Modeling Asset Risk Using Grouped EPSS

CVE/FIRST VulnCon 2025 · Main Stage

Overview

In an era of relentlessly escalating cybersecurity threats and an ever-growing deluge of vulnerabilities, traditional vulnerability management approaches are proving increasingly inadequate. This talk, "Modeling Asset Risk Using Grouped EPSS," presented by Stephen Jacobs, a Principal Security Engineer at Moderna Therapeutics and co-chair of the EPSS Special Interest Group, addresses this critical challenge head-on. Jacobs introduces a novel methodology to shift the focus from individual Common Vulnerabilities and Exposures (CVEs) to a more holistic, asset-centric view of risk.

Watch on YouTube

Visual summary for Modeling Asset Risk Using Grouped EPSS
Visual summary for Modeling Asset Risk Using Grouped EPSS

Key moments

  1. 0:00 Introduction to talk and speaker's background
  2. 2:00 Overview of the escalating vulnerability management problem
  3. 4:00 Industry average of closing only 10% of backlog
  4. 5:50 Scaling EPSS to assets and groups concept
  5. 6:30 Detailed explanation of the Grouped EPSS mathematical formula
  6. 8:00 Statistical property and independence of events assumption
  7. 8:50 Practical Python code for calculating Grouped EPSS

Modeling Asset Risk Using Grouped EPSS

Speakers: Stephen Jacobs, Principal Security Engineer, Moderna Therapeutics

Conference: VulnCon

YouTube: https://www.youtube.com/watch?v=W2UMqkRyBOY

Overview

In an era of relentlessly escalating cybersecurity threats and an ever-growing deluge of vulnerabilities, traditional vulnerability management approaches are proving increasingly inadequate. This talk, "Modeling Asset Risk Using Grouped EPSS," presented by Stephen Jacobs, a Principal Security Engineer at Moderna Therapeutics and co-chair of the EPSS Special Interest Group, addresses this critical challenge head-on. Jacobs introduces a novel methodology to shift the focus from individual Common Vulnerabilities and Exposures (CVEs) to a more holistic, asset-centric view of risk.

The core of Jacobs' presentation revolves around operationalizing the Exploit Prediction Scoring System (EPSS) by grouping CVEs to derive a cumulative probability of exploitation at the asset level. This innovative approach allows organizations to quantify the likelihood that at least one vulnerability on a specific asset, network segment, or even an entire department will be exploited in the wild. By providing a clear, data-driven mechanism to identify and prioritize the riskiest assets, the methodology empowers security teams to make more informed decisions, allocate resources effectively, and communicate tangible risk reduction to leadership, moving beyond the often-overwhelming volume of individual CVEs.

This talk is particularly relevant for vulnerability management practitioners, security engineers, and CISOs grappling with the scale and complexity of modern vulnerability landscapes. It provides a practical, actionable framework for integrating threat intelligence (via EPSS) with asset inventory and business context, transforming reactive patching into proactive, risk-aligned defense. Jacobs' work, initially explored in a blog post, distills complex statistical concepts into an implementable solution, offering a crucial step forward in managing organizational cyber risk.

Background

▶ Watch: Introduction to talk and speaker's background (0:00)

The landscape of vulnerability management is characterized by an escalating crisis of scale. Stephen Jacobs highlights this by presenting sobering statistics: the number of CVEs has been steadily increasing over the past 25 years, with 2025 already outperforming previous years since the CNA program expanded in 2017. This exponential growth in newly discovered vulnerabilities creates an unmanageable pipeline of data flowing into organizations. Compounding this challenge, industry averages indicate that organizations are only able to address approximately 10% of their vulnerability backlog month over month. This disparity between the rate of incoming vulnerabilities and the fixed capacity for remediation creates an ever-widening gap, making it virtually impossible for security teams to "patch all the things."

Jacobs recounts his personal struggle with this problem, stemming from his days at the Centers for Medicare and Medicaid Services (CMS), where regulatory mandates often dictated untenable remediation timelines based purely on vulnerability severity. Such prescriptive, volume-based requirements force organizations into a reactive, often ineffective, cycle of "creative compliance" rather than genuine risk reduction. The fundamental question that arises is: how can a vulnerability management program effectively measure and communicate risk and risk reduction if it cannot fix everything?

The solution, Jacobs suggests, lies in a paradigm shift. Instead of focusing solely on the severity or even the individual exploitability of single CVEs, the industry needs a mechanism to understand the cumulative risk posed by multiple vulnerabilities in context. This led him to revisit the EPSS original user guide on first.org, which alluded to the concept of scaling EPSS beyond individual vulnerabilities to broader groupings like assets, network segments, or even entire organizations. The foundational axiom of EPSS is that it provides a measure of the probability of a specific CVE being exploited in the wild within the next 30 days. Jacobs' innovation is to leverage this predictive power to assess risk at a higher, more actionable level.

Key Findings

▶ Watch: Industry average of closing only 10% of backlog (4:00)

The central contribution of Jacobs' talk is the formalization and operationalization of the grouped EPSS score. This metric represents the probability that at least one CVE within a defined group (e.g., an asset, a network segment, or a department) will be exploited in the wild within the next 30 days. This moves the conversation from "how likely is this vulnerability to be exploited?" to "how likely is this asset to experience exploitation due to any of its vulnerabilities?"

The mathematical foundation for the grouped EPSS score is derived from probability theory, specifically the concept of independent events. If we assume that the exploitation of individual vulnerabilities on an asset are independent events, the probability that at least one CVE will be exploited can be calculated by first determining the probability that none of the CVEs will be exploited, and then taking the inverse of that.

The formula is expressed as:

Grouped EPSS = 1 - Π (1 - EPSS_i)

Where:

  • EPSS_i is the EPSS score for an individual CVE on the asset.
  • Π (Pi) denotes the product of all (1 - EPSS_i) terms for every CVE on that asset.

Jacobs highlights that this seemingly complex formula is surprisingly easy to calculate in practice, requiring just a few lines of Python code using the Pandas library, which he demonstrates. The result is a single, cumulative score per asset, providing a powerful indicator of its overall likelihood of exploitation.

Beyond the core calculation, Jacobs emphasizes several key findings:

  1. Asset-Centric Prioritization: The grouped EPSS score allows security teams to identify the "riskiest assets" in their environment, shifting the focus from an overwhelming list of CVEs to a manageable list of critical assets.
  2. Enrichment with Business Context: The grouped EPSS score (representing likelihood) can be married with qualitative data about the asset's business purpose or data classification (representing potential impact). This combination provides a more comprehensive measure of risk, enabling targeted discussions with asset owners. For example, an asset with a high grouped EPSS score that processes sensitive data becomes an immediate priority.
  3. Delta Grouped EPSS for Remediation Impact: Jacobs introduces the concept of delta grouped EPSS, which calculates the difference in an asset's grouped EPSS score before and after a specific CVE is remediated. This metric helps identify which specific CVEs, when addressed, will "move the needle the most" in terms of reducing an asset's overall exploitation probability, ensuring that remediation efforts are maximally impactful.
  4. Dynamic Risk Posture: The grouped EPSS score is not static. It fluctuates daily due to the arrival of new CVEs and changes in individual EPSS scores. Tracking this score over time provides a dynamic, real-time "window into reality," offering a clearer understanding of the organization's asset risk posture and the efficacy of ongoing security efforts. This continuous monitoring serves as a powerful decision support mechanism.
  5. Not a Patch Management Replacement: Crucially, Jacobs stresses that this methodology does not replace good patch management practices. Instead, it acts as a sophisticated prioritization tool, guiding limited resources to where they can achieve the greatest risk reduction.

Technical Deep Dive

▶ Watch: Scaling EPSS to assets and groups concept (5:50)

The technical underpinning of Stephen Jacobs' grouped EPSS methodology lies in a straightforward yet powerful application of probability theory, specifically concerning the probability of independent events.

The core formula for calculating the grouped EPSS score for an asset (or any defined group of vulnerabilities) is:

Grouped EPSS = 1 - Π (1 - EPSS_i)

Let's break down this formula step-by-step:

  1. EPSS_i: This represents the Exploit Prediction Scoring System score for an individual CVE i. EPSS scores range from 0 to 1, indicating the probability of that specific CVE being exploited in the wild within the next 30 days.
  2. (1 - EPSS_i): If EPSS_i is the probability that CVE i will be exploited, then (1 - EPSS_i) is the probability that CVE i will NOT be exploited within the next 30 days.
  3. Π (1 - EPSS_i): The Greek letter Pi (Π) denotes the product (multiplication) of all the (1 - EPSS_i) values for every single CVE present on the asset. If we assume that the exploitation events for individual CVEs are statistically independent, then the product of their individual probabilities of not being exploited gives us the **cumulative probability that none of the CVEs on the asset will be exploited** in the next 30 days.
  4. 1 - Π (1 - EPSS_i): Finally, by subtracting this cumulative probability (that none will be exploited) from 1, we arrive at the **probability that at least one CVE on the asset will be exploited** within the next 30 days. This is the grouped EPSS score.

The assumption of independence of events is critical here. While in reality, some vulnerabilities might be chained or share common attack vectors, for the purposes of this statistical model, treating them as independent allows for this elegant and computationally efficient aggregation of probabilities. Jacobs acknowledges he is not a data scientist, but points to the statistical property about independence of events as the basis for the validity of this approach as outlined in the original EPSS user guide.

Jacobs demonstrates the practical implementation of this formula using Python and the Pandas library, highlighting its simplicity:

This snippet illustrates how, with a flattened CSV mapping assets to CVEs, and the daily EPSS scores, the calculation can be performed in just a few lines. The groupby('asset_id') operation is key, as it partitions the data by asset, allowing the lambda function to apply the grouped EPSS formula to all EPSS scores associated with that particular asset.

Beyond the initial calculation, Jacobs introduces the concept of Delta Grouped EPSS. This is a critical metric for guiding remediation efforts. It's calculated by:

Delta Grouped EPSS = Grouped EPSS (Asset_Before_Fix) - Grouped EPSS (Asset_After_Fix_Removing_CVE_X)

To calculate this, one would:

  1. Compute the current grouped EPSS for an asset.
  2. For each CVE on that asset, temporarily remove it from the list.
  3. Recalculate the grouped EPSS for the asset with that CVE removed.
  4. The difference between the original score and the new score indicates how much removing that specific CVE would reduce the asset's overall exploitation probability. This allows security teams to identify the "highest leverage" CVEs for remediation on a given asset, prioritizing those that will have the most significant impact on the asset's grouped EPSS score. This directly addresses the question of "which CVEs will move the grouped EPSS score needle the most across assets?"

Demo / Proof of Concept

▶ Watch: Statistical property and independence of events assumption (8:00)

While Stephen Jacobs' talk did not feature a live, interactive demonstration of his tooling, he effectively used sample data visualizations to illustrate the grouped EPSS concept and its practical application. These visuals served as a powerful proof of concept for the methodology.

The first visualization presented was a distribution graph of grouped EPSS scores across sample assets.

  • The x-axis represented the grouped EPSS score, ranging from 0 to 1.
  • The y-axis showed the number of assets falling into specific bins (e.g., 5% intervals) along the score range.

This graph, though based on sample data, immediately highlighted its utility. Jacobs noted that his sample data showed "peaks and valleys," with notable concentrations of assets around 65% and 90-95% grouped EPSS scores. He emphasized that the specific shape of this distribution would "vary by mileage" for each organization but that the presence of such peaks, especially those closer to 1, serves as a strong indicator for investigation. For instance, a spike of assets with grouped EPSS scores near 1 demands immediate attention: "Why are things so high?" This could be due to a single CVE with a very high EPSS score, or a multitude of CVEs with smaller scores. The visualization provides a clear starting point for deeper analysis.

The second key visualization was a sample overlay of data classification standards on top of the grouped EPSS distribution.

  • This visual demonstrated how an organization could successfully assign data classification labels (e.g., "sensitive," "confidential," "public") to their assets.
  • By coloring or segmenting the asset distribution based on these classifications, Jacobs illustrated the powerful "marriage" between the calculated likelihood of exploitation (grouped EPSS) and the potential impact (data classification).

This combined view directly addresses the fundamental definition of risk. It allows security teams to quickly identify assets that not only have a high probability of exploitation but also process highly sensitive data. For example, an asset with a grouped EPSS score of 0.95 and a "highly confidential" data classification immediately signals a severe risk. While Jacobs acknowledged that he doesn't delve into the quantitative aspects of impact, this qualitative overlay provides immense value for prioritization and communication.

Although these were illustrative examples rather than a live system, they clearly conveyed the potential for:

  • Identifying high-risk assets: Pinpointing assets with the highest grouped EPSS scores.
  • Contextualizing risk: Understanding why certain assets are risky by examining the underlying CVEs and their EPSS scores.
  • Prioritizing based on business value: Leveraging data classification to focus on assets that, if compromised, would have the greatest business impact.

Jacobs encouraged attendees to replicate this analysis with their own internal data, stressing that the insights gained would be unique to their environment and crucial for making better decisions.

Defensive Implications

▶ Watch: Practical Python code for calculating Grouped EPSS (8:50)

The grouped EPSS methodology offers profound implications for enhancing an organization's defensive posture, shifting from a reactive, volume-driven approach to a proactive, risk-informed strategy.

  1. Strategic Prioritization of Remediation: Instead of chasing individual CVEs based on their CVSS scores or raw EPSS, defenders can now prioritize entire assets or groups of assets that pose the highest cumulative risk of exploitation. Jacobs advises focusing on assets with grouped EPSS scores approaching 1, especially when combined with high business impact or sensitive data classification. This allows for a more efficient allocation of limited security resources, ensuring that efforts are directed where they will have the most significant impact on overall organizational risk. The question becomes, "Which assets are most likely to be exploited and cause the most damage?"
  2. Root Cause Analysis and Environmental Improvement: High grouped EPSS scores on certain assets should trigger deeper investigations. Defenders can ask: "Why are these assets continually accumulating high-likelihood vulnerabilities?" This can uncover systemic issues such as:
  • Outdated technology stacks
  • Ineffective patch management processes
  • Lack of clear asset ownership
  • Misconfigured security controls
  • Understanding these underlying causes enables long-term improvements in security posture rather than just continuous fire-fighting.
  1. Targeted Vulnerability Remediation for Maximum Impact: The delta grouped EPSS metric is a game-changer for remediation teams. It allows them to identify not just any CVE on a high-risk asset, but the specific CVEs whose remediation will lead to the greatest reduction in that asset's overall grouped EPSS score. This ensures that patching efforts are not only focused on the riskiest assets but also on the most impactful vulnerabilities within those assets, maximizing the "needle-moving" effect.
  2. Enhanced Communication with Leadership: The grouped EPSS score provides a clear, quantifiable metric that CISOs and security managers can use to communicate asset risk to non-technical stakeholders, such as the board or executive leadership. Instead of presenting a daunting list of thousands of CVEs, one can articulate: "This critical asset, which processes our most sensitive customer data, has a 95% probability of experiencing exploitation activity in the wild within the next 30 days." This type of statement, directly tied to business context and likelihood of exploitation, resonates far more effectively than abstract severity scores or raw vulnerability counts, allowing for better alignment with organizational priorities (e.g., data security).
  3. Continuous Monitoring and Measurement of Posture: By regularly recalculating grouped EPSS scores (e.g., daily), organizations gain a dynamic view of their asset risk posture. While external factors like new CVEs and shifting EPSS scores mean that the overall risk landscape will fluctuate, this continuous monitoring provides a "window into reality," allowing defenders to track trends, measure the effectiveness of their efforts, and adapt their strategies. Even if the overall grouped EPSS doesn't always decrease, understanding the fluctuations provides valuable intelligence for decision-making.
  4. Decision Support Mechanism: Ultimately, Jacobs frames grouped EPSS as a powerful decision support mechanism. It doesn't dictate actions but provides the necessary context and clarity to make smarter, more informed decisions about where to invest resources, which assets to protect most vigorously, and which underlying issues to address. It helps clear the "fog of war" in vulnerability management, enabling a more strategic and impactful defense.

It is crucial to remember Jacobs' emphatic caveat: this methodology does not substitute for good patch management. Rather, it is an advanced prioritization and intelligence tool designed to make existing patch management and remediation efforts more effective and risk-aligned.

Key Takeaways

  • Good patch management remains paramount: The grouped EPSS methodology is a decision support and prioritization tool, not a replacement for fundamental, diligent patch management practices.
  • Provides a clear lens into vulnerability risk posture: By combining the likelihood of exploitation (grouped EPSS) with asset-specific business context (e.g., data classification, ownership), organizations gain a holistic understanding of their true risk landscape.
  • Enables prioritization by riskiest asset/group: The approach shifts focus from overwhelming individual CVEs to identifying and addressing the assets or groups that pose the highest cumulative probability of exploitation, allowing for more strategic resource allocation.
  • Actions lead to smarter decisions, even if scores fluctuate: Due to the dynamic nature of new CVEs and EPSS score changes, remediation efforts might not always immediately or drastically reduce an asset's grouped EPSS score. However, applying this methodology consistently ensures that decisions are always smarter and more aligned with actual threat likelihood.
  • Decision support mechanism for targeted effort: Grouped EPSS acts as an intelligence layer, indicating precisely which assets or asset groups require additional, focused effort and investigation that might not have been apparent through traditional vulnerability metrics.

About the Speaker(s)

Stephen Jacobs is a Principal Security Engineer at Moderna Therapeutics, a company renowned for its pioneering work in developing the mRNA COVID-19 vaccine. In this role, he addresses complex security challenges within a large-scale manufacturing operation, highlighting his experience with critical infrastructure and high-stakes environments.

In addition to his corporate responsibilities, Jacobs is a co-chair of the EPSS Special Interest Group (SIG) alongside Jacobs, where he actively contributes to the community and development of the Exploit Prediction Scoring System. His professional background also includes tenure at Peloton and prior work as a contractor for the Centers for Medicare and Medicaid Services (CMS), where he gained significant experience managing security across disparate infrastructure and navigating stringent government requirements.

Jacobs candidly shared a personal insight into his demanding life, mentioning he is a father of three young children (ages 6, 4, and 2), which he humorously describes as "absolutely bonkers crazy," often seeking clarity and peace during professional events like conferences. This personal context underscores his dedication to finding practical, efficient solutions to complex problems, driven by a need to make sense of overwhelming data, both professionally and personally.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Jacobs brings a clean, practical methodology to VulnCon that does exactly what it says on the tin: takes a well-understood probability identity, applies it to EPSS aggregation at the asset level, and gives practitioners a usable prioritization lever. This is competent, honest practitioner work — not novel research, but not vendor fluff either. The math is straightforward, the implementation is genuinely simple, and the framing around delta-EPSS for remediation impact is the most useful conceptual addition. It will land well with the vulnerability management crowd at VulnCon, which is the right venue for it. Doesn't break new ground, probably could have been a thorough blog post, but Jacobs…

Heather Calloway (CISO) — SOLID

Stephen Jacobs presents a genuinely useful operationalization of EPSS — grouping vulnerability scores at the asset level to produce a cumulative exploitation probability. The math is sound, the implementation is accessible, and the delta EPSS concept for prioritizing remediation is a practical contribution. This is practitioner-grade work that earns its place at a vulnerability management conference. It doesn't reach the level of a must-see for CISOs and security leaders because it stops short of the governance and accountability dimensions that would make it boardroom-relevant, and the independence assumption embedded in the model goes underexamined for an audience that will need to…

→ Top-rated talks at CVE/FIRST VulnCon 2025

All talks from CVE/FIRST VulnCon 2025