Vulnerability economics

The four-line economic frame for every vulnerability: cost to introduce, cost to discover, cost to fix, and the value of exploitation — and why the math matters.

Vulnerability economics
  • Every vulnerability costs something to put there.
  • Every vulnerability costs something to discover.
  • Every vulnerability costs something to fix.
  • The exploitation of every vulnerability has a value associated with it.