Security1 distinct publisher3 min readPublished
Joye Purser answered the question most vulnerability programs only argue about mid-outage. She attached hours and dollars to the answer instead of leaving it as scoring philosophy. The preconditions are where it gets expensive.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
KEV records exploitation that someone has already observed [1], EPSS estimates how likely exploitation is [2], and CVSS describes the technical impact if it lands [3]. The ranking follows from that: evidence before forecast, forecast before property, then adjustments for asset exposure, business criticality, compensating controls and the consequences of compromise [4]. The worked case is the one every mid-sized shop already has open somewhere. A lower-severity flaw in an exposed identity system can carry more immediate risk than a critical flaw in an isolated asset [5].
The hours are the least interesting part of the 24-to-72 figure. Purser says many mid-sized organizations will struggle to hit it consistently [7], and what she names as the biggest requirement is organizational rather than technical: ownership, pre-approved emergency procedures, and coordination across security, IT and application teams [10]. Without the pre-approval, a 72-hour target resolves into a change advisory board meeting. Where a patch cannot ship inside the window, the fallbacks are written down too, and they are the ordinary ones: restrict access, disable the vulnerable feature, isolate the system [9].
The budget question is where the Help Net Security interview [17] gets specific and then stops. It asks where a 400-person manufacturer with a $250,000 security budget should spend its first $50,000 [11]. That tranche is 20 percent of the program [1]. Against headcount, the whole budget is $625 per employee per year and the first tranche is $125 of it [2], which is roughly the price of one phishing-resistant token per head with change left over. The text supplied to us ends inside the identity-hygiene answer, before the allocation itself appears [18], so the $50,000 here frames the problem rather than serving as a recommendation anyone can quote.
The control Purser names as unglamorous and still the best time-buyer is phishing-resistant multifactor authentication, on the grounds that it stops stolen credentials from becoming usable access immediately [15]. Behind it: dormant account removal, restricted privileged access, least privilege, credential rotation, and stronger controls on administrative accounts [16]. That closes the loop with the ranking. If an exposed identity system is what promotes a medium-severity finding to the front of the queue, identity hygiene is the compensating control that demotes it again, and it is cheaper than the emergency change window it prevents.
The honeypot advice cuts against the usual assumption that deception tooling is inherently safe simply because it is a defensive product. Deception is to be treated as potentially hostile infrastructure from the outset, isolated, tightly permissioned, continuously monitored, and never given unnecessary trust relationships with production [14]. That is the same posture you would apply to a third-party appliance you did not choose.
Ranked by verification strength, evidence, and original report placement.
The interview covers where a 400-person manufacturer with a $250,000 budget should spend its first $50,000.
Purser identifies KEV listing as the indicator of active exploitation, making an actively exploited vulnerability the highest priority, particularly on an internet-exposed or business-critical asset.
Purser uses EPSS to assess exploit likelihood, applied after KEV in the order.
Purser uses CVSS last, to understand potential technical impact.
The decision logic Purser says she would write down for an analyst is: active exploitation first, then exploit likelihood, then technical severity, with adjustments for asset exposure, business criticality, compensating controls, and the potential consequences of compromise.
Purser: a lower-severity vulnerability in an exposed identity system may pose a more immediate risk than a critical vulnerability in an isolated asset.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Three AI scanners disagreed on 95 percent of one codebase's findings in Contrast's test1 distinct publisher
security
Frontier AI can find the bugs faster. The patch queue is the number nobody published.1 distinct publisher
security
A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One voice, cleanly quoted, nothing checked
Every assertion in this story traces to one person in one interview. The score ordering, the 24-to-72-hour window, the honeypot warnings — Help Net Security quotes them accurately and no one else touches them. And nothing Purser offers is measured: asked directly whether she had watched a honeypot turn into a foothold or a compliance liability, she answers in the conditional 'can become', with no case, no count and no telemetry behind the remediation clock. Provenance is clean; the underlying support is professional judgment.
No uptake visible
KEV, EPSS and CVSS appear only as instruments Purser reaches for in a given order. This reporting never says how many organizations sequence them that way, how many hit her clock, or what any of it produced — and offers no release, deployment or incident from which we could count. Advice is not adoption, and there is nothing to observe.
Framing runs slightly ahead of the interview
The hours and dollars are genuinely there, so the promise of specifics is mostly kept — but Purser hedges the clock in the same breath she sets it, and declines the one question that would have made the deception section reportage rather than advice. The gap is ours more than hers: we said the transcript stops before the budget answer, and Help Net Security prints that answer in full, including the operational-technology segmentation and tested-backup priorities. Overstatement is modest and lives in the packaging.
Vendor field CISO, vendor-shaped shortlist
Purser's title is Global Field CISO at Cohesity, a data-protection company, and when asked where a squeezed manufacturer's first $50,000 goes she includes protected backups of critical systems with tested recovery. That is a short walk from advice to product category. The page also closes on a report download, so the interview sits inside a lead-generation frame at both ends. None of this makes the segmentation or MFA guidance wrong; it does mean nothing in the story is disinterested, and the parts nearest her employer's business deserve the most scrutiny.
Confident about what was said, not about whether it holds
A single publisher, a single interviewee, no corroboration, and a factual slip in our own summary that the source itself corrects. We can vouch for the wording of Purser's ordering and her clock. Whether 24 to 72 hours is achievable in the mid-market, or how often deception environments actually get turned around on their owners, this reporting cannot tell you.