Business initiative

Risk-Based Vulnerability Management (RBVM)

RBVM is supposed to tell you which of the 130 new CVEs a day actually matter, and legacy tools answer by re-ranking CVSS with threat intel. Zafran answers with evidence from your environment: runtime presence, reachability, exploitation activity, asset criticality and the controls you already own.

Definition

What RBVM means

Risk-Based Vulnerability Management (RBVM) is the practice of prioritizing vulnerabilities by the real risk they pose to the business rather than by CVSS score alone. A mature RBVM program combines threat intelligence, asset context and exploitability evidence so teams fix the small set of findings attackers can actually use, and can show why the rest can wait.

What buyers expect from an RBVM program

  • Prioritization beyond CVSS: exploit activity, asset criticality and business context in one score
  • Coverage across every scanner and asset class without replacing existing tools
  • Measurable outcomes: fewer tickets to IT, shorter MTTR on the findings that matter, defensible reporting

Mapping

How Zafran maps to your RBVM program

Replacing Kenna or another legacy RBVM platform? This is the same mapping we use in those migrations: your requirements column, Zafran's capability, and where it sits in the lifecycle.

Program requirementZafran capabilityLifecycle stage
Ingest findings from all existing scannersAgentless connectors normalize and de-duplicate infrastructure, cloud, AppSec and container findings on one exposure graph01Continuous Discovery & Detection
Score risk beyond CVSSExploitability scoring built from runtime presence, reachability, exploitation intelligence, asset criticality and control coverage02Assess & Validate
Reduce the exploitable backlog fastMitigation through controls you already own (EDR, WAF, firewall, cloud policy) while patches are scheduled03Risk Mitigation
Route fixes to owners with SLAsRemOps groups findings by root cause, assigns owners and tracks SLAs in ServiceNow or Jira04Remediation Workflows
Report risk reduction to leadershipBoard-ready exposure reporting with validation evidence and trend analytics per business unit05Reporting & Analytics

Capabilities

RBVM capabilities, in the product

Stylized dashboard callouts; each tile becomes a short micro-animation in production.

Cap 1

Exploitability score, not CVSS

Every finding carries a live score built from what is running, what is reachable, what is being exploited and what a control already blocks.

Cap 2

Noise funnel

All findings, runtime-present, reachable, exploited in the wild, unmitigated. Watch the backlog collapse.

Cap 3

One prioritized queue

A single de-duplicated table across scanners with owner, SLA and mitigation status.

Cap 4

Risk trend by business unit

Exploitable exposure over time, sliced the way your board slices the business.

RFP checklist

Evaluating RBVM vendors? Start here.

Download

RBVM evaluation checklist

Requirement language, scoring criteria and proof-of-value tests you can paste into an RFP.

  • Does the risk score account for runtime presence and network reachability, or only CVSS plus threat intel?
  • Can the platform show which existing control already mitigates a finding?
  • Does it ingest every scanner we run today without deploying new agents?
  • How are findings grouped, routed and tracked to closure across Security and IT?
  • What evidence does reporting provide that risk was reduced, not just that tickets were closed?
Download checklist

Outcomes

What RBVM teams see with Zafran

99%
of critical vulnerabilities not exploitable in the environment
-90%
fewer tickets sent to IT after validation
Minutes
from disclosure to validated exploitability

Illustrative figures for the wireframe; replace with validated customer outcomes.

“Zafran is tackling vulnerabilities from a hacker's perspective, adding a true layer of risk mitigation through compensating controls.”

Ricardo Lafosse
CISO, Kraft Heinz

“Zafran lets us evaluate the effectiveness and ROI of our security stack against what is actually exploitable.”

Dave Estlick
CISO, Chipotle

FAQ

Frequently asked questions

What is RBVM?

Risk-Based Vulnerability Management prioritizes vulnerabilities by the real risk they pose, using threat intelligence, asset context and exploitability evidence instead of CVSS alone.

RBVM vs CTEM: what is the difference?

RBVM is the prioritization discipline inside vulnerability management. CTEM is the broader, continuous lifecycle of discovering, validating, mitigating, remediating and reporting on exposure. Zafran delivers RBVM as one stage of that full lifecycle.

Does Zafran replace my scanner?

No. Zafran ingests findings from the scanners you already run and adds the runtime, reachability, exploitation and control context they lack.

Can Zafran replace a legacy RBVM tool such as Kenna?

Yes. Customers migrate from legacy RBVM platforms to Zafran to get validated exploitability and mitigation through existing controls, rather than a re-ranked list of the same findings.

How does Zafran score risk?

Each finding is scored on runtime presence, network reachability, active exploitation, asset criticality and whether an existing security control already blocks the attack path.

Bring Zafran into your RBVM evaluation

See how the platform maps to your requirements, on your data, in a 30-minute walkthrough.

WireframeSitemap