Vulnerability analysis goes beyond running scans — it requires assessing each finding against your organization's specific environment, risk tolerance, and asset value to determine true impact. Standard severity scores like CVSS provide a starting point, but organizations must often reclassify vulnerabilities to reflect their actual exposure.
Vulnerability Analysis Process
Once we've identified vulnerabilities on our network, what we're going to need to do is analyze those vulnerabilities and understand the impact if it were to ever be leveraged.
When we've discovered vulnerabilities on our network, the next part of our process here is to assess those vulnerabilities, and assess them for the possible impact that they would have to our organization.
This actually could be a fairly simple step. A lot of our vulnerabilities are going to be found through vulnerability scans and pen testing, and usually the reports that are generated from that will give us an idea of how critical these vulnerabilities are. A lot of these systems are going to have some sort of scoring system, and there's a good chance it's the CVSS, that's going to score things on a scale from 0 to 10 on how critical they are and how much we should really pay attention to these vulnerabilities. They also are probably going to have some sort of classification system, where they're going to label things as informational or low, or they're going to label them as high or critical, or somewhere in between.
Just because that's the rating that they give doesn't necessarily mean that's how it applies to your organization. Your organization has other considerations involved — for instance, the context in which it applies, the context to which these might apply. When they're giving you a rating, just an overall rating, it might be from an external standpoint: that is, how serious it is if they had access to it from an external standpoint. But it could be on an internal network that's well protected, or even an isolated network.
So there are a lot of environmental variables involved with your organization and how things are structured. You could have different exposure factors. You could be part of an industry or an organization that either says it's not that critical, or maybe says it's more critical. Or there could be a way that it could be exploited or weaponized that's different for your company. Maybe it doesn't deal with assets that are all that valuable, or maybe they're very valuable, and so you might recategorize these based off of that. It also has to do with your risk tolerance as a company.
Basically these ratings are a probability that this could happen, how easy it can happen, who can carry it out, and the impact it would be having on your organization. But only you can really fully determine the probability and impact that these have on your organization.
So what you may do is a reclassification. If something comes in as critical, but you analyze it and it has either less of a probability or less of an impact, then maybe you are going to recategorize it to a different category. That is something that you do have the option to do.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →