Home / Case studies / V-Score

Cyber · Vulnerability Management

Know your risk.
Fix what matters first.

KATO Vantage is built on the V-Score methodology - a peer-reviewed, open approach to vulnerability risk scoring developed with a government vulnerability management team and delivered through Kaze's Tanium channel partnership. It replaces a single static severity number with a live score that combines CVSS, exploit prediction, real-world exploitation and social media signal - and re-prioritises the moment the threat picture changes.

Case study

Replacing one static number with a living risk score

V-Score was developed with an active government vulnerability management team and is published, peer-reviewed research - not a vendor claim. Here's what changed when they moved off the CVSS score alone.


Powered by KATO Vantage

The problem

CVSS alone doesn't tell you what to fix first

  • CVSS is a static severity score, set once and rarely revisited - even as a vulnerability becomes an active, named threat campaign.
  • Its categories are broad and human-scored, which compresses scores toward the top of the range and leaves little to distinguish genuine emergencies from routine patching.
  • The NVD itself has fallen behind, with a backlog of 17,000+ CVEs awaiting a score.
  • Meanwhile only around 4–5% of known vulnerabilities are ever actively exploited - so treating every high CVSS score as equally urgent wastes limited remediation capacity.

Why this matters

Avg. known vulns / org
1,066
Ever remediated
13%
Avg. time to patch
271 days
NVD scoring backlog
17k+

The approach

Two layers: a global CVE score, then organisational context

Rather than one opaque number, V-Score builds a transparent weighted sum from named, openly available signals - then lets each system's own criticality and exposure adjust the score locally.

Layer 1 · Global

Per-CVE risk, worldwide

A weighted sum of impact and likelihood signals, each normalised to a common 0–1 range so any source can be added, dropped or reweighted.

CVSS · impact EPSS · exploit prediction Known exploits Social media exposure
Layer 2 · Local

Per-system risk, in context

The global score is carried into each system it's found on, multiplied by whether that system is network-accessible, and blended with a criticality rating the asset owner already maintains.

Network accessibility System criticality Prioritised instance queue

A realistic spread of risk, not a wall of red

Distribution of scores across the monitored CVE population, CVSS vs. V-Score

Critical High Medium Low
CVSS V-Score
56%
of 150,589 CVEs rated critical or high by CVSS
<3%
rated critical or high by V-Score - 4,789 CVEs

Real-world example

CVE-2022-21894 and the BlackLotus bootkit

The NVD set this CVE's CVSS score to 4.4 (Medium) in March 2023 - and never touched it again. Two years on, it still reads Medium, despite being confirmed by Microsoft as the vulnerability behind the BlackLotus UEFI bootkit campaign on 11 April 2023.

V-Score, which continuously tracks exploit intelligence and social media activity alongside CVSS and EPSS, moved this CVE from low-priority to top-priority critical the same day the BlackLotus link was confirmed.

CVSS vs. V-Score, Mar–May 2023

Both scores normalised to 0–1 (illustrative reconstruction - Fig. 2a)

Microsoft confirms link · 11 Apr 14 Mar28 Mar 11 Apr 25 Apr 09 May
CVSS - stuck at 4.4 V-Score - reacts same-day

Results after six months

Measured against CVSS on the same vulnerability population

Accuracy predicting CERT-flagged risk
75%
▲ vs 39% for CVSS
Recall of high-risk vulnerabilities
52%
▲ vs 18% for CVSS
Remediation rate
+229%
24 → 55 per week
Critical/high volume
3%
▼ from 56% under CVSS
ScoreAccuracyPrecisionRecallF1
CVSS39%5.4%18%8.3%
V-Score75%31.7%52.0%39.3%
100% of the VM team rated V-Score positively, with most saying it made them far more effective.
VM team user survey, six months after adopting V-Score
Back to the Vantage capability overview