How EPSS Is Wrong and Useful at the Same Time @FIRSTdotorg
How EPSS Is Wrong and Useful at the Same Time  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 1 hour ago
Jay Jacobs (Empirical Security, US)

Come learn how the Exploit Prediction Scoring System (EPSS) works and where it’s headed. We will cover the history, what EPSS was designed for, and the evolution of EPSS through the years, including the latest release. Learn about the massive data‑collection system behind EPSS, what data is used and is useful, and which data is the most “interesting.”

We will cover how EPSS overcomes the limitations in common scoring systems and get into common criticisms of the scoring system. Finally, no talk of EPSS would be complete without a discussion about how EPSS should fit into your vulnerability‑prioritization strategy (spoiler: it depends!), so you can grab the scores right away and get to work!

---

Jay Jacobs is a Co-founder and Data Scientist at Empirical Security and Data Scientist Emeritus at Cyentia Institute. Jay is also the lead data scientist for the Exploit Prediction Scoring System (EPSS), a co-chair of the EPSS special interest group at FIRST and chair of the Consumer Working Group within the CVE program. He is also a co-founder of the Society for Information Risk Analysts (SIRA), a not-for-profit association dedicated to advancing risk management practices where he served on the board of directors for several years.
How EPSS Is Wrong and Useful at the Same TimeWhy is Finnish Healthcare Doing So Well Against Ransomware?The Funny Story of Active Directory BackdooringPivoting To Resilience: Disruptive Incidents And How We Prepare For ThemLessons From NPMs Dark Side: Preventing the Next Shai-HuludThe CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is UsefulCISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software Safety
FIRST |

How EPSS Is Wrong and Useful at the Same Time

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER