Resources

Knowledge base.

Exposure management has a lot of acronyms and not much plain talk. This is where we fix that: how Verskop works, what the terms mean, and what the output looks like.

Start here

The essentials.

How Verskop works

The five stages, discover through monitor, and the evidence grading that runs through all of them.

Read the platform

Sample brief

A sanitized example of the DOCX and PDF a customer receives, with the citations that back every finding.

Request the sample

Compliance frameworks

Which frameworks the engine maps to, and why compliance is opt-in and never asserted for you.

See compliance mapping

Glossary

The terms, in plain language.

Exposure management CTEM
Continuously finding, prioritizing, and reducing the ways an attacker could get in, rather than scanning once and filing a report.
Exposure validation AEV
Proving a weakness is actually exploitable by safely emulating an attacker, instead of assuming it from a version number.
Attack-surface management EASM
Discovering and tracking everything of yours that faces the internet, the footprint an outsider can reach.
Known Exploited Vulnerabilities KEV
CISA's authoritative list of flaws confirmed to be exploited in the wild. If it is on the KEV list, it is not theoretical.
Exploit Prediction Scoring System EPSS
A probability that a given vulnerability will be exploited soon, used to rank what to fix first.
Financial risk quantification FAIR
A standard for putting a defensible dollar range on risk, so a board sees exposure in money, not severity labels.
Adversary tactics and techniques ATT&CK
MITRE's shared language for how attackers operate. Verskop maps findings to it so the story is concrete.
Confirmed vs assessed GRADING
Confirmed means observed on the live host and cited. Assessed means inferred and held for verification, out of the risk total.

Request access

See it on your own footprint.