Jonas Lindqvist Sample
IT/OT convergence. Owns 30 plants worth of legacy. · member since Apr 2026
A colleague built a shortlist scored partly on the number of CVEs published against each vendor. I have been arguing against it all week and want a sanity check.
My position: a vendor who runs a bug bounty, works with researchers and files CVEs properly will always look worse on that metric than one who quietly fixes things in a point release. Counting disclosures rewards silence. It also tracks how much software a company ships and for how long, which is portfolio size, not security.
Priya Raghunathan Sample
Detection engineering lead. Writes the rules, tunes the noise. · 2 months ago
You are right and there is a sharper version of the argument. The metric you want is not how many CVEs exist but how the vendor behaves around them: time from report to fix, quality of the advisory, whether they publish IOCs, whether they tell you when something is being exploited rather than waiting for the news.
Those are all observable from public advisories and they actually differentiate.
Chen Wei Sample
Detection content and purple teaming. · 2 months ago
Agreed. The one place raw counts are useful is the opposite direction from how they are usually used: if a product with a large installed base has almost no CVEs, that is sometimes a sign nobody is looking, not that nothing is there.
Rahul Deshpande Sample
Infrastructure and security. Patches what the vendors break. · 2 months ago
For the shortlist, ask each vendor for their last three security advisories and read them. The difference between a vendor who writes a clear advisory with affected versions and mitigations, and one who publishes two sentences, tells you more than any count.
Jonas Lindqvist Sample
IT/OT convergence. Owns 30 plants worth of legacy. · 2 months ago
That is the argument that won it. We replaced the count column with 'quality of last three advisories' and the ranking changed completely.