Evidence-Based Vulnerability Triage
I stopped asking severity to do all the work and added exploitation evidence, exposure, and authoritative catalogues.
Prioritisation
I do not want a severity score to decide priority by itself. It does not answer whether exploitation is likely or whether a specific environment is exposed, so ThreatWatch began combining severity with probability signals, authoritative exploitation catalogues, and current reporting.
This supports clearer tiers: findings that require immediate verification, developments worth monitoring, and background risk that should not displace more urgent work.
Data quality
External datasets can change coverage or enrichment practices without warning. ThreatWatch therefore needs multiple sources where appropriate, visible provenance, and graceful handling when one provider is incomplete.
The same evidence should flow into RedBlue without losing its source or age. A score is useful only when the analyst can understand the inputs behind it.