A CVE has technical characteristics, but it does not know where the affected asset sits, what it supports or whether an attacker can reach it. Priority emerges when public evidence is joined to local context.
Reachability changes likelihood
Internet exposure, identity paths and network segmentation affect whether exploitation is plausible. An isolated laboratory host and an exposed gateway should not inherit the same response simply because the CVE is identical.
Business function changes consequence
Service criticality, data sensitivity and recovery options influence the material outcome. Context should be specific enough to change a decision, not a generic criticality label copied across thousands of assets.
Control evidence changes urgency
Compensating controls can reduce exposure when they are present, enforced and tested. Assumed controls should never silently lower a priority.
Practical next steps
- Join findings to a dependable owner and service.
- Record external reachability and trust relationships.
- Capture control evidence with an expiry date.
- Recalculate priority when context changes.