Free practitioner tool // Evidence stays in your browser
Vulnerability Decision Brief
Turn a vulnerability record into a defensible response decision. The tool calculates the official CISA SSVC outcome, keeps KEV, EPSS and CVSS as separate signals, surfaces evidence gaps, and produces a one-page handoff for operations or leadership.
- Official SSVC decision logic
- No invented composite risk score
- Exportable operational record
Why this is more than a checklist
What this changes for vulnerability teams
The brief connects public intelligence, business context, response logic, and closure evidence without hiding them inside a proprietary score. The result is a decision another team can understand, challenge, execute, and later audit.
Consistent decisions
The same five CISA SSVC decision points produce the same official outcome, reducing analyst-to-analyst variation.
Signals keep their meaning
CVSS, EPSS, and KEV answer different questions. Keeping them separate prevents a convenient number from concealing uncertainty.
A clear incident boundary
Suspected or confirmed compromise is recorded independently, so an urgent patch decision does not replace incident triage.
Evidence-ready closure
The handoff records what is known, what is missing, who owns the action, and what will prove that treatment is complete.
- IdentifyCase and service
- EnrichKEV, EPSS, CVSS
- DecideOfficial SSVC outcome
- BoundIncident and evidence gaps
- HandoffCopy, PDF, or JSON
Field feedback wanted
Test it against a real decision
This first release will improve only if practitioners challenge it. After using it, tell us:
- Which evidence field was missing?
- Would you attach the exported brief to a remediation ticket or risk exception?
- Where did the operational guidance fail your environment?