Group Purchasing
Group Purchasing

Risk Rules Everything Around Me: Making Smart VM Decisions Without the Guesswork

  • Wed, Jul 23, 2025
  • Duration: 1 Hour
  • English
  • Jonathan Risto
  • Technical Presentation
Webcast Hero

Not all vulnerabilities are created equal—and fixing everything just isn’t realistic. This session shows how to align vulnerability prioritization with real-world risk.

Learn how threat intelligence, exploit prediction, and business impact modeling can help you focus on what truly matters.

We’ll explore how to build a practical prioritization framework using data sources like CISA KEV, EPSS, and MITRE ATT&CK, and address the cultural and operational challenges that come with risk-based approaches.

This webcast supports content from SANS Institute LDR516: Building and Leading Vulnerability Management Programs. To learn more about this course, explore upcoming sessions, and access your FREE preview, click here.

Watch more Vulnerability Management from Jonathan Risto OnDemand:

Meet the speaker

Jonathan Risto
Jonathan Risto

Jonathan Risto

Technical Director, Cyber Posture Management Program at Government of Canada

Jonathan Risto is a Principal Instructor at the SANS Institute and Technical Director for the Canadian Cyber Posture Program. Co-author of LDR516: Strategic Vulnerability and Threat Management, he helps leaders turn exposure data into actionable risk programs through frameworks like VMMM and CTEMMM.

Read more about Jonathan Risto