oolak / Features / Risk-based prioritisation
Risk-based prioritisation

Fix the few things that really matter, first.

oolak scores every vulnerability by how likely it is to be exploited, how important the asset is and whether it can be reached from the internet. Thousands of findings become a short list that your teams can actually finish.

Every finding with its risk score, exploitation data and owner.

Real threats first

Vulnerabilities that attackers are already using rise to the top of the list.

Business context included

A problem on a critical, internet-facing system outranks the same problem on a test machine.

Deadlines that make sense

Every severity has a due date, and breaches are visible long before an audit.

Risk-based prioritisation

What's included

  • The CISA Known Exploited Vulnerabilities list and FIRST EPSS scores are added to every finding.
  • The risk score combines severity, exploitation data, asset criticality and internet exposure.
  • Your organisation decides how much each factor counts.
  • The "what to fix first" funnel narrows all findings down to a short list.
  • SLA policies set a due date for each severity and track every breach.
  • Each finding moves through open, remediated, reopened and decommissioned states.
  • Saved filters can be shared with the whole team.
  • Results break down by team, site and group.
  • Findings come from Tenable, Nessus, Qualys, Rapid7, CrowdStrike, OpenVAS and DefectDojo.
  • Cloud findings come from AWS Inspector, Security Hub, Microsoft Defender for Cloud and Google Security Command Center.
  • Application findings come from OWASP ZAP, Burp Suite, Nuclei, Trivy, Grype, Semgrep and TruffleHog.
  • Cloud identity and permission risks are assessed alongside vulnerabilities.
  • Decision models suggest a priority for every finding, and a person makes the final call.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

How is the risk score calculated?
The score starts from the scanner severity and is adjusted by KEV membership, EPSS probability, asset criticality tier (crown jewel, tier 1 to 3), internet exposure and relationships such as WAF or CDN protection. The weights are configurable per organisation.
How are SLAs measured?
Each severity has a policy with a due date. Status per finding and the aggregated compliance percentage are calculated the same way everywhere, and findings without a policy are reported separately.