Free course · Module 1 · Lesson 1 of 4

"Critical" isn't the same as urgent

About 11 minutes · fills in: Part 1, what we don't sort by

What you'll decide

That your business will stop deciding what to fix first by the label on the alert, and what you'll look at instead.

Most security alerts arrive with a label: Critical, High, Medium, Low. Often there's a number too, like 9.8 out of 10. The label is red, the number is big, and it feels like it's telling you what to do first.

It isn't. It's telling you something narrower, and once you see what, a lot of alerts get less frightening and a few get much more urgent.

Plain-English terms

Vulnerability. A flaw in software or a device that an attacker could use to get in or cause damage. People shorten it to "vuln". A report full of them is a list of possible ways in, not a list of break-ins.

CVE. The ID a flaw gets when it's made public: "CVE", the year, and a number. It lets your IT provider, your software vendor, and the government all talk about the same flaw.

CVSS. The scoring system behind the 0 to 10 number. 9.0 and up is labeled Critical, 7.0 to 8.9 High, 4.0 to 6.9 Medium, anything lower Low.

Patch. A fix from the vendor, usually delivered as an update.

What the score measures

A CVSS score answers one question: if someone used this flaw, how bad could it get? That's worth knowing. But it's worked out once, about the flaw itself, before anyone knows where it's installed.

So the score doesn't know any of this:

Is anyone using it?

Whether anyone is using this flaw to break into businesses. Most published flaws are never used in a real attack.

Can a stranger reach it?

Whether the thing with the flaw can be reached from the internet, or sits on your office network behind the router.

What would it hurt?

Whether that machine runs payroll or plays music in the break room.

A 9.8 on a printer that only people in your office can reach, with no known attacks, is a real flaw. It's also a Tuesday problem. A 7.2 on the box that lets your staff work from home, on a flaw criminals are using this week, is the kind of thing that turns into a closed business.

Why this matters more for a small business

A large company has people whose whole job is to read these reports. You have an IT provider who comes in on Thursdays, or you have yourself. Every hour spent on the wrong fix is an hour not spent on the right one.

And the lists are long. A routine scan of a 20-person office can come back with dozens or hundreds of items, many marked Critical. If the label sets the order, you'll spend months working through scary-sounding problems nobody is exploiting, and the dangerous one sits in the middle of the list with a smaller number.

Tens of thousands of new flaws are published every year. The U.S. government's cybersecurity agency, CISA, keeps a list of the ones it knows attackers have used. That list is a small fraction of the total. Lesson 2 shows you how to use it.

What to look at instead

You'll build the full rule over the next three lessons. It comes down to three questions, asked in this order:

  1. Is someone actually using this attack right now?
  2. Can a stranger on the internet reach the thing with the flaw?
  3. What would it hurt? Money, email, customer data, or the system you can't open without.

The severity score is still useful. It's what you use to break ties once those three are answered. It just doesn't get to go first.

Monday morning. Your IT provider emails three alerts and asks where to start. They can do one today and the rest later this week.

CRITICALAlert A

23 Windows updates pending on office PCs

The PCs are set to install updates automatically on Saturday night.

Being attacked not knownReachable from internet noScheduled installs Saturday night
CRITICAL9.8Alert B

Flaw in the office printer's settings page

The printer is only reachable from inside the office. The IT provider checked: no reports of anyone using it.

Being attacked noReachable from internet no
HIGH7.2Alert C

Flaw in the firewall's remote-access feature

That's the feature your staff use to connect from home, so it's reachable from the internet.

Being attacked yes, on CISA's listReachable from internet yes

Scenario

Three "critical" alerts on a Monday

Which do you tell them to start with?

Pick the one you would choose. It opens with the reasoning, then you can compare the rest.

AStart with B, then A, then C. Highest score first.

That's the order the labels suggest, and it's the trap. B has the biggest number, but nobody outside your office can reach the printer and nobody is known to be attacking this flaw. C has the smaller number, but it's reachable from anywhere and criminals are using it right now. Sorting by score puts the one real emergency last.

BStart with C, then A, then B.
Best answer

C is the only alert where someone is actively using the attack and a stranger can reach it. That's what makes it urgent, whatever the label says. A mostly handles itself on Saturday; the useful question is whether any PC has been failing to update. B goes on the schedule, because nobody outside can reach it and nobody is known to be using it.

CStart with A. It's 23 problems, not one.

Counting problems feels productive, but the number of items doesn't say how dangerous any one of them is. Those updates are already scheduled. The one alert that's reachable from the internet and actively attacked is C.

DAsk them to do all three today.

If they can, fine. But you're writing rules for the day they can't, and that day comes often. When your IT provider asks where to start, the answer should be quick and the same every time: C.

Two questions for your IT provider

You don't need to understand firewalls or read a CVE entry to make this call. Ask your IT provider two plain questions about every urgent-sounding alert: Is anyone using this in attacks? and Can someone on the internet reach it? A good IT provider can answer both. If they can't, that tells you something too.

Remember

Build your file

Part 1: What we don't sort by

If you haven't yet, download your Fix-First Rules file and save it somewhere private, like your own OneDrive or Google Drive folder. You'll add one part per lesson; by the end of Lesson 4 it's finished.

Fill in the details at the top (business, your name, today's date). Then, in Part 1, type your business's rule in your own words over the grey example. It should say that the label or score on an alert does not decide the order, and name what does.

Example: "We don't fix things in order of the Critical/High label or the score. We fix what's being attacked and reachable from the internet first, then whatever touches our money, email, and customer records. The score only breaks ties."