Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
critical-infrastructure-threatstandards-framework-updateindustrial-control-system-vulnerability

OT Security Pushes Beyond CVSS for Risk Assessment

Updated 3mo agoFirst seen Mar 17, 20262 sources

Operational technology security practitioners are increasingly arguing that CVSS is not an adequate way to measure risk in industrial environments, even after the release of CVSS 4.0. The reporting says OT defenders view traditional vulnerability severity scoring as poorly suited to environments where safety, uptime, physical process impact, and sector interdependencies matter more than the characteristics of an individual software flaw.

Experts cited in the coverage say OT risk assessment needs to focus on cascading consequences, cross-sector dependencies, and consequence management rather than trying to refine a vulnerability-centric scoring model. The articles describe a broader shift in OT security thinking: instead of treating CVSS as a universal standard, organizations operating critical infrastructure are being urged to adopt methodologies that better reflect real-world operational impact and the administrative realities of industrial systems.

Share:
OT Security Pushes Beyond CVSS for Risk Assessment
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 16, 20263mo ago

Experts call for broader OT-specific risk methodology beyond CVSS

Experts from multiple firms argue that even updated CVSS remains poorly suited to OT because risk depends on local context, safety consequences, asset conditions, and cascading cross-sector impacts. They advocate greater automation, machine-readable advisories such as CSAF, or broader consequence-based methodologies centered on infrastructure criticality and dependencies.

OT security practitioners increasingly supplement CVSS with other prioritization inputs

Defenders in operational technology environments increasingly use threat intelligence, CISA's Known Exploited Vulnerabilities catalog, Exploit DB, EPSS, and SSVC alongside CVSS to better assess real-world risk and exploitability. This reflects a shift away from relying on vulnerability severity scores alone.

CVSS 4.0 introduced with added safety and environmental factors

The updated CVSS 4.0 framework added safety and environmental considerations intended to improve vulnerability scoring. Experts cited in the coverage say these changes still do not adequately capture operational technology risk in practice.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Affected products
1 linked
Windows
Organizations
10 linked
Dell TechnologiesCisco SystemsBooz Allen HamiltonClarotyAtlantic CouncilHewlett Packard EnterpriseAmpyx CyberTPO GroupFrenosInformation Security Media Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.