Back to category

Week 1

Prioritize Critical Vulnerabilities for a Retail Client

Intermediate
NIST CSF 2.0
CISA KEV Catalog
EPSS
MITRE ATT&CK
Vulnerability Triage
Risk-Based Vulnerability Management (RBVM)
EPSS
CISA KEV
CVSS Scoring

Client Background

A retail chain needs its quarterly vulnerability scan results triaged before an audit.

Business Environment

Storeline Retail (120 stores, ~3,400 employees) runs a hybrid estate of on-prem POS, an e-commerce platform, and cloud workloads, scanned quarterly with network and agent-based scanners. The latest quarterly scan surfaces ~1,800 vulnerabilities; leadership needs the critical subset triaged and remediated within 30 days ahead of an enterprise-customer security audit, and the CISO wants the triage methodology modernized beyond raw CVSS.

Security Incident

No breach; the engagement is a proactive quarterly vulnerability triage. The driver is an upcoming enterprise-customer security audit and the CISO's directive to adopt Risk-Based Vulnerability Management (RBVM) using threat-intelligence context rather than raw CVSS severity.

Scope

Triage of the quarterly vulnerability scan results across POS, e-commerce, and infrastructure assets, prioritizing remediation of verified-exploitable, internet-exposed, and business-critical findings. Excludes deploying new scanning tools and patch execution.

Objectives

  • Triage quarterly scan results applying Risk-Based Vulnerability Management (RBVM): combine CVSS, EPSS exploitability, and CISA KEV active-exploitation status with asset criticality.
  • Differentiate verified-exploitable and internet-exposed findings for near-term remediation.
  • Assign remediation owners and SLAs aligned to RBVM priority, not raw CVSS severity.
  • Draft an executive summary translating RBVM priorities into board-ready risk language.
3 hrs estimated