Week 1
Prioritize Critical Vulnerabilities for a Retail Client
Client Background
A retail chain needs its quarterly vulnerability scan results triaged before an audit.
Business Environment
Storeline Retail (120 stores, ~3,400 employees) runs a hybrid estate of on-prem POS, an e-commerce platform, and cloud workloads, scanned quarterly with network and agent-based scanners. The latest quarterly scan surfaces ~1,800 vulnerabilities; leadership needs the critical subset triaged and remediated within 30 days ahead of an enterprise-customer security audit, and the CISO wants the triage methodology modernized beyond raw CVSS.
Security Incident
No breach; the engagement is a proactive quarterly vulnerability triage. The driver is an upcoming enterprise-customer security audit and the CISO's directive to adopt Risk-Based Vulnerability Management (RBVM) using threat-intelligence context rather than raw CVSS severity.
Scope
Triage of the quarterly vulnerability scan results across POS, e-commerce, and infrastructure assets, prioritizing remediation of verified-exploitable, internet-exposed, and business-critical findings. Excludes deploying new scanning tools and patch execution.
Objectives
- Triage quarterly scan results applying Risk-Based Vulnerability Management (RBVM): combine CVSS, EPSS exploitability, and CISA KEV active-exploitation status with asset criticality.
- Differentiate verified-exploitable and internet-exposed findings for near-term remediation.
- Assign remediation owners and SLAs aligned to RBVM priority, not raw CVSS severity.
- Draft an executive summary translating RBVM priorities into board-ready risk language.