Case Study - Risk Intelligence (Fix What Matters, in Order)
400 findings, 10 engineers, 30 days. Risk intelligence turned panic into a 12-item list the board funded the same day.
SEVERITY
EXPLOIT
ASSET
EXPOSURE
BUSINESS
= Prioritized queue, not CVSS sort
Client Context
Conglomerate — bank + hospital + e-commerce sharing one security team. 400+ open findings, everyone shouting “my app first”. Board: “give me the 10 that could kill us.”
Challenge
Combine severity, exploitability, asset criticality, exposure, and business context into defensible remediation priority — replacing CVSS-only sorting that ranked a back-office medium above an internet-facing payment critical.
Scope - Snipeyes Risk Intelligence
- Asset criticality workshop (funds, PII/PHI volume, SLA, regulatory scope: OJK/BI/UU PDP)
- Exploitability scoring (public exploit, attack path length, compensating controls verified)
- Business-context weight (transaction value, patient safety, outage cost per hour)
- Output: risk-based prioritization queue + “why this first” narrative per item
Key Findings (redacted)
- CVSS Top-10 vs Risk Top-10 overlapped only 3 items — 7 true top risks were CVSS 6-8 with internet exposure + payment/PHI impact
- #1 risk: CVSS 7.5 payment callback flaw (Rp40B/day flow) outranked CVSS 9.8 on isolated back-office host
- 60% effort was going to bottom-half risks before reprioritization
Outcome
- Board funded 12-item fix plan same meeting; all 12 closed in 30 days, measurable exposure drop 73%
- Engineers stopped arguing priority — “risk score + reason” ended the debate
- Model reused quarterly; new findings auto-scored on arrival
Relevance for you: If everything is “critical” — nothing is. Score risk, not just severity.