Home / Knowledge hub / Severity
Knowledge hub
Severity
How bad a finding is, from critical down to informational.
What it means
Severity describes how bad a finding would be if somebody used it, usually on a scale running from critical down to informational. It is a judgement about impact, not a measure of how likely the finding is to be real.
Teams muddle those two constantly, which is how a list ends up sorted by a number that means several things at once.
Why it matters
Severity orders the fixes, so it decides where engineering time goes. Rate everything high and the ranking stops meaning anything. Rate defensively and something that matters waits behind something that does not.
It also needs context you have and a tool does not. The same flaw is critical on the payments path and minor on an internal report nobody outside the office can reach. Certainty belongs in the conversation too. A demonstrated flaw at medium deserves attention before a theoretical one at high, and one number cannot carry both ideas. Severity also leaves the building. It travels into customer reports, so a scale nobody believes internally will not survive outside either.
How it shows up
Watch for a scale with no room at the bottom. If a hardening suggestion and a data exposure share a label, the label does no work and the queue becomes an argument instead of a plan.
Agree what each tier means in your business before the first report lands. Writing down what critical actually requires saves having that argument every month. Cyberlop uses six tiers, critical, high, medium, low, informational and best practice, and it tracks confidence separately from impact. How we rank findings.
Questions people ask
Severity, answered
What is the difference between severity and priority?
Severity describes how bad the outcome would be. Priority describes how soon you will act, which also takes in effort, release timing and who is asking.
A finding can be high severity and low priority. Saying that out loud avoids a lot of arguing.
Why do two tools score the same CVE differently?
Because a base score still assumes something about how the software runs. Different assumptions about exposure and attack complexity move the number a long way.
Taking the highest score you can find is not caution. It just moves your queue somewhere less useful.
Can we downgrade a finding's severity?
Yes, when your context justifies it and you write the reason down. Unreachable third-party code and non-production environments are the usual honest cases.
Downgrading without a recorded reason is how the same argument comes back next quarter.
Is severity the same as a CVSS score?
No. CVSS is one way of producing a severity, and it targets published vulnerabilities in software that many organisations share.
A finding in your own application usually needs your judgement about what it would actually reach.
Everything arrives marked critical. Where do we start?
Separate impact from certainty. A demonstrated medium is worth more of your morning than a theoretical high.
Cyberlop uses six tiers, critical down to best practice, and tracks confidence apart from impact for exactly this reason.
Sources
Where this comes from
Related
Terms that sit next to this one
CVSS
A scoring system that turns a vulnerability into a number out of ten.
Risk acceptance
Deciding, on the record, to live with a known issue rather than fix it.
False positive
A reported issue that turns out not to be real.
Remediation
The actual work of fixing a finding: the change, the review, the release.
Vulnerability
A weakness that somebody could use to cause harm.
Is your queue sorted by anything real?
Six tiers, critical down to best practice, with confidence tracked separately from impact, so you can read the list in order. Ask how Cyberlop ranks what it finds for you.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.