Skip to main content
Regulaxy
Protect

Rank by business impact, not by CVSS alone.

CVSS measures the vulnerability. It does not know that this host is the one payments depends on.

The artifact

An explainable score with its terms

The problem

A score you cannot explain will not convince an owner.

When you ask a system owner to take their system down overnight, the first question is why this one and why now. "The tool said 8.7" is not an answer. The score has to come apart into terms somebody can argue with.

What it looks like

A score, with its working underneath

A table of terms you can export and attach to the approval request. It is also what goes to the system owner in the summary mail.
Figure — a score broken into its terms
How it works
  1. 01

    Business-impact analysis

    Each system carries a criticality, a description and an agreed service level. That is your data, not ours, and it is the base of everything downstream.

  2. 02

    Terms

    Each patch accumulates terms: system criticality, exposure tier, the worst severity among its vulnerabilities, how far past due it already is, and how many hosts it touches.

  3. 03

    Transparency

    The score is shown with all of its terms, and they sum to exactly the score. No hidden weight and no normalisation you cannot reproduce.

  4. 04

    Recommendation

    Systems are ordered by score, and each row opens the wizard with that system's hosts — split by operating system, because the cadences differ.

What it connects to

The score is computed from data already in the system.

  • The BIA register
  • The vulnerability register
  • Host inventory
  • Due dates

Show us your worst window.

Bring the one that keeps slipping. Thirty minutes, your estate, no slides.