Severity-based vulnerability management is breaking down. Attackers are moving faster than patch cycles, and legacy "scan and patch" is now a liability.In this session, Nadav Ostrovsky (Co-Founder & CTO, Astelia, former Israeli National Red Team leader) and Ross Young (former CIA officer, CISO, and author) cover how attackers chain reachable vulnerabilities to reach crown-jewel assets, why exploitability alone isn't enough, and how to defend "don't fix" decisions to IT, audit, and the board.
Why legacy “scan and patch” is now a liability, not hygiene
How attackers actually chain reachable vulnerabilities to reach crown-jewel assets
Why exploitability alone isn’t enough — and how reachability changes prioritization
What security leaders should change now, before programs fail under attack speed

