For the CISO
You know what's open.
The question is how long it stays open.
The scanner does its job. The report arrives, the findings are ranked, and the board sees a number coming down too slowly. The reason is almost never that no fix exists — it is that the fix is waiting on a window nobody closed. That wait is what you report on, and it is the one thing you have no tool to manage.
- TodayThe fix waits for a window
- When the window is booked immediatelySame install, earlier
The figure illustrates the mechanism. It is not based on a customer measurement, and we will not show a number we do not have.
What the report doesn't show
The number falls slowly, and the reason isn't in the scanner.
Technically fixed, practically open
The patch exists, has been tested, and is ready. It is waiting on an approval from an owner who is on leave. On the report it is still a red row.
CVSS doesn't know your business
A 9.8 on a test box and a 7.5 on the core platform. The technical score cannot tell you which one takes payments down.
Blast radius is guesswork
When a window is planned, the question of what falls over with this system is usually answered from the memory of whoever happens to be in the room.
Nothing to report but a count
Open findings is a poor measure of a process. What the board asks is how long it takes to close one, and there is no field for that.
What changes
The patch becomes a schedulable unit.
The patch, not the CVE
One patch usually fixes several vulnerabilities across several hosts. The register groups by patch, because that is the unit a window can be booked for.
A score you can explain
Shown with every term that produced it and how much each contributed — business criticality, exposure, patch age. The terms sum to the score. You can disagree with it; you cannot call it arbitrary.
Blast radius read from the estate
The dependency map is built from actual host-to-host traffic rather than a document. That is also where the two-systems-one-night warning comes from.
A measure you can report
Per patch: when it entered the register, which window it was booked into, and what happened there. The interval is time-to-remediate, and it is read out rather than collected.
What you personally receive
A ranked patch register with time-to-remediate
What is open, on which systems, who owns them, and when a window was booked. That is what goes on the quarterly slide instead of a count.
What is blocking your fixes today?
If the answer is "a window" rather than "a patch", that is precisely the problem this product was built for.