Skip to main content
Account

Table 10 ERS components and baseline weights (practitioner-elicited)

From: Evaluating exposure-driven security governance for proactive risk mitigation of AI-powered cyber attacks in digital infrastructures

Component

Definition (normalized)

Baseline weight (w, i)

Rationale (practitioner elicitation summary)

E

Exploitability signal (EPSS probability for the CVE; else default exploitability prior)

0.25

Emphasizes likely-to-be-exploited issues; ranked highest by SOC/IR and vulnerability-management roles

V

Technical severity (normalized CVSS base score: CVSS/10)

0.15

Retains inherent severity while allowing exploitability and context to dominate prioritization

K

Known exploited indicator (KEV/verified exploitation)

0.15

Escalates exposures with verified exploitation pressure and active weaponization signals

A

Asset criticality (business tiering and data sensitivity, normalized to 0–1)

0.20

Ensures prioritization reflects business impact (crown-jewel services/data) and mission disruption

X

Exposure factor (reachability + attack-path + control gaps, e.g., internet-facing, auth gaps, misconfigurations)

0.15

Captures practical reachability and defense-in-depth weaknesses that increase likelihood of compromise

T

Threat context (campaign/sector targeting; ATT&CK relevance; adversary interest)

0.10

Accounts for contextual threat pressure beyond static vulnerability scoring