Case Study - Risk Intelligence (Fix What Matters, in Order)

400 findings, 10 engineers, 30 days. Risk intelligence turned panic into a 12-item list the board funded the same day.

ILLUSTRATION — RISK FORMULA
⚠️
SEVERITY
💥
EXPLOIT
💎
ASSET
🌐
EXPOSURE
🏦
BUSINESS

= Prioritized queue, not CVSS sort

Client Context

Conglomerate — bank + hospital + e-commerce sharing one security team. 400+ open findings, everyone shouting “my app first”. Board: “give me the 10 that could kill us.”

Challenge

Combine severity, exploitability, asset criticality, exposure, and business context into defensible remediation priority — replacing CVSS-only sorting that ranked a back-office medium above an internet-facing payment critical.

Scope - Snipeyes Risk Intelligence

  • Asset criticality workshop (funds, PII/PHI volume, SLA, regulatory scope: OJK/BI/UU PDP)
  • Exploitability scoring (public exploit, attack path length, compensating controls verified)
  • Business-context weight (transaction value, patient safety, outage cost per hour)
  • Output: risk-based prioritization queue + “why this first” narrative per item

Key Findings (redacted)

  • CVSS Top-10 vs Risk Top-10 overlapped only 3 items — 7 true top risks were CVSS 6-8 with internet exposure + payment/PHI impact
  • #1 risk: CVSS 7.5 payment callback flaw (Rp40B/day flow) outranked CVSS 9.8 on isolated back-office host
  • 60% effort was going to bottom-half risks before reprioritization

Outcome

  • Board funded 12-item fix plan same meeting; all 12 closed in 30 days, measurable exposure drop 73%
  • Engineers stopped arguing priority — “risk score + reason” ended the debate
  • Model reused quarterly; new findings auto-scored on arrival

Relevance for you: If everything is “critical” — nothing is. Score risk, not just severity.