Apr 2025
Vulnerability Information Cones
Applying Light Cones as a Mental Model for Navigating Uncertainty in Security

Inspiration
I spent the last week bouncing between my two favorite security conferences — FIRST’s VulnCon in Raleigh (where I spoke) and BSidesCharm in Baltimore — and I was inspired to articulate my mental model of vulnerabilities, risk, and the decisions we make with imperfect information.
In order to do that, I need to be blunt. I’m kind of an astrophysics nerd in my spare time. So if any of this goes way over your head, I apologize in advance. It took me time to understand the concepts in the theory of relativity and on which my mental model is based.
Light Cones
Hearing folks talk about the data quality, what pieces of information mean to varying operators, and how we forecast risk made me think of a favorite physics concept of mine: light cones.

Light cones are a way physicists visualize what information or events can affect you (from the past) and what you can influence (into the future).
In the theory of relativity, light cones are the representation of paths of light emanating from an event in the past towards an observer in the present, and away from an observer into the future.
In cybersecurity (and really all aspects of life), we also deal with “what we know” versus “what might happen” versus “what we can’t see yet.” In other words, we have our own past, future, and unknown cones of information that shape our decisions.
Bear with me here.
Let’s set the stage with a few guiding truths, then explore how light cones can shed light on vulnerability management.
Axioms
- Imperfect Information is the Norm: We never have a 100% complete picture. We’re always making decisions with incomplete data — some vulnerabilities are well-documented, others lurk undiscovered. Uncertainty is a given.
- Threats Evolve Over Time: The risk landscape is dynamic. New vulnerabilities emerge every day, and attackers constantly devise new exploits. Our decisions are time-sensitive and must adapt as situations change.
- Past Data Is Prologue (Not Gospel): We rely on historical data like vulnerability databases and incident reports to guide us. Past events (breaches, exploits) inform our present priorities, but they don’t perfectly predict the future. History rhymes, it doesn’t repeat exactly.
- Prediction Reduces Uncertainty: We now have tools to forecast vulnerability arrival rates and which vulnerabilities might be exploited next. These probabilistic models aren’t crystal balls, but they help us peer a bit into the future and prioritize proactively.
- Unknown Unknowns Always Exist: No matter how much data we gather, there will always be blind spots — vulnerabilities no one knows about yet and attack scenarios we haven’t imagined. Complete certainty is impossible, so we must plan and act despite the unknowns.
We also know that we are not the only decision maker or observer in the environment, as others will have access to different data sets of varying magnitude, with varying degrees of uncertainty.
Vulnerability Information Cones
Let’s take the light cone concept, substitute the word information for light (which in astrophysics these are somewhat the same thing) and apply this model to our decision-making process in vulnerability management.
Below is a 2-dimensional slice of the same diagram above (which is a 3-dimensional slice of a 4-dimensional reality). I’ve added vulnerability information labels to visualize where they fall.

I’ll cover the Decision Operator, Past Information Cone, Future Information Cone, and Null Information Cones. Each of these can be mapped to an analogy of a driver behind the wheel of a car. Below is a diagram that roughly captures the analogy.

Decision Operator (Driver)
We sit in the “Decision Operator” seat, modeling what information means to us (either intuitively or via machine learning) and how to use it to make decisions. We are only aware of what we have access to, and other operators will have access to different sets of information across the hypersurface of the present.
Hypersurface here is just a fancy word for “everyone’s perspective.” It’s our 3-dimensional reality shown in 1-dimension on the Information Cones diagram.
Past Information Cone (Rearview Mirror)
In the theory of relativity, the past light cone of an event contains all the information and events in the past that could possibly affect that event (nothing outside it can reach you). In our context, think of the past information cone as all the known vulnerability data and security knowledge that’s available to us up to now.
It’s like looking through your rearview mirror at the road you’ve already traveled — not to drive backwards, but to understand where you’re coming from and what hazards you’ve already passed.
Our Past Information Cone is made up of traditional vulnerability data. CVEs, non-CVEs, CVSS, Threat Intelligence, KEV lists, etc. This information may be timely, but we will technically always be looking at it as information from the past. We can use it to inform decisions now and in the future.
The Past Information Cone is our starting point for decision-making. It’s analogous to an astronomer observing light from distant stars — it tells us about the past state of the system. Inside this cone, we have causal influence: prior vulnerability disclosures and attacks directly inform what we do now. For example, if last month’s ransomware campaign exploited a specific VPN flaw, that known fact should influence our priorities. The past cone is rich with lessons learned that can shape current decision-making.
Future Information Cone (Headlights)
If the past cone is about what’s behind us, the future light cone in relativity represents all the events that can be affected by what happens now — essentially, the realm of possibility and influence ahead of us.
Our Future Information Cone consists of any forward-looking metric or system that helps us decide where to focus before a risk materializes. In the diagram, I list EPSS and Vuln4Cast, both of which are probabilistic models of the future, with the former predicting exploitation and the latter predicting vulnerability arrival rates. They both extend our vision beyond the here-and-now.
Of course, predictions will never be 100% accurate. Just as headlights might not reveal a sudden hazard in time, our forecasting tools have uncertainty. We might get false positives (worrying about exploits that never come) or false negatives (missing the one that does). But even an imperfect headlight is better than none when navigating a dark, curvy road. The key is to use these probabilistic insights to complement the past data — together, they give us a rich feedback loop to inform future decisions.
The Null Information Cones (Blindspots)
In relativity, anything outside your combined past and future light cones is essentially disconnected from you — no information from those events can reach you in time, and you cannot influence them. These are sometimes called “elsewhere” or a null region.
I’ll borrow that concept for the third region: the Null Information Cones. This represents the vulnerabilities and threats that are currently outside our knowledge and predictive reach. They’re the things that, at this moment, we don’t even know we don’t know.
In our Null Information Cones, we have unknown vulnerability instances and unknown exploitation events. We shouldn’t doubt their existence, but if we do not have access to this information, we cannot possibly base our decisions off them. Sure, we may be able to infer what is there through whispers or their potential effect on information within our other information cones.
How To Use This Perspective
You’ve just been on a small tour of how I think about decision-making as it applies to vulnerability management (and really in general). With this perspective, I leave you with some takeaways that have helped me navigate cybersecurity and life.
- Don’t be paralyzed by imperfection: We will never have perfect data on vulnerabilities and exploits — but we have enough data to make informed decisions. Vulnerability lists and threat intel will not catch everything, and forecasts won’t always be right, but using them in combination is far better than flying blind. Imperfect information, used wisely, beats no information.
- Reduce uncertainty by continuously expanding your “information light cone”: Invest in processes that enlarge what you know and can predict. That means enriching your past cone (e.g. participate in information-sharing communities to learn about exploits sooner; keep asset inventory up to date so you know what’s affected by known vulnerabilities). It also means pushing out your future cone — adopt tools like EPSS, engage in risk modeling exercises, watch emerging trends — so you can foresee more of what’s coming.
- Stay agile and ready for the unexpected: Even with all the data and predictions, never assume you’ve got it all covered. Maintain a strong incident response capability and general cyber hygiene that can handle the curveballs. If a new zero-day hits tomorrow (null cone becomes reality), having good backup plans, network segmentation, and a practiced IR team means you can contain the damage. In other words, keep some defensive driving skills in your toolbox for those long-tail events.
This perspective wouldn’t have been possible without me embracing interests that I thought were out of reach.
Follow your passions.
The views presented in this blog are entirely my own and do not represent the views of any organization or other affiliation.