Scan Results Are Not a Risk Decision: The Skill CISSP and CISM Candidates Undertrain
August 20, 2026
Randy Hall, CEO— AI-assisted and reviewed prior to publication.

A test result is a fact. A risk decision is a judgment about what that fact means for this business, this asset, and this quarter's priorities. Most practitioners stop at the fact: they hand leadership a severity score and call it done. The skill that actually protects the organization is converting that score into an accept, mitigate, transfer, or avoid decision leadership can defend.
What does it actually mean to turn a finding into a risk decision?
It means adding the three things a scanner cannot know on its own: what the affected asset is worth to the business, whether anyone is actually trying to exploit the flaw, and what it costs to fix versus what it costs to leave alone. A CVSS score of 9.8 on a payment database and the same score on an unused test box are not the same risk, even though the scanner reports them identically.
That gap is not theoretical. As one industry analysis puts it, CVSS scores measure technical severity, not business risk, and closing that gap requires combining the score with exploit status, asset criticality, and exposure before anyone decides what gets fixed first. A practitioner who cannot make that translation is handing a spreadsheet to a board and calling it strategy.
Why do scanners keep producing more findings than teams can act on?
Because scan and audit volume has outpaced any organization's remediation capacity, and severity-only triage no longer works as a filter. NIST recently changed how it handles the National Vulnerability Database specifically because submission volume grew faster than the agency's ability to analyze each one, a shift that places more responsibility on individual security teams to contextualize risk themselves. That responsibility used to sit with a central authority. Now it sits with whoever is reading the report.
The result is prioritization paralysis. A scanner returns three hundred criticals, a team has the capacity to fix twenty this week, and the score alone cannot tell anyone which twenty matter. Rapid7's own research on exposure management notes that CVSS alone is insufficient because it measures theoretical severity and does not account for whether an attacker is actually using the vulnerability or how valuable the affected asset is. This is exactly why federal guidance now treats severity scores as one input rather than the decision itself. CISA's Known Exploited Vulnerabilities catalog exists precisely because a CVE with real-world exploitation evidence deserves different urgency than one that is theoretically severe but never seen in the wild, and CISA is explicit that organizations should treat the catalog as one input to a broader prioritization framework, not the whole framework.
What does CISSP and CISM training actually test here, and why does it matter to a hiring manager?
Both exams test the judgment step, not the technical step, and that is exactly the skill a scanner cannot replace. The ISC2 CISSP exam outline builds its heaviest-weighted domain, Security and Risk Management, around applying risk management concepts and aligning the security function with business strategy and objectives. CISM mirrors that structure from the manager's chair. ISACA's own CISM exam content outline frames its risk domain around identifying and assessing risk specifically to support informed business decisions, not around finding more flaws.
This is the part hiring managers underweight when they buy certifications by keyword. A team full of people who can run a scan is common. A team that can look at three hundred findings and produce a defensible, documented remediation order, one that a CFO or general counsel could review and understand, is rare and worth a premium. NIST's own risk assessment guidance backs this up structurally: the Guide for Conducting Risk Assessments frames the entire process around combining likelihood and impact to produce a prioritized, documented set of findings that supports control selection, not a raw severity list.
Here is the difference in practice, boiled down to what actually changes on a remediation ticket:
| Input | What it tells you | What it does not tell you |
|---|---|---|
| CVSS base score | Theoretical severity in a vacuum | Whether this asset matters, or whether anyone is exploiting it |
| KEV catalog status | Confirmed real-world exploitation | Whether your specific environment is exposed or compensating controls exist |
| Asset criticality and business impact | What breaks and who is affected if this is exploited | Nothing on its own, unless paired with severity and exploitability |
A practitioner trained to work across that whole row, not just one cell, is the one who keeps a remediation backlog from becoming unmanageable. That is the judgment CISSP and CISM certification exists to validate, and it is the reason Forge University's CISSP prep builds its risk domain coverage around scenario-based decisions rather than definition recall.
How should leadership build this into team structure and hiring?
Start by testing for the decision, not the vocabulary. Anyone can define residual risk in an interview. Fewer candidates can walk through a mock finding, state the business impact, and recommend a treatment they'd stand behind in front of an audit committee. If your current review process rewards people for closing tickets fast rather than closing the right tickets first, you are optimizing for the wrong output.
Second, treat this as a documentation discipline, not just an analytical one. NIST's guidance is explicit that risk determinations need to be recorded with the reasoning behind likelihood and impact ratings so the rationale survives past the person who made the call. That record is what protects the organization when a decision to accept a risk turns out badly, and it is what regulators and auditors ask for after the fact. A curriculum overview of how this maps across certifications is a reasonable starting point if you are deciding which credential to fund for which role on your team.
Third, recognize that this skill compounds. A CISM-certified manager who can turn a penetration test report into a treatment decision this quarter builds an audit trail that makes next quarter's board conversation faster, because the reasoning behind past decisions is already documented and consistent. Teams without that discipline re-litigate the same severity arguments every cycle, which is expensive in a way that never shows up on a single line item.
What does skipping this actually cost?
It costs credibility first and budget second. A security team that cannot explain why it fixed the medium-severity finding on the customer database before the critical one on the internal test server loses the trust of the executives who fund it. Once that trust is gone, every future request for remediation time or tooling budget gets scrutinized harder, which slows the whole program down.
It also costs actual risk exposure. Industry research on exploitation patterns consistently finds that a large share of confirmed attacks target flaws that never scored as the most severe on paper, which means teams chasing the highest number first are frequently protecting the wrong asset while a lower-scored, actively exploited flaw sits open. That is not a tooling failure. It is a judgment failure, and it is the exact failure CISSP and CISM training is designed to close.
If your team is building this capability now, the fastest path is structured practice against realistic scenarios rather than memorizing scoring formulas. You can start training with a study plan built specifically around risk-treatment scenarios rather than pure technical recall, which is where most exam candidates and most working practitioners actually fall short.
The organizations getting ahead of this are not the ones with the most scan coverage. They are the ones whose people can look at that coverage and tell leadership, with evidence, what to fix first and why. That is a hiring decision, a training investment, and a risk management discipline all at once, and it is worth treating as one.