Brad Liggett
Brad Liggett is a veteran in the cybersecurity realm, with more than twenty five years of experience in the tech industry. Leveraging his extensive knowledge as in Cyber Threat Intelligence, Brad has led companies through the waves of technological evolution, setting up best practices for effectively and securely adapting to the swift advancements in digital technology. At present, Brad is at the forefront of aiding organizations in their quest to outpace cyber threats and fortify their defenses.
Session
Most vulnerability programs do exactly what they were built to do. They scan everything, ticket the 9.8s and report a shrinking critical count to the board. Attackers still walk in through the CVSS 6.2 on the public VPN. This talk explains why severity scores were never meant to measure risk, and how free signals like CISA KEV and EPSS can cut the list down to what attackers actually use. It also covers how reachability, compensating controls and asset value decide what really matters in your environment, and what CISA's new BOD 26-04 means now that CVSS is out of the federal decision model. Attendees leave with a practical way to move from "fix 150,000" to "fix the 40 that will breach you," plus one question to ask their team on Monday.
Takeaways:
- Why CVSS measures severity, not risk
- How to use KEV and EPSS together to prioritize
- How compensating controls change exposure, and what BOD 26-04 means for that
- A simple maturity path from scanning to exposure management