--- title: "Module 8 β Threat & Vulnerability Management" description: "Quantum vulnerability management for the exploitation-first era. Kill-chain-based prioritisation, the ~90% subtraction, four time-budgeted quanta, and the Kill Chain Assessment app." eyebrow: "Consulting Module" lead: "Time-to-exploit has collapsed to roughly four hours. Median remediation sits at 43 days. No amount of 'patch faster' closes a gap that runs the wrong way by two orders of magnitude. The answer is not to patch faster β it is to stop using the vulnerability list as the unit of work." actions: - label: "Get in Touch" url: "/about/#contact" primary: true - label: "View All Modules" url: "/consulting/skills/" --- ## The Problem with the Old Model CVSS scores severity in the abstract. It knows nothing about whether the vulnerable asset is internet-reachable, whether it sits on the kill chain, whether an exploit exists in the wild, or whether a compensating control already neutralises it. Sorting 40,000 findings by CVSS produces a list precisely uncorrelated with where an attacker will actually go. The 2026 Verizon DBIR confirms vulnerability exploitation is now the leading initial-access vector β roughly twice phishing. This is not a maturity problem solved with more analysts. It is a model that has run out of road. ## What It Delivers
The Kill Chain Assessment app maps your environment as an attack graph and runs a shortest-path computation across every entry point to every crown jewel. The result is the kill chain β the cheapest route from attacker foothold to existential impact. Every finding is classified P0 (on the shortest chain), P1 (on some path), or P2 (off-chain entirely).
Roughly 90% of "critical" vulnerabilities are not exploitable in a given environment once compensating controls, reachability, and segmentation are mapped. This subtraction β removing false urgency before adding any work β turns "40,000 criticals" into the few hundred that are real and the few dozen that are on fire. It is the highest-leverage move in the programme and it is pure deletion.
Critical (hours): On the kill chain, reachable, exploit available now. Response is a compensating control β sever reachability, block at the edge, isolate β not the patch. You cannot meet a four-hour window with a vendor patch cycle.
Severe (days): Material risk; reachable with friction. One change window, verify enforcement.
Standard (sprint): The real, non-urgent tail. Drain in sprint-sized batches on the normal change calendar.
Dark (unsized): Reachability or exploitability unknown. Route to discovery β characterise before remediating.
osquery deployed as a sovereign discovery platform alongside scripted checks for the findings scanners miss β service account privileges, unpatched firmware, container base image CVEs, exposed management interfaces. Discovery before scanner procurement is almost always sufficient to find the kill chain.
The programme does not measure MTTR. It measures whether the kill chain got shorter. Ten incidents that produce ten patches leave the estate equally fragile. Ten incidents that each sever one structural path leave an estate that is genuinely harder to compromise every time it is tested. That is the only honest definition of improvement.
The winning move is not to patch the long tail faster. It is to make most of it not matter β and contain the few that do in hours, not weeks.