In one example, a non-transitory computer-readable storage medium stores
executable program instructions that detect, at a remote device node,
vulnerability data associated with an exploitable
vulnerability of a target enterprise network; retrieve, by a first local device node, the
vulnerability data, which may include a CVSS
score, determine, by a second local device node, a vulnerability
score VT by determining a first subscore VT1, where the first subscore VT1 is based on a Maximized
Confidentiality Impact (MCI) metric that is a modified privacy metric to capture the privacy
impact of the exploitable vulnerability, where the first subscore VT1 is also based on a Maximized Highest
Impact (MHI) metric to capture reputation damage based on an outsized
single impact attribute, and on a Modified
Confidentiality (MC) metric, Modified Integrity (MI) metric and Modified Availability (MA) as provided by CVSS; and remediate the exploitable vulnerability based on the vulnerability
score VT.