Risk-based Vulnerability Management (RBVM)
RBVM? Risk based EVERYTHING management.
Vulnerability management was never meant to be a department — the vuln-scanner industry built a circus around it. 'Risk-based' got bolted on retroactively to deal with the noise. But fixing scoring on vulnerabilities alone leaves the same problem on CSPM, ASM, ASPM, audit findings, and everything else. The 'R' in GRC was always meant to be risk management; that's the right level to do the work. Get risk-based risk management right and vulnerabilities slot in alongside every other finding source.
- CVE CVE-2024-3094 · xz
CriticalMediumAirgapped · no exploit path - CSPM Open security group
HighLowInternal-only subnet - ASM Exposed admin panel
MediumHighInternet-facing · exploited - Same rubric across CVE · CSPM · ASM · audit · bounty
How Adversarial delivers RBVM
Findings, Not Just Vulns
CVEs, cloud posture issues, ASM exposures, audit findings, bug-bounty submissions — all on the same register, all scored by the same rubric.
Exposure-Aware
Internet-facing vs airgapped, customer-facing vs internal, exploited-in-the-wild vs theoretical — the rubric reflects what actually matters.
Velocity Over Volume
Trend reporting that measures how fast remediation closes the gap, not how many tickets are still open.
The whole thing is Adversarial.
RBVM is how analysts in this category will recognize the platform — but underneath it is one deterministic system of record covering threats, risks, incidents, and compliance.