Skip to content
Blog Article

Vulnerability Management 2.0: Operational Metrics That Matter

Moving beyond CVE counts to exploitability-weighted backlog burn and exposure half-life.

July 13, 2025
7 min read
Risk Engineering
Vulnerability Management 2.0: Operational Metrics That Matter

Limitations of Raw Counts

Total open vulns provides minimal decision signal—focus on exploitable paths affecting crown assets. This is a key metric in our [Security Maturity Model](/resources/blog/maturity-model-blog).

Exposure Half-Life

Measure time for 50% of newly discovered exploitable vulnerabilities to be remediated; track trend.

Exploitability Weighting

Combine EPSS, KEV catalog presence, asset sensitivity, & network exposure to prioritize.

Workflow Automation

Auto-create remediation epics with dependency graph context; integrate change windows & rollback plans.

Metrics

Exposure half-life, KEV item SLA adherence %, mean validation failure rate, remediation throughput (items/week).

Sources & Further Reading

CISA KEV Catalog.

EPSS (Exploit Prediction Scoring System).

NIST NVD (reference metadata).

Key Takeaways

Exposure half-life trending down = real risk reduction narrative.