Custom Report
The EPSS-based reporting that you shared has been added to the Custom Reports section under Vulnerability Management. This report provides executive-level visibility into vulnerability severity, EPSS distribution, and vulnerability age metrics to help prioritise remediation efforts more effectively.
Per-Severity Overview
What it answers: “At each severity level, how big is the problem and are we responding fast enough?”
For Critical, High, Medium, and Low, this shows:
Open vulnerabilities — How many findings are still unresolved at that severity.
Median EPSS — Typical exploit likelihood in the next 30 days (0–1 scale). Helps separate “theoretical” risk from “likely to be attacked soon.”
Avg. time open — How long findings have been open on average, with a Within target / Above target indicator against CISA-aligned remediation timelines.
Business value: Executive snapshot for prioritization and SLA discussions — e.g. “We have few critical items, but they’ve been open too long” or “High volume at medium severity with low exploit likelihood.”
EPSS Distribution by Severity
What it answers: “Within each severity band, which issues are most likely to be exploited in the near term?”
Open vulnerabilities are grouped into exploit-likelihood bands (e.g. low through high EPSS). Each severity level gets its own breakdown so leadership can see whether, for example, “high” severity items are mostly low-likelihood noise or concentrated in dangerous bands.
Business value: Supports risk-based patching — focus effort on findings that are both severe and likely to be exploited, not just severity alone. Reduces wasted effort on large backlogs of low-likelihood items.
Age Distribution by Severity
What it answers: “How long have these vulnerabilities been sitting in our environment?”
For each severity, shows how open findings are distributed across age windows:
0–30 days — Recently discovered
31–60 days — Aging
61–90 days — Stale
(Findings older than 90 days still count in overview totals but are not shown in these bars.)
Business value: Highlights remediation velocity and backlog health — whether the organization is closing issues promptly or allowing risk to accumulate. Useful for QBRs, audit readiness, and proving continuous improvement.
We believe this report will be valuable for organizations of all sizes and especially beneficial for MSPs looking to enhance risk-based vulnerability management for their clients.