Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →CVSS, the Common Vulnerability Scoring System, is an open framework for rating the severity of a security vulnerability on a scale from 0.0 to 10.0. The score is derived from factors like how a flaw is exploited and the impact on confidentiality, integrity, and availability. Higher scores indicate more severe vulnerabilities.
CVSS bands map to labels: 0.1 to 3.9 is low, 4.0 to 6.9 medium, 7.0 to 8.9 high, and 9.0 to 10.0 critical. Teams use these scores to decide what to patch first.
The base score reflects the flaw in isolation; it is not a complete picture of your risk. A "critical" CVE on a system with no network exposure may matter less than a "medium" on an internet-facing one, which is why context still drives prioritization.
traztech delivers vulnerability triage and prioritization for startups and growth-stage companies, led by a published security researcher.
Book a callFor a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.
CVSS scores drive remediation SLAs in most vulnerability management policies, which is where they meet compliance: an auditor will compare your stated timeframe against what actually happened.
The trap is treating the base score as the risk. A 9.8 on a component you do not expose is less urgent than a 6.5 on your authentication path, and a policy that cannot express that produces either panic or ignored alerts.
No. CVSS base scores describe the vulnerability, not your environment. Exploitability in your specific configuration and exposure should drive the priority.
Whatever you can genuinely meet. Auditors compare your policy against your evidence, so a realistic thirty-day critical SLA you hit beats a seven-day one you miss.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
Before you go
Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.