All news

Compensating Controls + EPSS-driven risk scoring

Two upgrades that change how Lorika prioritises remediation work — both pulling on real-world data instead of CVE severity alone.

What's new

Why this matters

The single biggest complaint about vulnerability management is "you flagged 4,000 things and 3,800 of them aren't actually exploitable in our environment." Compensating controls and EPSS together cut the noise by an order of magnitude — without hand-waving away genuine risk.