Uploaded May 2026 | Updated September 2026, 21 minutes ago
Ertugrul Yaprak (Picus Security, TR), Mehmet Kiliç (Picus Security, TR)
Most vulnerability management programs still rely on base CVSS scores and scanner output, even though real‑world risk is heavily shaped by an organization’s own security controls and asset context. The result is familiar: long lists of “critical” findings that are already mitigated, and overlooked “medium” issues that are fully exposed. In this session, we will present a practical approach to validate vulnerability management by combining CVE data, adversary techniques, attack modules, security control effectiveness, and asset criticality into a unified, exposure-driven prioritization workflow. We will begin by examining the relationship between CVEs and security controls, focusing on how standard controls actually impact exploitability in practice. Building on this, we will refine the existing CVSS score to “Contextual CVSS”, which utilizes temporal metrics with exploitability and environmental metrics derived from an organization's context and security control effectiveness. Using real-world, data-driven insights from our ongoing research and development, we will demonstrate how contextualization alters score distributions and risk rankings across groups of CVEs, and how a score of vulnerability or exposure can be layered on top to drive re-prioritization at scale. We will introduce the “Exposure Score”, a unified risk measure that combines control effectiveness, exploitability, and asset importance, as well as contextual CVSS. Finally, we will demonstrate how these exposure metrics can be aggregated at the asset level to support risk-based decision-making for both technical teams and business stakeholders, in a tool- and vendor-agnostic manner that attendees can adapt to their own environments.
---
Ertugrul Yaprak is the Director of the Data Department at Picus Security and leads the data engineering pipeline and AI workflows. He holds a bachelor's degree in computer science and has been involved in data projects for over 20 years.
Mehmet KILIC is the Director of Cyber Security Practices at Picus Security. In this role, he leads the company’s cybersecurity product strategy, identifies real-world customer challenges, and explores innovative security solutions. He focuses on bridging business needs with technical development to deliver effective and practical cybersecurity capabilities.
Ertugrul Yaprak (Picus Security, TR), Mehmet Kiliç (Picus Security, TR)
Most vulnerability management programs still rely on base CVSS scores and scanner output, even though real‑world risk is heavily shaped by an organization’s own security controls and asset context. The result is familiar: long lists of “critical” findings that are already mitigated, and overlooked “medium” issues that are fully exposed. In this session, we will present a practical approach to validate vulnerability management by combining CVE data, adversary techniques, attack modules, security control effectiveness, and asset criticality into a unified, exposure-driven prioritization workflow. We will begin by examining the relationship between CVEs and security controls, focusing on how standard controls actually impact exploitability in practice. Building on this, we will refine the existing CVSS score to “Contextual CVSS”, which utilizes temporal metrics with exploitability and environmental metrics derived from an organization's context and security control effectiveness. Using real-world, data-driven insights from our ongoing research and development, we will demonstrate how contextualization alters score distributions and risk rankings across groups of CVEs, and how a score of vulnerability or exposure can be layered on top to drive re-prioritization at scale. We will introduce the “Exposure Score”, a unified risk measure that combines control effectiveness, exploitability, and asset importance, as well as contextual CVSS. Finally, we will demonstrate how these exposure metrics can be aggregated at the asset level to support risk-based decision-making for both technical teams and business stakeholders, in a tool- and vendor-agnostic manner that attendees can adapt to their own environments.
---
Ertugrul Yaprak is the Director of the Data Department at Picus Security and leads the data engineering pipeline and AI workflows. He holds a bachelor's degree in computer science and has been involved in data projects for over 20 years.
Mehmet KILIC is the Director of Cyber Security Practices at Picus Security. In this role, he leads the company’s cybersecurity product strategy, identifies real-world customer challenges, and explores innovative security solutions. He focuses on bridging business needs with technical development to deliver effective and practical cybersecurity capabilities.










