# Vulnerabilities, MCO/MCS & risk analysis

Adrien Murillo — Murillo Consulting

Prioritize CVEs, hardening gaps and risk scenarios by exposure, business impact and operating constraints.

Prioritize CVEs, hardening gaps and risk scenarios by exposure, business impact and operating constraints.



## Qualify the context
Identify critical assets, feared events, dependencies, exposure and operating constraints.

## Build risk scenarios
Describe threat sources, attack paths, likelihood, impacts and existing measures.

## Prioritize remediation
Produce a backlog that connects CVEs, exposure, affected assets, actions, correction evidence and residual risk.

## Deliverables
- risk scenarios
- CVE/remediation backlog
- KPI/KRI
- residual-risk decisions

## Boundaries
- Automated scoring without workshops.
- Unavailable business stakeholders.
- A standalone penetration test.



## Navigation
- [DevOps and Cloud DevSecOps consultant.](/en/profil)
- [Engineering services.](/en/services)
- [Selected work.](/en/realisations)
- [Open-source projects.](/en/projets)
- [Guides to put into practice.](/en/ressources)
- [Let’s discuss your project.](/en/contact)
- [From scope to handover.](/en/approche)
- [Real contexts. Real constraints.](/en/secteurs)
- [Learn by making decisions.](/en/lab)
- [Legal notice](/en/mentions-legales)
- [Privacy](/en/confidentialite)
- [Terms of use](/en/conditions-utilisation)
- [Train your teams. Through practice.](/en/formation)

[Contact](mailto:contact@adrien-murillo.com)
