For years, security teams have been taught to look at vulnerability risk through a number.
That number has been useful. The Common Vulnerability Scoring System, or CVSS, gave the industry a shared language for severity. It helped security teams compare flaws, explain risk to leadership and bring order to an otherwise relentless stream of vulnerabilities.
But a useful measure can become dangerous when it hardens into a habit.
Many organisations still treat CVSS as the default answer to a difficult question: what should we fix first? The highest score rises to the top. The rest follow behind. It is clean, defensible and easy to report.
It is also increasingly incomplete.

Nigel Ng, Senior Vice President, APJ, Tenable
Attackers do not respect our scoring systems
Attackers do not care which flaw looks most severe on a spreadsheet. They look for the shortest route to something valuable: an exposed system, a misconfigured cloud workload, a forgotten credential, an overprivileged identity, or a vulnerable service connected to a critical business process.
That is why the highest-scoring vulnerability is not always the most dangerous one. A critical flaw buried inside an isolated system may matter less than a lower-scoring weakness on an internet-facing asset tied to sensitive data.
CVSS tells a security team something important about the vulnerability itself. What it cannot show on its own is the environment around it: where the flaw sits, how exposed it is, whether it is being actively exploited, what privileges surround it, what data it can reach, and which business process it could disrupt.
The question cannot simply be: how severe is this vulnerability? It has to be: what can an attacker do with it here?
The old patching model is breaking
Vulnerability management was once framed as a problem of discovery. Today, most security teams are not struggling because they lack lists. They are struggling because the lists are too long, the environments are too complex and the time available to act is shrinking.
Tenable’s 2026 Cloud and AI Security Risk Report illustrates the scale of the challenge. It found that 86% of organisations use third-party code packages with critical vulnerabilities, while 18% have overprivileged AI identities expanding their cloud attack surface. These are not isolated technical issues. They are signs of a broader reality: modern exposure now cuts across code, cloud, identity, permissions, data and business systems.
At the same time, attackers are getting faster. AI is not making every attacker a genius, but it is making many parts of the attack cycle easier to scale. Vulnerability analysis, target identification, exploit adaptation and social engineering can all be accelerated. Tenable CTO Vlad Korsunsky has argued that AI is compressing exploitation timelines and pushing security teams away from reactive patching cycles towards exposure management.
This does not mean defenders should panic about every theoretical AI-enabled attack. It means the cost of poor prioritisation is rising. In a slower threat environment, patching the wrong things first was inefficient. In a faster one, it becomes dangerous.
Across APAC, that pressure is becoming more acute. Organisations are digitising quickly, expanding cloud environments, adopting AI-enabled tools and relying on increasingly complex technology supply chains. INTERPOL’s 2025/2026 Asia and South Pacific Cyber Threat Assessment warned of a dramatic increase in cybercrime across the region, driven by rapid digitalisation, new technologies and more organised criminal networks. It also noted that in more than half of countries surveyed, cybercrime now accounts for more than 30% of recorded crime across the region.
Singapore’s Cyber Security Agency has also pointed to an increasingly complex and AI-enabled threat landscape, with its 2025/2026 Cyber Landscape publication highlighting initiatives to strengthen Singapore’s cyber resilience as technology adoption accelerates.
What actually reduces risk
We are not saying to simply abandon CVSS. That would be a mistake. CVSS still provides a valuable baseline for technical severity. It remains useful for triage, communication and consistency.
The mistake is treating that baseline as the final answer.
Exposure management starts from a different premise. Instead of ranking flaws in isolation, it brings vulnerability, asset, cloud, identity and business context together to show where risk actually concentrates and which paths an attacker is most likely to take. CVSS becomes one input among several, alongside exploitability, asset exposure, identity context, cloud configuration, business criticality and likely impact.
That changes the order of work. It helps teams separate what is theoretically severe from what is operationally dangerous. It also helps leaders understand cyber risk in terms the business can act on.
The measure of progress should change too. If security leaders report only the number of critical vulnerabilities closed, they may create the illusion of progress while leaving the most dangerous exposure paths intact. Closing a thousand low-context vulnerabilities may look productive. Removing one path that connects an exposed system, a known exploit and privileged access to a critical business application may reduce far more risk.
This is the uncomfortable truth at the centre of modern vulnerability management: not every critical vulnerability is equally urgent, and not every urgent risk is critical on paper.
Attackers exploit relationships and pathways. Defenders need to do the same.
The organisations that manage this shift well will not be the ones that patch everything at the same speed. No organisation can do that consistently. They will be the ones that understand which exposures matter most, which systems are most consequential and which attack paths must be closed before they are used.
CVSS still matters. But it should not be treated as the patching gospel.
Finding the vulnerability that matters most is not a scoring problem. It is an exposure management problem. In a region digitising this fast, that discipline will separate the organisations that look busy from the organisations that are actually getting safer.
Link applied: https://www.tenable.com/cybersecurity-guide/learn/what-is-exposure-management
