Cohesity's Purser on vulnerability
Dr. Joye Purser of Cohesity outlines a decision logic for analysts when KEV, EPSS, and CVSS scores conflict, prioritizing active exploitation first.

Dr. Joye Purser, Global Field CISO at Cohesity, has provided a clear decision logic for security analysts facing conflicting vulnerability scores. In an interview with Help Net Security, she stated that active exploitation, indicated by the KEV catalog, must be the highest priority. This is followed by assessing exploit likelihood via EPSS and then evaluating technical severity with CVSS, with adjustments for an organization's specific context.
Purser's rule is explicit. Active exploitation comes first, then exploit likelihood, then technical severity. Adjustments must be made for asset exposure, business criticality, and compensating controls. A lower-severity flaw in an exposed identity system can pose a more immediate risk than a critical one in an isolated asset. The scores are useful, but they need to be applied in the context of the environment.
Realistic remediation targets and tradeoffs
For a critical, internet-exposed vulnerability with known exploitation, Purser sets a reasonable target of 24 to 72 hours. Many mid-sized organizations will struggle to achieve this consistently.
Getting there requires significant tradeoffs. Security and IT teams need the authority to interrupt normal release schedules. They must dedicate engineering resources to emergency testing and deployment. Sometimes, they must accept temporary service disruption or reduced functionality. When an immediate patch is not possible, organizations need to be prepared to use compensating controls like restricting access or isolating a system.
The biggest requirement is organizational. Actively exploited internet-facing vulnerabilities have to be treated as an operational priority. Faster remediation requires ownership, pre-approved emergency procedures, and coordination across teams.
The hidden risks of deception technology
Purser identified a primary failure mode vendors do not advertise. A honeypot intended to observe attackers can become another foothold. This happens if it has access to production systems, reusable credentials, excessive privileges, or its own vulnerabilities.
Compliance and governance concerns can also arise. Deception systems may capture attacker activity, credentials, or production-like data. If retention, privacy, legal, and evidentiary requirements are not considered in advance, those systems can create unanticipated obligations.
Deception technology should therefore be isolated and tightly permissioned. Treat it as potentially hostile infrastructure from the outset. Never allow unnecessary trust relationships with production environments.
Unglamorous, high-value controls
Phishing-resistant multifactor authentication remains one of the most important controls an organization can deploy. It is not new or glamorous, but preventing stolen credentials from immediately becoming usable access can significantly slow an attacker down.
Basic identity hygiene is equally important. Organizations should remove dormant accounts, restrict privileged access, enforce least privilege, rotate credentials, and apply stronger controls to administrative accounts. Attackers still succeed because credentials are reused, privileges are broader than necessary, or old accounts remain active.
These controls are most effective when used together. MFA, restricted administrative access, segmented privileges, and credential revocation can make common attack paths harder. They can also limit lateral movement after an initial compromise, a key factor in squad defense coordination.
Budget allocation for a manufacturer under threat
When asked where to spend the first $50,000 of a $250,000 budget defending a 400-person manufacturer, Purser emphasized operational safety. The priority must be protecting operations and human safety. She suggests ensuring critical operational technology is segmented from corporate IT and eliminating unnecessary external access.
The next priority would be identity. Use phishing-resistant MFA for privileged and remote access. Remove stale accounts and tightly control administrative privileges. She also advised ensuring the organization has protected backups of its most critical systems and has tested recovery.
Some budget should go toward basic visibility and response readiness. The organization needs to know which assets are exposed, who owns them, and who has the authority to isolate systems. With a limited budget, the goal is to reduce easy attack paths and contain the blast radius. A single compromise must not stop the entire operation, a principle that aligns with maintaining robust fixtures in critical infrastructure.




