<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Stephen Shaffer</title>
  <link href="https://www.stephenshaffer.io/feed.xml" rel="self"/>
  <link href="https://www.stephenshaffer.io/"/>
  <id>https://www.stephenshaffer.io/</id>
  <author><name>Stephen Shaffer</name></author>
  <entry>
    <title>Introducing the Local Exploit Hazard Model</title>
    <link href="https://www.stephenshaffer.io/blog/introducing-the-local-exploit-hazard-model"/>
    <id>https://www.stephenshaffer.io/blog/introducing-the-local-exploit-hazard-model</id>
    <summary>An approach to synthesizing global and local exploit signals to quantify vulnerability remediation efficiency.</summary>
  </entry>
  <entry>
    <title>Hacking Reality: Why Data Science Is the Blue Team&amp;rsquo;s Ultimate Exploit</title>
    <link href="https://www.stephenshaffer.io/blog/hacking-reality-why-data-science-is-the-blue-teams-ultimate-exploit"/>
    <id>https://www.stephenshaffer.io/blog/hacking-reality-why-data-science-is-the-blue-teams-ultimate-exploit</id>
    <summary>Security ships risk models and almost never checks them against what happened. The gap worth closing is observation infrastructure, not scoring.</summary>
  </entry>
  <entry>
    <title>Vulnerability Information Cones</title>
    <link href="https://www.stephenshaffer.io/blog/vulnerability-information-cones"/>
    <id>https://www.stephenshaffer.io/blog/vulnerability-information-cones</id>
    <summary>Light cones borrowed from physics as a mental model for deciding under imperfect information.</summary>
  </entry>
  <entry>
    <title>Updating Exploit Likelihood with Control Effectiveness</title>
    <link href="https://www.stephenshaffer.io/blog/quantifying-swiss-cheese-the-bayesian-way"/>
    <id>https://www.stephenshaffer.io/blog/quantifying-swiss-cheese-the-bayesian-way</id>
    <summary>Putting numbers on the Swiss-cheese model: control effectiveness as a distribution, updated with evidence, then folded back into exploit likelihood.</summary>
  </entry>
  <entry>
    <title>Modeling Asset Risk Using EPSS</title>
    <link href="https://www.stephenshaffer.io/blog/modeling-asset-risk-using-epss"/>
    <id>https://www.stephenshaffer.io/blog/modeling-asset-risk-using-epss</id>
    <summary>Rolling per-CVE EPSS probabilities up to an asset-level view of exploitation risk.</summary>
  </entry>
  <entry>
    <title>Determining EPSS Score Thresholds for Prioritization</title>
    <link href="https://www.stephenshaffer.io/blog/determining-epss-score-thresholds-for-prioritization"/>
    <id>https://www.stephenshaffer.io/blog/determining-epss-score-thresholds-for-prioritization</id>
    <summary>Where to draw the line, and what it costs you when you draw it in the wrong place.</summary>
  </entry>
  <entry>
    <title>Flipping the Vulnerability Management Model: CVSS &amp;rarr; SSVC</title>
    <link href="https://www.stephenshaffer.io/blog/flipping-the-vulnerability-management-model-cvss-ssvc"/>
    <id>https://www.stephenshaffer.io/blog/flipping-the-vulnerability-management-model-cvss-ssvc</id>
    <summary>My take on leveraging SSVC over CVSS for vulnerability action prioritization.</summary>
  </entry>
  <entry>
    <title>Sabermetrics and Cyber Risk Quantification</title>
    <link href="https://www.stephenshaffer.io/blog/sabermetrics-and-cyber-risk-quantification"/>
    <id>https://www.stephenshaffer.io/blog/sabermetrics-and-cyber-risk-quantification</id>
    <summary>What sabermetrics did for the game, and where it points for cyber risk.</summary>
  </entry>
  <entry>
    <title>Learning How to Quantify Cyber Risk Using Bayes</title>
    <link href="https://www.stephenshaffer.io/blog/learning-how-to-quantify-risk-using-bayes"/>
    <id>https://www.stephenshaffer.io/blog/learning-how-to-quantify-risk-using-bayes</id>
    <summary>A walk through Bayesian thinking for cyber risk: priors, evidence, and updating as new data arrives.</summary>
  </entry>
</feed>
