What Rapid7 Active Risk changes about your vulnerability queue
Active Risk folds exploitability and attacker tradecraft into the score. Here is how to use it without drowning your IT teams in noise.
Rapid7’s Active Risk scoring exists because severity alone failed operators. When every scanner shouts Critical, nothing is Critical. Active Risk re-weights findings using exploit availability, attacker interest and related threat intelligence — so the top of the queue looks more like what an adversary would actually try.
How to read Active Risk in practice
Treat Active Risk as a triage input, not a substitute for judgement. Pair it with asset criticality:
- High Active Risk + internet-facing or tier-0 asset — emergency path, measured in days.
- High Active Risk + internal, non-sensitive — scheduled remediation with a firm owner.
- Low Active Risk + high CVSS — document why it waits; do not pretend it is Urgent.
Avoid the two common failure modes
1. Re-labelling the same backlog. If you swap CVSS for Active Risk but keep an infinite Critical SLA, nothing changes. Shrink the Urgent bucket until a team can empty it.
2. Ignoring compensating controls. A finding behind strong segmentation and MFA may still score high. Capture mitigations in the ticket so auditors see intent, not negligence.
Make the score operational
Wire InsightVM into the tools engineers already use — ServiceNow, Jira, Azure DevOps — with owners, due dates and reopen-on-regression. A score that never becomes a ticket is still a PDF.
As a Rapid7 partner, CyberUnify configures InsightVM sites, asset groups and risk views so Active Risk drives a weekly remediation cadence your teams can finish.
Related: InsightVM Implementation