Quantifying Swiss Cheese, the Bayesian Way
I wrote a short piece on how to actually quantify the classic Swiss-cheese model of defense instead of just showing it in slides. Using Bayesian updating, I show how you can take EPSS scores for CVEs on an asset, layer in control effectiveness (like firewall, EDR, etc.), and update those probabilities over time as you get real data. It’s a lightweight, data-driven way to express how much your defenses actually reduce exploit likelihood, and it ties nicely into FAIR-CAM thinking too. Would love feedback or discussion from anyone doing something similar with telemetry or Bayesian models. submitted by /u/t0sche [link] [comments]Technical Information Security Content & DiscussionRead More