How we rate risk.
Every story in the daily KLM Innovation Security Monitor carries one of six ratings. They are not about how important the event is. They are about how urgent the action is, and whether there is an action to take at all.
Active exploitation of a critical flaw, with data exposure or full system compromise in progress. The breach is happening now, and it is spreading.
Deploy immediately
No exceptions.
Confirmed exploited vulnerability, or confirmed breach with a high likelihood of lateral movement. The flaw is real, the exploitation is real, and the blast radius is large.
Deploy within 48 hours
Exploited vulnerability or active attack pattern with a moderate blast radius. Real risk, real exposure, but the path to full compromise is not yet open.
Deploy within 2 weeks
Active risk with a concrete defensive action available now. An exploited CVE not yet in a KEV catalog, a confirmed misconfiguration in the wild, or a pattern with a high likelihood of exploitation. You can fix this today.
Deploy within 30 days
Hardening opportunity, or risk with a low likelihood of exploitation. Worth doing, not urgent. The cost of delay is low, but it accumulates.
Deploy within 90 days
Guidance, specifications, frameworks, new tools, or research findings without active exploitation. Useful for awareness and planning. There is nothing to patch, no active exploitation, no confirmed breach.
No deploy required
Awareness and planning only.
Significance does not equal severity.
A specification, a framework, or a new tool can be the most consequential development of the year and still rate CONTEXT. That is not a downgrade. It is the scale doing its job. Severity measures urgency and actionability. A standard with a comment period through year end is not a vulnerability. A scanner with a 26% hit rate is not a breach. Build them into your roadmap. Do not panic.
OWASP Agent Control Standard v0.1 shipped · CONTEXT
It is a specification with a public comment period. No active exploitation, no patch to deploy. See it rated this way in the Sep 20 Security Monitor.
See it in practice.
The daily Security Monitor applies this scale to AI and API security events as they happen. Each story is rated, each pattern is tracked across days, and the risk summary table maps every finding to a concrete action.