What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
Dr. Joye Purser says the best way to rank vulnerabilities is to prioritize active exploitation first, then exploit likelihood, then technical severity, while factoring in exposure, business criticality, and compensating controls. The interview also covers rapid remediation for internet-facing systems, safer use of deception technology, and the most cost-effective controls for a mid-sized manufacturer. #KEV #EPSS #CVSS #Cohesity #DrJoyePurser

Keypoints

  • KEV should outrank EPSS and CVSS when a vulnerability is actively exploited.
  • Internet-exposed critical flaws should be remediated within 24 to 72 hours.
  • Emergency patching may require schedule breaks, extra engineering effort, and temporary service tradeoffs.
  • Deception technology can become a liability if it is overtrusted, connected, or poorly maintained.
  • Phishing-resistant MFA, identity hygiene, segmentation, and backups deliver strong early defense for limited budgets.

Read More: https://www.helpnetsecurity.com/2026/08/31/joye-purser-cohesity-kev-epss-cvss-conflicts/