1. Why Severity-Only Triage Fails
$ core idea: CVSS scores describe a vulnerability's characteristics in isolation — they do not capture whether exploitation is active in the wild, whether the affected system is internet-exposed, whether an attacker can reach it from your network, or whether it sits on a business-critical service. All of those factors change operational urgency.
$ defender angle: A medium-severity finding on a public-facing VPN or identity provider often deserves faster action than a critical finding on an isolated development host with no network exposure. Risk comes from the intersection of vulnerability, exposure, and asset value — not from a number in the NVD.
$ prove understanding: Define asset criticality and exposure categories that matter to defenders.