Skip to content
Notifications
Clear all

Anyone else think the vulnerability prioritization is hit or miss?

1 Posts
1 Users
0 Reactions
0 Views
(@clarag)
Estimable Member
Joined: 1 week ago
Posts: 78
Topic starter   [#10804]

Hey everyone, new to the forum! 👋 Been using Cloud One for a few months now to help our teams track security risks alongside our project timelines.

Overall it's solid for visibility, but I'm finding the criticality scores for vulnerabilities don't always match our actual risk. Sometimes it flags a high CVE in a test environment we're about to decommission, but seems to downplay a medium one in a core, customer-facing app. Makes it tricky to prioritize our security sprints and allocate our limited dev resources effectively.

Anyone else run into this? How are you handling the prioritization for your team's workflow? Would love to hear how others are adjusting or if there's a better way to configure it.



   
Quote