Rank by business impact, not by CVSS alone.
CVSS measures the vulnerability. It does not know that this host is the one payments depends on.
An explainable score with its terms
The problem
A score you cannot explain will not convince an owner.
When you ask a system owner to take their system down overnight, the first question is why this one and why now. "The tool said 8.7" is not an answer. The score has to come apart into terms somebody can argue with.
What it looks like
A score, with its working underneath
- System criticality — high+28
- Exposure tier — Tier 1+18
- Worst vulnerability severity+22
- Days past due+12
- Affected host count+6
86of 100
- 01
Business-impact analysis
Each system carries a criticality, a description and an agreed service level. That is your data, not ours, and it is the base of everything downstream.
- 02
Terms
Each patch accumulates terms: system criticality, exposure tier, the worst severity among its vulnerabilities, how far past due it already is, and how many hosts it touches.
- 03
Transparency
The score is shown with all of its terms, and they sum to exactly the score. No hidden weight and no normalisation you cannot reproduce.
- 04
Recommendation
Systems are ordered by score, and each row opens the wizard with that system's hosts — split by operating system, because the cadences differ.
The score is computed from data already in the system.
- The BIA register
- The vulnerability register
- Host inventory
- Due dates
Show us your worst window.
Bring the one that keeps slipping. Thirty minutes, your estate, no slides.