Opinion
CISA changes focus, which is great, but many SMEs are not ready to follow
It should have been a moment worth celebrating. On 28 September 2026, the US Cybersecurity and Infrastructure Security Agency retired its weekly vulnerability bulletin, framing the move as consistent with a broader shift from severity-based vulnerability management to risk-based prioritisation. Newly disclosed vulnerabilities will still be recorded on CVE.org, but organisations are now pointed towards the Known Exploited Vulnerabilities catalogue, CISA’s own advisories, and vendor security alerts for anything that actually demands action.
At Guardian360, we have been making this argument for years. Not every vulnerability deserves your attention. The overwhelming majority of disclosed flaws are never exploited, and chasing all of them, rather than the handful that matter, is a poor use of a security team’s limited time. So when the agency responsible for federal cybersecurity in the United States starts saying the same thing, it is tempting to treat it as a straightforward win and move on.
It is not quite that simple. CISA is right about the principle. But a lot of the organisations we work with, particularly small and medium-sized enterprises, are not yet in a position to benefit from that principle at all.
What has CISA actually changed?
The change itself is narrower than the headlines suggest. CISA has not stopped tracking vulnerabilities; it has stopped publishing a weekly summary of them. The agency’s reasoning rests on CISA’s own FY2024-2025 Vulnerability Review, which analysed exploitation data from 2024 and 2025 and found that although the volume of disclosed vulnerabilities kept climbing, the number that attackers actually exploited grew only marginally. In other words, the flood of new CVEs is not translating into a proportional flood of real-world attacks, so a weekly list of everything new was arguably never the most useful artefact in the first place.
The scale of that flood is worth pausing on. Microsoft’s most recent monthly security update disclosed close to a thousand vulnerabilities in a single release, well above its typical volume until very recently, and analysts expect vendor disclosure numbers to keep climbing before they plateau, as Dark Reading reported. Bug bounty platforms have reported submissions doubling and tripling in the same period.
A fair criticism of how, not what
None of that means the execution was beyond reproach. Kevin Surace, CEO of TokenCore, made a point worth taking seriously in Dark Reading’s coverage of the change: removing the bulletin shifts the work of assembling a clear picture onto defenders who are already stretched thin, particularly at smaller organisations. A dependable weekly touchpoint disappearing overnight, with no direct replacement announced alongside it, is not the most graceful way to manage a transition that the agency itself believes is right.
We would have preferred to see CISA pair the announcement with something more constructive: a short migration note, perhaps, pointing existing subscribers towards exactly which resources now do the job the bulletin used to do. The principle is sound. The communication around it was clumsy.
Is CISA really your only source?
That said, the criticism only lands if CISA’s bulletin was genuinely irreplaceable, and it was not. The KEV catalogue already exists, is already the resource CISA is now actively pointing people towards, and already answers the question a weekly roundup could only gesture at: which vulnerabilities are actually being used against real organisations right now. Vendor advisories continue regardless. In Europe, the European Union Agency for Cybersecurity publishes its own threat landscape reporting; its most recent edition, covering incidents between July 2024 and June 2025, draws the same conclusion CISA has: that ransomware and financially motivated crime, not an obscure long tail of theoretical vulnerabilities, remain the dominant threat, and that basic cyber hygiene is what actually keeps most organisations out of trouble.
Losing one weekly email is an inconvenience. It is not the loss of an entire early-warning system.
The real issue: most SMEs are not fighting the last vulnerability, they are fighting the first one
Here is where the celebration needs to slow down. Risk-based vulnerability prioritisation is genuinely good advice, but it is advice for an organisation that already has its fundamentals in order: an accurate asset inventory, a functioning patch process, multi-factor authentication on the accounts that matter, and backups it has actually tested. Only once those basics are in place does it make sense to spend energy figuring out which of the remaining vulnerabilities deserve priority over the others.
A great many small and medium-sized enterprises are not there yet. ENISA’s own threat landscape work makes the same point from a different angle: SMEs are increasingly targeted precisely because they are seen as easier entry points, and basic cyber hygiene, not sophisticated prioritisation frameworks, is what the agency identifies as the vital defence. Verizon’s most recent Data Breach Investigations Report adds a harder number to that picture. Exploited vulnerabilities became the leading initial access vector in 2025, accounting for 31 percent of breaches, up from 20 percent the year before. Yet only 26 percent of critical vulnerabilities in CISA’s own KEV catalogue were fully remediated in that same period, a decline from 38 percent the year before. Organisations are not failing to prioritise correctly. Many of them are failing to act at all, even on the vulnerabilities that are already flagged as the ones that matter most.
Telling an organisation in that position to “focus on risk, not severity” is true, but it skips a step. If you have not yet patched the vulnerabilities that are already known to be exploited, a more sophisticated prioritisation model will not save you. It will just give you a more elegant way of describing the same backlog.
If not CVSS, then what?
For the organisations that have done the groundwork, the practical answer is not complicated. Prioritise by whether a vulnerability is already listed as exploited, most usefully via KEV. Weigh that against how exposed the affected asset actually is, an internet-facing server carries different risk to an isolated internal system running the same software. And connect both of those to business impact: a vulnerability on a system that holds customer data or keeps the primary production process running deserves attention before one on a machine nobody would notice going down.
None of that is glamorous. It is also considerably more useful than treating every CVE as equally urgent, which is the exact habit CISA is trying to break.
Before you build a risk-based model, ask a harder question first
CISA changing focus is a good thing, and it deserves to be said plainly rather than begrudgingly. But the lesson for most SMEs is not “start prioritising vulnerabilities by risk.” It is “get honest about whether you have earned the right to prioritise at all.” Ask your own organisation the uncomfortable version of that question: if you stripped away every framework and every scoring model, is patching happening, is MFA switched on where it counts, and would your backups actually work if you needed them tomorrow? If the answer to any of those is no, that is where your attention belongs before CVSS, KEV, or any other acronym enters the conversation.
Sources
- Vijayan, J., CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus, Dark Reading, 17 September 2026
- CISA, FY2024-2025 Vulnerability Review
- Verizon, Data Breach Investigations Report, based on breach data from October 2024 to October 2025
- ENISA, ENISA Threat Landscape 2025
- CISA, Known Exploited Vulnerabilities (KEV) Catalog