1. Why Severity-Only Triage Fails
$ core idea: Severity scores help with standardization but do not capture whether a vulnerability is actively exploited in the wild, internet-exposed, reachable in your architecture, or relevant to a business-critical service.
$ defender angle: A medium-severity issue on a public identity system may deserve faster action than a high-severity issue on an isolated lab host. Context drives operational risk.
$ prove understanding: Define asset criticality and exposure categories that matter to defenders.