Insight #1
As an industry we need to move away from CVSS base score as the risk measuring stick. It doesn’t work and is extremely broken.
Insight #2
This week a researcher submitted CVEs for intentionally vulnerable applications. The CVEs were initially accepted and sent social media platforms into a tizzy. It’s time to revamp the entire CVE system, because at ~80 CVEs per day it is in a state of disarray.
Insight #3
If you are a US-based organization that does business both within the borders and abroad, you best start preparing for GDPR-like privacy requirements to keep US data within the US.