security

Why Security Context Matters More Than Severity

Severity scores tell you how bad a finding could be in isolation. Context tells you whether it matters in your environment.

Hrudu Shibu2 min de lectura

Most security tools rank findings by severity. A CVSS score, a "critical" label, a red badge in a dashboard. It feels objective, and it gives teams a tidy way to sort a backlog. The problem is that severity describes a vulnerability in isolation, not the risk it poses inside a specific environment.

A critical vulnerability on an isolated test instance with no network path to anything sensitive is not an emergency. A medium vulnerability on an internet-facing host that holds a role with write access to a production database might be the most urgent thing you deal with this quarter. Severity alone cannot tell these two apart.

What context adds

Context is the set of facts that turn a finding into a risk you can reason about:

  • Exposure — is the asset reachable from the internet, or only from a tightly controlled internal segment?
  • Asset criticality — does it touch customer data, production systems, or disposable scratch space?
  • Identity and permissions — what can an attacker do once they land here?
  • Reachability — is there an actual path from an entry point to something that matters?

None of these show up in a severity score. All of them change the answer to the only question that matters: should I fix this now?

From a list to a graph

Context is relational. A permission matters because of what it grants on another resource. An exposed host matters because of where it can reach. The natural way to represent that is a graph that connects assets, vulnerabilities, identities, permissions, cloud resources, and findings into one picture.

Once the relationships are explicit, prioritization stops being a sort on a single column and becomes a question of which findings sit on a real path to a real target. That is the shift Pacifics is built around: not louder alerts, but connected context.

Where to start

You do not need to boil the ocean. Start by asking, for your loudest findings, whether there is actually a path from an exposed entry point to a critical asset. More often than not, the ranking you get from context looks very different from the one you get from severity — and it is a far better guide to where your limited time should go.