Blog
Blog
Essays on exploit prediction and decision models, mostly about making risk measurable.
Jul 2026
Introducing the Local Exploit Hazard Model
An approach to synthesizing global and local exploit signals to quantify vulnerability remediation efficiency.
Read →
Feb 2026
Hacking Reality: Why Data Science Is the Blue Team’s Ultimate Exploit
Security ships risk models and almost never checks them against what happened. The gap worth closing is observation infrastructure, not scoring.
Read →
Apr 2025
Vulnerability Information Cones
Light cones borrowed from physics as a mental model for deciding under imperfect information.
Read →
Oct 2025
Updating Exploit Likelihood with Control Effectiveness
Putting numbers on the Swiss-cheese model: control effectiveness as a distribution, updated with evidence, then folded back into exploit likelihood.
Read →
Aug 2024
Modeling Asset Risk Using EPSS
Rolling per-CVE EPSS probabilities up to an asset-level view of exploitation risk.
Read →
Nov 2023
Determining EPSS Score Thresholds for Prioritization
Where to draw the line, and what it costs you when you draw it in the wrong place.
Read →
Jun 2023
Flipping the Vulnerability Management Model: CVSS → SSVC
My take on leveraging SSVC over CVSS for vulnerability action prioritization.
Read →
Jun 2023
Sabermetrics and Cyber Risk Quantification
What sabermetrics did for the game, and where it points for cyber risk.
Read →
May 2023
Learning How to Quantify Cyber Risk Using Bayes
A walk through Bayesian thinking for cyber risk: priors, evidence, and updating as new data arrives.
Read →