Organizational Context Matters: Security Control Effectiveness on Vulnerabilities for Prioritization @FIRSTdotorg
Organizational Context Matters: Security Control Effectiveness on Vulnerabilities for Prioritization  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 21 minutes ago
Ertugrul Yaprak (Picus Security, TR), Mehmet Kiliç (Picus Security, TR)

Most vulnerability management programs still rely on base CVSS scores and scanner output, even though real‑world risk is heavily shaped by an organization’s own security controls and asset context. The result is familiar: long lists of “critical” findings that are already mitigated, and overlooked “medium” issues that are fully exposed. In this session, we will present a practical approach to validate vulnerability management by combining CVE data, adversary techniques, attack modules, security control effectiveness, and asset criticality into a unified, exposure-driven prioritization workflow. We will begin by examining the relationship between CVEs and security controls, focusing on how standard controls actually impact exploitability in practice. Building on this, we will refine the existing CVSS score to “Contextual CVSS”, which utilizes temporal metrics with exploitability and environmental metrics derived from an organization's context and security control effectiveness. Using real-world, data-driven insights from our ongoing research and development, we will demonstrate how contextualization alters score distributions and risk rankings across groups of CVEs, and how a score of vulnerability or exposure can be layered on top to drive re-prioritization at scale. We will introduce the “Exposure Score”, a unified risk measure that combines control effectiveness, exploitability, and asset importance, as well as contextual CVSS. Finally, we will demonstrate how these exposure metrics can be aggregated at the asset level to support risk-based decision-making for both technical teams and business stakeholders, in a tool- and vendor-agnostic manner that attendees can adapt to their own environments.

---

Ertugrul Yaprak is the Director of the Data Department at Picus Security and leads the data engineering pipeline and AI workflows. He holds a bachelor's degree in computer science and has been involved in data projects for over 20 years.

Mehmet KILIC is the Director of Cyber Security Practices at Picus Security. In this role, he leads the company’s cybersecurity product strategy, identifies real-world customer challenges, and explores innovative security solutions. He focuses on bridging business needs with technical development to deliver effective and practical cybersecurity capabilities.
Organizational Context Matters: Security Control Effectiveness on Vulnerabilities for PrioritizationNIST’s National Vulnerability Database Update and the Vulnerability Enrichment EcosystemDefeating Node.js Malware through API TracingDetection Engineering 101 : Establishing a Structured Approach to Detection EngineeringThe CVE Program Quality Era: Strengthening Trust and Impact In Global Vulnerability DataFragile by Design: Large-Scale Evidence of Supply Chain RiskFriday Keynote Address - Network Security is a Team Sport, so How Do We Set and Manage the TeamVulnerabilities Without CVEs: Governing the Dark Matter of Internal and Unknown SoftwareEpisode 61: Chris Butera, CISA, FIRSTCON26 Speakernx Compromise - AI as an Attack VectorAutomating CNA CVE Reporting and Monthly Bulletins at AtlassianClosing Remarks
FIRST |

Organizational Context Matters: Security Control Effectiveness on Vulnerabilities for Prioritization

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER