Research
Our team (formerly of Kenna Security as well as co-creators of the EPSS) invented risk-based vulnerability management. But we believe there's areas of exposure management that haven't even been tapped, and they need to be explored urgently given the monumental challenges facing security teams. We're excited to publish our research (including ongoing benchmarks of our global and local models) and present them here.
Jay Jacobs, Chief Data Scientist
Michael Roytman, CTO
Dr. Benjamin Edwards, Head of Modeling
Jerry Gamblin, Head of Research
Known Exploited vs Recently Exploited
Past exploitation is not a guarantee of future exploitation. However, recent exploitation is in fact a powerful predictor of future exploitation!
Known (Re-)Exploited Vulnerabilities
Conventional wisdom in cybersecurity tells us that if a vulnerability is known to be exploited that everyone should patch it immediately, but the reality is a lot more nuanced. Known exploited in the past does not guarantee future exploited.