Skip to content
Weekly Signal

Insight

Score vs Signal

A high severity score can be quiet. A lower score with exploitation evidence can demand action. That distinction matters.

Threat IntelligenceVulnerability Prioritisation

A CVSS 9.8 with no evidence of exploitation can wait behind a CVSS 7.5 that is being actively exploited on internet-facing infrastructure. That statement sounds controversial only because vulnerability programmes have spent years treating severity as priority.

Score describes the vulnerability

CVSS Base provides a consistent description of intrinsic technical severity. It does not know whether the product exists in your organisation, whether an attacker can reach it or whether exploitation is occurring. FIRST’s own guidance is explicit that the Base score measures severity, not risk.

Signal changes the decision

Signal comes from evidence that alters urgency: KEV inclusion, credible exploitation, EPSS probability, exploit maturity, internet exposure, product prevalence and the freshness and agreement of sources. It does not replace organisational context. It gives the organisation a better starting order.

The practical consequence

If a team patches every critical vulnerability first, it can spend scarce change capacity on theoretical impact while exploitable weaknesses remain exposed. If it follows threat evidence alone, it can also overreact to issues on technology it does not own. Good prioritisation connects both.

The right question is not “which score wins?” It is “what does each piece of evidence tell us, and what would change the action?”

See how Cornish Geek Signal v1 combines these inputs or review the current Threat Radar.