Decision Matrix

Turn vulnerability signals into the right defender action.

Use this page when a CVE or advisory has several signals and you need to choose patch, mitigate, detect, monitor, validate, or escalate without overreacting.

Decision rule: urgency is not one score. Combine exploitation, exposure, affected version, patch availability, business impact, source confidence, and operational risk before assigning work.

Choose the lane that best matches the evidence

Evidence Checklist Escalation Ladder Open playbooks

Common patterns and the safer default action

Plain-language snippets for tickets and handoffs