CODE OVER CHAOS / FIELD LAB 01

A vulnerability is a dot.
Risk is the pattern.

A transparent, defensive worksheet for deciding what deserves attention first—without confusing a severity score for the whole truth.

DEFENSIVE DECISION LAB

Five small signals. One accountable decision.

Severity describes a vulnerability. Risk emerges from repetition: exposure, identity, operational consequence, and controls compound around it.

METHOD & LIMITS

Evidence, inference, opinion—kept in separate rooms.

Evidence

Active exploitation, reachability, privilege, business impact, and verified controls are observable inputs.

Inference

The score combines those inputs to create a consistent conversation starter. It is not a probability model.

Editorial view

Small repeated weaknesses can scale into systemic failure. Search for the copied condition, not only the first broken instance.

PRIMARY-SOURCE LEDGER

Show the receipts.

NVD Vulnerability Metrics

NIST explicitly distinguishes CVSS severity from risk, which depends on context beyond a base score.