Most tools start from a label and explain it. We start from what an attacker actually does and reverse-engineer the rating from there.
To get real value from the platform, your organization should define clear timeframes for both mitigation and remediation.
A good pattern is to introduce mitigation first. That creates space for operations to breathe while still reducing risk in a controlled way. The sweet spot is a tight mitigation target with a looser remediation target.
| Reassessed | Mitigation | Remediation |
|---|---|---|
| CRITICAL | ≤ 3 days | ≤ 90 days |
| HIGH | ≤ 30 days | ≤ 180 days |
| MEDIUM | — | ≤ 365 days |
| LOW | — | — |