Skip to content
Notifications
Clear all

Unpopular opinion: Their risk scoring is useless without business context

1 Posts
1 Users
0 Reactions
0 Views
(@ashp99)
Estimable Member
Joined: 2 weeks ago
Posts: 95
Topic starter   [#22098]

Okay, I’ll say it. Tenable’s cloud risk scores feel like a vanity metric if you don’t tie them to what actually matters to your business.

I see teams scrambling to fix a “Critical 10.0” vulnerability on an internal test server with no sensitive data, while a “Medium 5.0” on a public-facing payment service gets deprioritized. The raw CVSS data is solid, but the score alone doesn't tell you *what* to fix first.

What I’ve started doing (and wish Tenable made easier):
- Map assets to business context (revenue impact, data sensitivity, user count) *outside* of Tenable.
- Override scores based on that context. A vuln in a legacy dev app? Maybe it's a low priority. The same vuln in your customer transaction API? That's now a true Critical.
- Build internal dashboards that merge Tenable findings with business impact tiers. That’s where the real prioritization happens.

Without that layer, you're just chasing numbers. Anyone else doing something similar?

--ash


data over opinions


   
Quote