A vulnerability analyst is preparing an executive summary after a scan of a hybrid estate. The report includes CVSS scores for internet-facing web servers. Which summary statement best communicates risk in business terms?
Select an answer to reveal the explanation.
Short Explanation
Think of an executive summary like a weather warning: you do not report barometric pressure, you say the bridge may close. If your report says only CVSS 9.8, you have told them a number, not the consequence. Translate the flaw into customer data, downtime, or revenue risk.
Full Explanation
Vulnerability reporting to executives is a translation exercise: CVSS describes technical severity, but leadership needs expected impact on confidentiality, availability, revenue, or regulatory exposure. A critical score becomes useful only when tied to affected assets that matter to the business, such as internet-facing servers handling customer data or payment workflows, because that tells decision makers what could be compromised and how operations would be disrupted. A statement focused only on scanner counts, CVE totals, or patch scheduling remains technical and does not explain consequence, so it fails the executive communication objective. Listing exploit maturity, attack vectors, and affected versions supports technical triage, but it does not convert severity into business risk for a non-technical audience. Emphasizing percentage change in findings or emergency maintenance describes workload pressure, not the actual exposure or expected impact of the vulnerabilities. Exam caveat: do not confuse technical severity with business risk; CVSS is a starting point, not the executive message. Operational check: before sending the report, ask whether each critical finding names the affected business service, the likely customer or revenue impact, and the remediation decision leadership must make.