stephenshaffer.io

Blog

Blog

Essays on exploit prediction and decision models, mostly about making risk measurable.

Jul 2026 Introducing the Local Exploit Hazard Model An approach to synthesizing global and local exploit signals to quantify vulnerability remediation efficiency. Read → Feb 2026 Hacking Reality: Why Data Science Is the Blue Team’s Ultimate Exploit Security ships risk models and almost never checks them against what happened. The gap worth closing is observation infrastructure, not scoring. Read → Apr 2025 Vulnerability Information Cones Light cones borrowed from physics as a mental model for deciding under imperfect information. Read → Oct 2025 Updating Exploit Likelihood with Control Effectiveness Putting numbers on the Swiss-cheese model: control effectiveness as a distribution, updated with evidence, then folded back into exploit likelihood. Quantifying Swiss Cheese, the Bayesian Way Read → Aug 2024 Modeling Asset Risk Using EPSS Rolling per-CVE EPSS probabilities up to an asset-level view of exploitation risk. Read → Nov 2023 Determining EPSS Score Thresholds for Prioritization Where to draw the line, and what it costs you when you draw it in the wrong place. Read → Jun 2023 Flipping the Vulnerability Management Model: CVSS → SSVC My take on leveraging SSVC over CVSS for vulnerability action prioritization. Read → Jun 2023 Sabermetrics and Cyber Risk Quantification What sabermetrics did for the game, and where it points for cyber risk. Read → May 2023 Learning How to Quantify Cyber Risk Using Bayes A walk through Bayesian thinking for cyber risk: priors, evidence, and updating as new data arrives. Read →