Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortra:Why Vulnerability Count Doesn't Predict Breach Risk

Fortra
07/10/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I mean, these things are just littered with vulnerabilities. You just kick a rock and you've hit a vulnerability with these companies, but they've never been compromised, or if they have been compromised, they've never noticed. It's never affected their business. They're still in business. So why does it matter that you have 300,000 or 300 million vulnerabilities or 400 million vulnerabilities? Why does that matter? It turns out it doesn't really correlate with loss or even breach, which is a lower bar. And so I'm not saying they're free of vulnerability and those vulnerabilities aren't real things that could be used to break in. But I am saying that if you're going to patch, clearly, that's not the way to do it. Clearly, that is not having the most impact on breaches and losses. And so that's kind of where I like to draw the line and where the breach and loss informs your patch management.

TL;DR

  • Many large organizations carry hundreds of millions of vulnerabilities and have still never experienced a material breach or measurable business loss.
  • Raw vulnerability counts do not meaningfully correlate with breach likelihood or financial loss, making them an unreliable prioritization metric.
  • RSnake argues that patch management strategy should be driven by breach probability and business impact rather than total vulnerability volume.

Summary

In this short clip from The Art of Security podcast, cybersecurity expert Robert "RSnake" Hansen challenges one of the most deeply held assumptions in vulnerability management: that a high vulnerability count signals high risk. Hansen points out that many large organizations carry tens or even hundreds of millions of vulnerabilities in their environments — and yet have never suffered a material breach or measurable business loss. His central argument is that raw vulnerability counts simply do not correlate with actual breach likelihood or financial impact, making them a poor basis for prioritizing remediation efforts. Rather than chasing every CVE in the queue, Hansen advocates for a risk-based patching strategy grounded in breach probability and business impact. The implication for security teams is significant: patch management should be informed by what actually drives losses, not by what inflates a vulnerability dashboard. This clip serves as a provocative entry point into a longer episode exploring how organizations can rethink their approach to vulnerability management in a world where perfect remediation is impossible.

Chapters

0:00 - The Vulnerability Overload Reality
0:19 - Does Volume Actually Matter?
0:28 - No Correlation with Loss or Breach
0:41 - Rethinking Patch Prioritization

Key Quotes

0:00 "Many companies now that have over 10 million vulnerabilities and up to hundreds of millions of vulnerabilities — these things are just littered with vulnerabilities."
0:28 "It turns out it doesn't really correlate with loss or even breach, which is a lower bar."
0:41 "If you're going to patch, clearly, that's not the way to do it. Clearly, that is not having the most impact on breaches and losses."
0:51 "That's kind of where I like to draw the line and where the breach and loss informs your patch management."

FAQ

Does having millions of vulnerabilities mean a company is at high risk of being breached?

Not necessarily, according to RSnake. He notes that many companies with over 100 million vulnerabilities have never been compromised or suffered business impact, suggesting vulnerability count alone is a poor predictor of breach risk.

What should drive patch management decisions if not vulnerability count?

RSnake argues that breach likelihood and business loss should be the primary inputs — patching should focus on vulnerabilities most likely to result in an actual compromise or measurable financial harm.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Threat Intelligence
  • Security Operations
  • Best Practices
  • Thought Leadership
  • short_form
  • Risk-Based Patching
  • Patch Prioritization
  • Breach Likelihood
  • CVE Overload
  • Security Risk Quantification
  • Cybersecurity Strategy
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortra:Why Vulnerability Count Doesn't Predict Breach Risk

              Industry Events (Sponsor Hosted)

              • Oct
                13

                Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                10/13/202601:00 PM ET
                • Oct
                  15

                  Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                  10/15/202611:00 AM ET
                  • Oct
                    20

                    Harnessing Data Governance for AI with Cyera and Snowflake

                    10/20/202611:00 AM ET
                    • Oct
                      27

                      Maximize Security, Value, and Returns on Your Microsoft Investment

                      10/27/202611:00 AM ET
                      • Oct
                        27

                        The HUMAN Experience: Real-Time Insights into Page Intelligence

                        10/27/202601:00 PM ET
                        More events

                        Upcoming Webinar Calendar

                        • 10/13/2026
                          01:00 PM
                          10/13/2026
                          Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                          https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                        • 10/15/2026
                          11:00 AM
                          10/15/2026
                          Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                          https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                        • 10/20/2026
                          11:00 AM
                          10/20/2026
                          Harnessing Data Governance for AI with Cyera and Snowflake
                          https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                        • 10/27/2026
                          11:00 AM
                          10/27/2026
                          Maximize Security, Value, and Returns on Your Microsoft Investment
                          https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                        • 10/27/2026
                          01:00 PM
                          10/27/2026
                          The HUMAN Experience: Real-Time Insights into Page Intelligence
                          https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                        • 10/28/2026
                          01:00 PM
                          10/28/2026
                          [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                          https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                        • 11/04/2026
                          11:00 AM
                          11/04/2026
                          Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                          https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                        • 11/04/2026
                          11:00 AM
                          11/04/2026
                          Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                          https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                        • 11/05/2026
                          02:00 PM
                          11/05/2026
                          HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                          https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                        • 11/05/2026
                          02:00 PM
                          11/05/2026
                          Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                          https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                        • 11/19/2026
                          01:00 PM
                          11/19/2026
                          360View: Govern, Secure & Recover Your Microsoft 365 Environment
                          https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version