TechKnowSurge
CompTIA CySA+ 2.3 CompTIA CySA+ 2.5 ISC2 CISSP 7.8 NIST CSF ID.RA-05 CompTIA Security+ 4.3 CompTIA SecurityX 2.6 NIST 800-53 RA-5
VideoSecurityFree

Prioritization and Escalation

Vulnerability prioritization is the process of ranking identified security weaknesses by severity so remediation efforts are applied in the most effective order. Understanding when to escalate urgent patches and how zero-day vulnerabilities fit into this workflow are key components of a sound vulnerability management program.

Complete this video to capture a CTF flag worth 1 point.

About this video

Vulnerability management follows a structured lifecycle that moves from discovery and validation through assessment and, ultimately, prioritization. Once vulnerabilities have been identified and classified by severity — commonly using ratings of low, medium, high, or critical — security teams must determine the order in which those issues will be remediated. In most cases, this means addressing critical vulnerabilities first and working down through lower severity levels, though the specific approach can vary depending on organizational context and risk tolerance. Not all prioritization decisions follow a strictly severity-based sequence. Certain vulnerabilities require immediate escalation regardless of where they might fall in a standard queue, particularly when a patch is publicly announced and delayed deployment would expose systems to significant risk. These situations are often surfaced through security news feeds and industry advisories rather than internal scans or penetration tests, and they demand an accelerated response outside the normal remediation cycle. A related concept frequently encountered in this context is the zero-day vulnerability, which refers to a flaw that is unknown to the vendor or developer, leaving them zero days to prepare a fix. In practice, the term is sometimes misapplied to any urgent patch situation, even when a patch already exists and the vendor has had time to respond. Understanding the distinction between a true zero-day and an expedited patch deployment is important for accurately communicating risk and managing remediation workflows.

What you'll learn

What's covered

Vulnerability Prioritization

Aligned to

CompTIA CySA+
2.3 Given a scenario, analyze data to prioritize vulnerabilities.
2.5 Explain concepts related to vulnerability response, handling, and management.
ISC2 CISSP
7.8 Implement and support patch and vulnerability management.
NIST CSF
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
CompTIA Security+
4.3 Explain various activities associated with vulnerability management.
CompTIA SecurityX
2.6 Explain how threat and vulnerability management techniques are used in the enterprise.
NIST 800-53
RA-5 Vulnerability Monitoring and Scanning

Key terms

Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Vulnerability Assessment
The process of identifying, quantifying, and prioritizing vulnerabilities in a system.
Patch Management
The process of acquiring, testing, and installing software updates to fix vulnerabilities and improve functionality.
Zero-Day
A vulnerability that is unknown to the vendor and has no available patch at the time of exploitation.
Escalation
The process of elevating a security issue — such as a critical vulnerability or active incident — to a higher priority or authority level when the standard response process is insufficient or too slow to address the threat.
Remediation
The process of fixing or mitigating identified vulnerabilities to eliminate or reduce their associated risk.

Topics

Vulnerability Management Vulnerability Prioritization Zero Day Vulnerabilities Patch Management Severity Classification Escalation Procedures Cybersecurity

Transcript

Once we've found vulnerabilities on our network, and we've also done an assessment of what kind of vulnerabilities they are and classified them, the next step is that we've got to prioritize them: in which order we're going to fix these vulnerabilities, or remediate these vulnerabilities.

Where prioritization sits in vulnerability management

When it comes to vulnerability management, the first step is going to be to discover those vulnerabilities. Next, what we have to do is we have to validate the vulnerabilities and assess the vulnerabilities. Once we've done that, then we're going to start prioritizing them in the order in which we're going to tackle or fix or remediate these vulnerabilities.

This actually could be a pretty simple step. That is, you've already got some sort of classification, you've done some analysis on this and you've got some classification to it, so it could be categorized by a number or by these classifications of low, medium, high or critical. And then you'll have to decide now which order to put them in, and it's probably going to be based off of these classifications. You're going to tackle all the criticals, and then all the highs, and then all the mediums, and so on and so forth.

Now, we might not 100% of the time go with whatever the most critical one is first. There are other reasons why I prioritize; I have all different methods of prioritizing my projects, and in this case vulnerabilities and the fixes for those vulnerabilities. However, most of the time it's just going to be based off of the rating and what we should tackle.

Escalation

There are times when things need to be escalated right away. That is, there is a patch that comes out and it needs to be applied right away, immediately, and if not it could put us at big risk. Now, you don't always find this through a vulnerability scan or pen testing. Usually it's found because there are big announcements and it's on news feeds, and this is an issue with this type of system and you need to patch it right away. And so we escalate it to being the top priority and we are going to push it out right away.

Now, sometimes this is mislabeled as zero day. Zero day is when the developers have zero days to respond to something, because they don't know about it, or maybe it's just been discovered. And so zero day happens pretty early on in the life cycle of a vulnerability. A lot of times I find that the patches come out, you need to deploy it ASAP, but for some reason people still call this a zero day. I think it's just mislabeled, but it is a term that's used and popular.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →