Quantifying Swiss Cheese, the Bayesian Way @FIRSTdotorg
Quantifying Swiss Cheese, the Bayesian Way  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 8 hours ago
Stephen Shaffer (Moderna | EPSS SIG, US)

This session shows how to use asset and CVE data to build a living, Bayesian quantitative model that updates asset-level exploitation likelihoods and overall organization-level exploit-vector incident likelihood using the Exploit Prediction Scoring System (EPSS), control effectiveness data, and public incident data.

---

Stephen Shaffer is currently a Principal Security Engineer at Moderna focused on vulnerability risk management and security data science. He is also the Exploit Prediction Scoring System (EPSS) Special Interest Group (SIG) Co-Chair, championing the use of the EPSS model to quantify vulnerability risk. Previously, he had stints at Peloton, and Centers for Medicare and Medicaid Services (CMS) as a contractor, where he mainly focused on cloud security, compliance engineering, and building security tooling. Stephen is passionate about continuous learning, leading with empathy, and cutting through the FUD in the industry.
Quantifying Swiss Cheese, the Bayesian WayMind Over Malware: Reducing Decision Fatigue in Incident Response TeamsSupply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?Incident Preparedness Takeaways from 5000 Exercise ParticipantsEpisode 63: John Hollenberger, Fortinet, FIRSTCON26 SpeakerRevolutionizing Malware Analysis with Agentic AI: Lessons and InnovationsIdentifying Exploited and Likely-to-Be-Exploited VulnerabilitiesTaming the Scanner Storm: How VEX Brings Context to Vulnerability DataEpisode 62: Tim Brown, Team8, former SolarWinds CISO, FIRSTCON26 KeynoteUnmasking MSC FilesImproving Security Across Nations with FIRST: Dr. Lisa Bradley, FIRST PSIRT SIG MemberFlipping the Criticality Funnel, A Practical Path to Real Prioritization
FIRST |

Quantifying Swiss Cheese, the Bayesian Way

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER