Free course · Module 1 · Lesson 2 of 4
Exploited and exposed comes first
What you'll decide
The test your business uses to spot a real emergency, and what happens the moment something passes it.
Lesson 1 left you with three questions. This lesson turns the first two into a test you can run on any alert in under a minute. Anything that passes goes to the front of the line with a 24-hour deadline. Everything else waits its turn.
Plain-English terms
Exploited. Someone is using this flaw to attack real businesses. A flaw that could be used in theory doesn't count on its own.
CISA KEV list. The Known Exploited Vulnerabilities catalog, kept by the U.S. Cybersecurity and Infrastructure Security Agency. It lists flaws the government knows have been used in real attacks. It's free, public, and searchable.
EPSS. A score from 0 to 1 that estimates how likely a flaw is to be attacked in the next 30 days. Your IT provider may quote it. 0.9 or higher counts as exploited for this test.
Internet-facing. A stranger anywhere in the world can connect to it directly, without being in your building or on your Wi-Fi.
The two questions
Question 1: Is someone actually using this attack right now? Count it as yes if any of these is true:
- It's on the CISA KEV list.
- The vendor's own warning says it's being actively exploited.
- Your IT provider or website host tells you it's being used in attacks.
- It has an EPSS score of 0.9 or higher.
Question 2: Can a stranger on the internet reach the thing with the flaw? Things that usually can:
- your website, and any online store or booking system you run yourself
- the remote-access feature that lets staff work from home
- your router or firewall, especially its settings page
- camera systems you can view from your phone
- anything your IT provider set up to be reached from outside
Things that usually can't: office PCs, printers, and a server in the back room, as long as they sit behind the router and nobody opened a door to them.
Yes to both means drop everything. That's the gate. It gets a 24-hour deadline, and your IT provider shouldn't need to wait for a meeting to start. Everything else goes into one of three other boxes.
The four boxes
Every problem lands in exactly one of these. Flip the two switches to see where.
Try it: answer both questions and the box lights up.
Box 1 Fire
Fix within 24 hours
Drop everything. Your IT provider starts without waiting for a meeting.
Box 2 Next
72 hours or 30 days
Being used in attacks, but a stranger can't reach it directly. How soon depends on what it touches (Lesson 3).
Box 3 Watch
Normal schedule
Fix it on the normal schedule, sooner if it touches something important. Ask to be told if it joins the KEV list, because then it's Box 1.
Box 4 Schedule
Routine updates
Automatic updates handle most of this without anyone deciding anything.
The boxes settle two cases that the severity label gets wrong.
An exploited flaw inside your network isn't automatically an emergency. It still matters, and Box 2 usually outranks Box 3. But a stranger can't reach it directly, so it's ranked by what it touches, not rushed ahead of everything.
A scary score on something nobody can reach and nobody is attacking is routine work. It's a real flaw that gets fixed. It doesn't get to jump ahead of a real emergency.
Two special cases
Settings count too. A router still on its factory password, or a camera system with the default login that anyone can reach from outside, fails both questions. Automated tools try default passwords on everything connected to the internet, all day. Treat those as Box 1.
Some problems aren't yours to fix. A flaw in Microsoft 365, Google Workspace, QuickBooks Online, or Square's own systems gets fixed by that vendor on their servers. It doesn't go in your boxes. Your part of those services is the settings: two-step login on every account, as few administrators as possible, and knowing what's shared outside the company. Software installed on your computers, like QuickBooks Desktop, web browsers, or the Office apps, is still yours to keep updated.
Scenario
Sort six real problems
This is the kind of mixed list a small business gets from an IT provider, a website host, and a camera installer. Tap the box you'd put each one in. You'll see the answer and the reasoning straight away.
1Your website host emails: a contact-form plugin on your site has a flaw that attackers are actively using.
Show the answer
Box 1, Fire. Your website is reachable by anyone, and the host says the flaw is being used. Update or switch off that plugin today. Ask the host to confirm when it's done.
2The office printer has a flaw scored 9.8. Nobody is known to be using it. The printer is only on the office network.
Show the answer
Box 4, Schedule. Highest score on the list, lowest urgency. Nobody outside can reach it and nobody is known to be attacking it. It goes in the next round of routine updates.
3The old laptop in the back office still runs Windows 10, which stopped getting free security updates in October 2025. Your IT provider says one of its unfixed flaws is being used in attacks. It isn't reachable from the internet. Your bookkeeper uses it for payroll.
Show the answer
Box 2, Next, near the top. Exploited, but a stranger can't connect to it directly. What it touches is what moves it up: payroll and the bank. Because it can't be patched anymore, the real fix is replacing it or moving payroll off it. Lesson 4 covers what to do while you arrange that.
4Your router's settings page can be reached from the internet, and it still uses the password printed on the sticker.
Show the answer
Box 1, Fire. This is the settings case. Automated tools try factory passwords on every router they can reach, constantly. Change the password today, and ask your IT provider to switch off outside access to the settings page unless someone truly needs it.
5Microsoft announces a flaw in Exchange Online, the email service behind Microsoft 365, and says it has already been fixed.
Show the answer
Not in your boxes. That's Microsoft's server, and Microsoft fixed it. Nothing to schedule. Your part of Microsoft 365 is the settings: two-step login on every account and as few admins as possible.
6The camera system you watch from your phone has a flaw scored 7.5. Your IT provider checked: it's not on the KEV list and there are no reports of attacks.
Show the answer
Box 3, Watch. A stranger can reach it, but nobody is known to be using this flaw. Fix it on the normal schedule. Camera systems are a popular target, so ask your IT provider to tell you if this flaw ever shows up on the KEV list. If it does, it becomes Box 1 that day.
0 of 6 sorted
What the 24 hours asks of you
A 24-hour deadline only works if the person who has to act is allowed to act. If your IT provider has to wait for your approval, or for their next scheduled visit, the clock runs out before anyone touches it.
So the gate comes with one decision you make now, calmly, instead of during an emergency: your IT provider may make an emergency fix for anything in Box 1 without waiting for you. They tell you right after. That might mean a short outage, or switching a feature off until a fix is ready. Agree to that now.
Remember
- Two questions find the emergencies: is someone using this attack, and can a stranger on the internet reach it?
- Yes to both is Box 1, fixed within 24 hours. Everything else waits its turn in Boxes 2 to 4.
- Settings count too, and flaws on a vendor's own servers aren't yours to fix.
Build your file
Part 2: The gate
Open your Fix-First Rules file. The two questions are already in Part 2. Fill in the three rows under them:
- Who decides something passed the gate. Usually your IT provider, with you told right away.
- Who gets called, and how. A phone call, not an email.
- Emergency-fix permission. Write yes once you've agreed with your IT provider that they can act on Box 1 without waiting, and the date you agreed. If you haven't had that conversation yet, write no, and have it this week.
Example: "Decided by: Jordan at our IT provider. Calls: me (owner), cell, any hour. Emergency fixes pre-approved: yes, agreed March 3."
Where this goes next
Step 3 of the Security Starter, turning on automatic updates, clears most of Box 4 without anyone deciding anything, so your attention goes to Boxes 1 and 2. In the VM Program Kit, this test is Stage 1 of the Prioritization Model, the threat gate.