arXiv · 2609.37217
When Cyber Scoring Systems Diverge: An Empirical Comparison
Abstract
Vulnerability scoring systems underpin cyber patch prioritization and risk management, but their comparative behavior is almost always assessed in the abstract, through correlation studies in IT vulnerability databases, rather than by the operational consequences they produce when embedded in a system-level risk model. Here we present an empirical comparison of four vulnerability scoring systems, namely CVSS (Common Vulnerability Scoring System), EPSS (Exploit Prediction Scoring System), SSVC (Stakeholder-Specific-Vulnerability Categorization), and IronMiner (operationally calibrated proprietary scoring system). As a substrate for comparison, we use a reconstruction of the 2015 Ukraine Power Grid operational-technology (OT) network that provides a documented incident topology. The results show a high degree of disagreement between the scoring systems. This suggests that the choice of the scoring system could significantly influence mitigation strategies and vulnerability prioritization, implying that a composite or hybrid scoring approach could offer a more suitable solution.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Kirsi Hellsten, Joni Herttuainen, Ambrose Kam, Arlanda Johnson, David Welsh, Kimmo Kaski. 2026-09-29. When Cyber Scoring Systems Diverge: An Empirical Comparison. https://arxiv.org/abs/2609.37217
Cite the original work for its findings. Save a collection to share your selection of sources.