Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortra:Why Vulnerability Count Doesn't Predict Breach Risk

Fortra
07/10/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I mean, these things are just littered with vulnerabilities. You just kick a rock and you've hit a vulnerability with these companies, but they've never been compromised, or if they have been compromised, they've never noticed. It's never affected their business. They're still in business. So why does it matter that you have 300,000 or 300 million vulnerabilities or 400 million vulnerabilities? Why does that matter? It turns out it doesn't really correlate with loss or even breach, which is a lower bar. And so I'm not saying they're free of vulnerability and those vulnerabilities aren't real things that could be used to break in. But I am saying that if you're going to patch, clearly, that's not the way to do it. Clearly, that is not having the most impact on breaches and losses. And so that's kind of where I like to draw the line and where the breach and loss informs your patch management.

TL;DR

  • Many large organizations carry hundreds of millions of vulnerabilities and have still never experienced a material breach or measurable business loss.
  • Raw vulnerability counts do not meaningfully correlate with breach likelihood or financial loss, making them an unreliable prioritization metric.
  • RSnake argues that patch management strategy should be driven by breach probability and business impact rather than total vulnerability volume.

Summary

In this short clip from The Art of Security podcast, cybersecurity expert Robert "RSnake" Hansen challenges one of the most deeply held assumptions in vulnerability management: that a high vulnerability count signals high risk. Hansen points out that many large organizations carry tens or even hundreds of millions of vulnerabilities in their environments — and yet have never suffered a material breach or measurable business loss. His central argument is that raw vulnerability counts simply do not correlate with actual breach likelihood or financial impact, making them a poor basis for prioritizing remediation efforts. Rather than chasing every CVE in the queue, Hansen advocates for a risk-based patching strategy grounded in breach probability and business impact. The implication for security teams is significant: patch management should be informed by what actually drives losses, not by what inflates a vulnerability dashboard. This clip serves as a provocative entry point into a longer episode exploring how organizations can rethink their approach to vulnerability management in a world where perfect remediation is impossible.

Chapters

0:00 - The Vulnerability Overload Reality
0:19 - Does Volume Actually Matter?
0:28 - No Correlation with Loss or Breach
0:41 - Rethinking Patch Prioritization

Key Quotes

0:00 "Many companies now that have over 10 million vulnerabilities and up to hundreds of millions of vulnerabilities — these things are just littered with vulnerabilities."
0:28 "It turns out it doesn't really correlate with loss or even breach, which is a lower bar."
0:41 "If you're going to patch, clearly, that's not the way to do it. Clearly, that is not having the most impact on breaches and losses."
0:51 "That's kind of where I like to draw the line and where the breach and loss informs your patch management."

FAQ

Does having millions of vulnerabilities mean a company is at high risk of being breached?

Not necessarily, according to RSnake. He notes that many companies with over 100 million vulnerabilities have never been compromised or suffered business impact, suggesting vulnerability count alone is a poor predictor of breach risk.

What should drive patch management decisions if not vulnerability count?

RSnake argues that breach likelihood and business loss should be the primary inputs — patching should focus on vulnerabilities most likely to result in an actual compromise or measurable financial harm.


Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Vulnerability Management
  • Threat Intelligence
  • Security Operations
  • Best Practices
  • Thought Leadership
  • short_form
  • Risk-Based Patching
  • Patch Prioritization
  • Breach Likelihood
  • CVE Overload
  • Security Risk Quantification
  • Cybersecurity Strategy
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortra:Why Vulnerability Count Doesn't Predict Breach Risk

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                      https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version