Vulnerability & Exposure Management Prioritization

Atlas Retail Group • 2,400 stores • $1.2B e-commerce • PCI + SOC 2

Risk-Adj. Open Exposure Days
11.2
↓ 2.1d vs. last month
Tier-1 Critical Backlog
47
↑ 8 KEV-listed: 12
SLA Attainment (All Tiers)
81%
↑ 3% Goal: 90%
Attack Surface +30d
+3.1%
↑ 1.4% New microservices
MTTR Critical (Days)
9.4
↓ 1.2d Target: 7d

Prioritized Remediation Queue — Top 25

Priority CVE Asset Tier BU CVSS EPSS KEV ROED Owner SLA
1CVE-2023-46604payment-gateway-031Payment9.894.2%KEV22dPlatformBreach
2CVE-2023-44487api-gateway-prod-011E-Commerce7.589.1%KEV19dEngineeringBreach
3CVE-2023-42793checkout-service-v21E-Commerce9.187.4%KEV18dEngineeringBreach
4CVE-2023-36884payment-processor-021Payment8.382.6%KEV17dPlatformBreach
5CVE-2023-38831store-pos-gateway1Store Systems7.876.3%KEV16dRetail ITBreach
6CVE-2023-4966loadbalancer-prod-011E-Commerce9.471.8%KEV15dInfrastructureDue 2d
7CVE-2023-28252identity-service-prod1Corporate7.968.5%KEV14dSecurityDue 3d
8CVE-2023-3519vpn-gateway-hq1Corporate9.865.2%KEV13dInfrastructureDue 4d
9CVE-2023-27997marketplace-api-v31E-Commerce9.261.9%Exploit12dEngineeringOK
10CVE-2023-32315inventory-sync-prod1Store Systems8.158.7%Exploit11dRetail ITOK

Showing 10 of 25 • Priority = f(EPSS, KEV, Asset Tier, ROED, Compensating Controls)

ROED Burndown by Asset Tier (90d)

KEV-Matched CVE Trend (90d)

Remediation SLA Attainment by Owning Team

Team Critical SLA % High SLA % Medium SLA % Total Open Breached Avg ROED Trend
Engineering89%84%92%142169.1d↑ 4%
Platform67%72%88%892914.2d↓ 2%
Infrastructure78%81%90%641410.3d↑ 1%
Retail IT85%87%94%112178.7d↑ 6%
Security92%94%96%3126.4d↑ 3%
Corporate IT76%79%86%481211.8d↓ 1%

Attack Surface Expansion (90d)

Marketplace microservices: +47 endpoints • Payment API v3: +22 endpoints

Scanner vs. Runtime Exposure Delta

Runtime-only detections: 34 • Scanner-only (not deployed): 89

Compensating Control Strength

WAF: 94% • Network Seg: 87% • EDR: 91%

Pen-Test Finding Closure

Critical 4/4
High 11/14
Medium 18/27

Last pen-test: Dec 2024 • Next: Mar 2025

BU Risk Ranking

Payment 847
E-Commerce 623
Store Systems 412
Corporate 289

Risk Score = ROED × Asset Count × Tier Weight

Largest Exposure Cluster — Payment Gateway Legacy Components

Apache ActiveMQ RCE (CVE-2023-46604)
Affects: payment-gateway-{01,02,03,04} • CVSS 9.8 • KEV Listed
4
Spring Framework RCE (CVE-2023-20863)
Affects: payment-processor-{01,02,03} • CVSS 8.1 • Exploit Available
3
Jetty HTTP/2 DoS (CVE-2023-44487)
Affects: All payment services • CVSS 7.5 • KEV Listed
8

Total cluster ROED: 312 days • Remediation plan: Q1 2025 migration to managed PaaS

Exception Queue

Lab Environment Exclusions
12 CVEs • Expires: Mar 15
Approved: Risk Committee
Air-Gapped OT Systems
8 CVEs • Permanent
Compensating: Physical Seg
Vendor Patching Lag
5 CVEs • Review: Jan 31
Mitigation: WAF Rules
Legacy POS Hardware
19 CVEs • Sunset: Jun 2025
Compensating: Network ACLs

Total exceptions: 44 • Re-assessment cycle: 90d

CISA KEV Feed: v2024.01.15 (Updated daily)
EPSS: v2024.01.14
Scan Coverage: 98.7%
Last Full Scan: 6h ago
Next Remediation Council: Jan 22, 2025