Vulnerability Overload: Making Prioritization Work in the Real World

Critical Assets Podcast by Patrick Miller

Episode notes

In this episode, Patrick Miller speaks with Kylie McClanahan, CTO at Bastazo, about the practical (and often messy) realities of patch and vulnerability management in operational technology (OT) environments. Kylie shares grounded insights into patching challenges, the gaps between IT and OT remediation cycles, and the real-world implications of relying too heavily on scoring systems like CVSS.

The conversation covers CISA’s Known Exploited Vulnerabilities (KEV) catalog, exploring how it’s being used (and possibly misused) in prioritization workflows, and where the disconnects lie between policy directives and operational feasibility. Kylie also critiques the current state of vendor responsiveness, machine-readable vulnerability disclosure (CSAF), and the importance of asset and exposure awareness.

This episode is essential listening  ... 

 ...  Read more
Keywords
fercnercnerc cipsecurity metricscybersecurityNIST CSFNISTvulnerability managementpatch managementCVSSKEVSSVCCSAFCISA