exploitation in the wild. This aligns with the principle that the most immediate threats should be addressed first, regardless of their theoretical severity score.

Following KEV, the next tier of consideration involves exploit likelihood, often informed by metrics like EPSS (Exploit Prediction Scoring System). This helps identify vulnerabilities that, while perhaps not yet actively exploited according to CISA, have a high probability of being targeted by attackers soon. Technical severity, as indicated by CVSS scores, serves as a crucial, but not sole, determinant in the prioritization process. This multi-faceted approach ensures that resources are directed towards the most pressing risks.

Beyond these core metrics, Purser stresses the importance of contextualizing vulnerability data with an organization's specific environment. Factors such as asset exposure (e.g., internet-facing vs. internal systems), business criticality of the affected asset, and the presence of existing compensating controls are vital for accurate risk assessment. A vulnerability that might seem minor on paper could pose a significant threat if it affects a critical, internet-exposed system with no mitigating security measures in place.

To underscore the urgency of addressing actively exploited vulnerabilities, Cohesity targets a remediation window of 24 to 72 hours for exploited internet-facing systems. This aggressive timeline necessitates efficient security operations, robust patching processes, and potentially the reallocation of resources from less critical tasks. Purser acknowledges that meeting such a tight schedule involves trade-offs and requires a mature security posture.

The discussion also touches upon the challenges and potential hidden failures within such a rapid remediation strategy. Maintaining visibility across the entire attack surface, ensuring patch deployment success, and avoiding the introduction of new issues through hasty patching are all critical considerations. The effectiveness of this prioritization model hinges on continuous monitoring, accurate asset inventory, and a well-defined incident response plan.

Ultimately, Dr. Purser's framework offers a pragmatic and actionable method for cybersecurity teams to cut through the noise of vulnerability data. By integrating active exploitation, exploit likelihood, technical severity, and environmental context, organizations can build a more resilient defense against the ever-evolving threat landscape.

Synthesized by Vypr AI