Uploaded May 2026 | Updated September 2026, 8 hours ago
Stephen Shaffer (Moderna | EPSS SIG, US)
This session shows how to use asset and CVE data to build a living, Bayesian quantitative model that updates asset-level exploitation likelihoods and overall organization-level exploit-vector incident likelihood using the Exploit Prediction Scoring System (EPSS), control effectiveness data, and public incident data.
---
Stephen Shaffer is currently a Principal Security Engineer at Moderna focused on vulnerability risk management and security data science. He is also the Exploit Prediction Scoring System (EPSS) Special Interest Group (SIG) Co-Chair, championing the use of the EPSS model to quantify vulnerability risk. Previously, he had stints at Peloton, and Centers for Medicare and Medicaid Services (CMS) as a contractor, where he mainly focused on cloud security, compliance engineering, and building security tooling. Stephen is passionate about continuous learning, leading with empathy, and cutting through the FUD in the industry.
Stephen Shaffer (Moderna | EPSS SIG, US)
This session shows how to use asset and CVE data to build a living, Bayesian quantitative model that updates asset-level exploitation likelihoods and overall organization-level exploit-vector incident likelihood using the Exploit Prediction Scoring System (EPSS), control effectiveness data, and public incident data.
---
Stephen Shaffer is currently a Principal Security Engineer at Moderna focused on vulnerability risk management and security data science. He is also the Exploit Prediction Scoring System (EPSS) Special Interest Group (SIG) Co-Chair, championing the use of the EPSS model to quantify vulnerability risk. Previously, he had stints at Peloton, and Centers for Medicare and Medicaid Services (CMS) as a contractor, where he mainly focused on cloud security, compliance engineering, and building security tooling. Stephen is passionate about continuous learning, leading with empathy, and cutting through the FUD in the industry.










