Page 1 of 1

SME Questionnaire Form - June 23

Publication Target Date: June 23

Submission Deadline: June 22

Article Working Title: Why Vulnerability Management and Asset Prioritization Break Down in Critical Infrastructure

Editorial Brief:

IT-centric vulnerability management does not work in critical infrastructure, and the volume of known, unpatched vulnerabilities in a large multi-site operator runs well beyond what any patch program could address. The article should examine why the standard model fails — CVSS scores that measure IT exploitability rather than consequence to a physical process, patch timelines that assume change windows OT cannot provide, and asset inventories that are incomplete by default — and what actually works instead. The functional alternative is consequence-based prioritization: a crown-jewel analysis that asks which assets, if compromised, produce an unacceptable physical, safety, or service outcome, and concentrates limited resources there. But the article should be honest that building such a model requires process knowledge security teams often lack and that getting the basics right — knowing what you have, where it is, and how it connects — is far harder in the field, with small teams and tiny budgets, than the literature admits. It should treat compensating controls for unpatchable systems, the legacy-equipment problem where no patch will ever exist, and how prioritization must adapt across a multi-site operator where every site has a different asset population. These lessons are universal across critical infrastructure.

About you

First Name

Last Name

Company/Organization

Job Title/Designation (to be used in feature)

Business Email

Short Bio

Upload headshot (JPG/PNG up to 5MB; Square 500×500px, 300 DPI recommended)

Question Set

How many known, unpatched vulnerabilities exist in your environment, and how do you actually manage that backlog?

How do you translate a CVSS score into a consequence-based risk rating that reflects impact to your physical process or service?

How do you build and maintain a crown-jewel or asset-criticality model when security teams lack deep process knowledge?

What compensating controls do you deploy for systems that cannot be patched, and how do you verify they are reducing risk?

How do you handle assets from vendors that no longer exist or no longer support the product?

What does getting the basics right — inventory, connectivity, prioritization — actually take in a small-team, multi-site reality?

Thank you for your response!