Skip to main content
With a list of findings in hand, the most common mistake security teams make is starting with the easiest fix rather than the highest-impact one. Checking off low-effort items feels productive, but it often leaves your most dangerous exposures open the longest. Leverage Cyber’s prioritization framework measures every finding across three dimensions — financial impact, remediation effort, and exploit proximity — so every dollar of remediation spend reduces the maximum amount of risk before you move on to lower-priority work.

The Prioritization Framework

Every finding in Leverage Cyber is scored across three dimensions that together determine where it sits in your remediation roadmap.

ALE Impact

The Annual Loss Expectancy — the estimated dollar value of risk if the finding remains open for a full year. This is your single most important input; it translates technical severity into business language your leadership can act on.

Remediation Effort

A normalized estimate of the work required to fully resolve the finding. Low means less than one business day. Medium means one to five business days. High means more than five business days or requires cross-team coordination.

Exploit Proximity

How close is the finding to a fully working attack? Immediate means an attacker can exploit it today with no additional prerequisites. Requires Additional Steps means exploitation is plausible but needs chaining with another weakness. Theoretical means the path to exploitation is indirect or unlikely without unusual circumstances.

The Priority Matrix

Use this matrix to assign a priority tier to every finding. When in doubt, bias toward higher priority — the cost of over-prioritizing a fix is almost always lower than the cost of under-prioritizing an exposure. P1 findings represent existential or near-existential financial risk to the organization and must enter active remediation immediately — not queued, not scheduled for a future sprint. P2 findings should be assigned to a named owner and resolved within the current sprint or planning cycle. P3 and P4 findings belong in your security backlog but should be reviewed each quarter to confirm they haven’t been re-categorized by changed conditions.
Exploit Proximity acts as a modifier on top of the matrix. A Medium ALE / Low Effort finding with Immediate exploit proximity should be promoted to P1 — an attacker doesn’t care about your sprint cycle. Use your judgment to escalate findings where active exploitation is confirmed or highly probable.

Quick Wins

Quick wins are findings that are simultaneously low effort and high ALE. Examples include enabling DMARC enforcement on a domain, forcing a password reset on an exposed privileged account, or closing an RDP port that has no business reason to be internet-facing. These actions take under a day and can remove hundreds of thousands of dollars in annualized risk in a single afternoon. Quick wins should always jump to the front of your remediation queue, regardless of what else is in your backlog. Even if you’re mid-sprint on a P2 initiative, a newly identified P1 quick win should be executed the same day it’s identified. The asymmetry of impact — minimal effort, maximum risk reduction — makes waiting unjustifiable. To find your current quick wins in Leverage Cyber, filter your findings dashboard by Effort: Low and sort by ALE descending. The top of that list is where you start.

When to Accept Risk

Not every finding can be remediated immediately, and some may never be fully resolvable given business or technical constraints. Formal risk acceptance is how you document a deliberate, informed decision to leave a finding open rather than letting it sit in a backlog indefinitely. To formally accept a risk in Leverage Cyber:
1

Document the finding

Record the finding ID, current ALE, and the specific reason remediation is not being pursued — business dependency, cost, vendor limitation, or other constraint.
2

Obtain appropriate sign-off

Risk acceptance for P1 or P2 findings requires sign-off from your CISO, CTO, or a designated risk owner with authority to accept financial exposure at the relevant ALE threshold. P3 and P4 acceptances can be approved at the security team lead level.
3

Set a mandatory review date

Every accepted risk must have a review date. For High or Critical findings, the review date must be no more than 90 days out. For Medium and Low findings, 180 days is acceptable. At the review date, the acceptance is either renewed with fresh sign-off or the finding re-enters the active remediation queue.
4

Log it in the platform

Mark the finding as risk-accepted in the Leverage Cyber dashboard and attach the sign-off documentation. This keeps your open ALE figure accurate and ensures the finding appears in your quarterly reassessment review.
Risk acceptance is not the same as ignoring a finding. An accepted risk must be actively monitored. If the threat landscape changes, if exploitation of the underlying vulnerability is observed in the wild, or if your ALE estimate is revised upward, the acceptance should be revisited immediately — do not wait for the scheduled review date.

Tracking Progress

Your remediation roadmap is a living document. As findings are resolved, Leverage Cyber updates both your open ALE — the total annualized risk still exposed — and your closed ALE — the risk you’ve successfully eliminated. Tracking the ratio between these two figures gives your security team and executive leadership a clear, dollar-denominated measure of progress that doesn’t require translating CVSS scores or severity labels. Use the Remediation Progress view in the dashboard to monitor:
  • Open ALE by priority tier — see at a glance how much P1 risk remains vs. P2 and below
  • ALE closed this period — track the dollar value of risk eliminated in the current sprint, quarter, or year
  • Finding age by tier — identify P1 findings that have been open longer than your SLA and escalate accordingly
  • Roadmap completion percentage — compare your current posture against the target state defined in your week-1 risk report
As findings are resolved and verified by Leverage Cyber’s continuous monitoring, they automatically move from open to closed and your risk score updates in real time. You don’t need to manually update the dashboard — resolution is confirmed through passive re-assessment of the same signals that originally identified the finding.
Involve your CISO or security team lead in the prioritization review as early as possible — ideally at the same session where you assign priority tiers. The remediation roadmap becomes significantly more actionable when ownership is assigned at the same time as priority. A finding with a P1 label and no named owner will still sit unresolved; a finding with a P1 label and an owner who has committed to a resolution date will not.