stephenshaffer.io

Portfolio

Stephen Shaffer

Security-focused technology professional currently focused on the intersection of data science and risk management.

Blog

Longer pieces, previously published on Medium.

Jul 2026 Introducing the Local Exploit Hazard Model An approach to synthesizing global and local exploit signals to quantify vulnerability remediation efficiency. Read → Feb 2026 Hacking Reality: Why Data Science Is the Blue Team’s Ultimate Exploit Security ships risk models and almost never checks them against what happened. The gap worth closing is observation infrastructure, not scoring. Read → Apr 2025 Vulnerability Information Cones Light cones borrowed from physics as a mental model for deciding under imperfect information. Read → Oct 2025 Updating Exploit Likelihood with Control Effectiveness Putting numbers on the Swiss-cheese model: control effectiveness as a distribution, updated with evidence, then folded back into exploit likelihood. Quantifying Swiss Cheese, the Bayesian Way Read → Aug 2024 Modeling Asset Risk Using EPSS Rolling per-CVE EPSS probabilities up to an asset-level view of exploitation risk. Read → Nov 2023 Determining EPSS Score Thresholds for Prioritization Where to draw the line, and what it costs you when you draw it in the wrong place. Read → Jun 2023 Flipping the Vulnerability Management Model: CVSS → SSVC My take on leveraging SSVC over CVSS for vulnerability action prioritization. Read → Jun 2023 Sabermetrics and Cyber Risk Quantification What sabermetrics did for the game, and where it points for cyber risk. Read → May 2023 Learning How to Quantify Cyber Risk Using Bayes A walk through Bayesian thinking for cyber risk: priors, evidence, and updating as new data arrives. Read →

Speaking

Talks, webinars, podcasts and panels.

Jun 2026 The New Rules of Risk: EPSS v5 and Agentic Adversaries runZero Hour, episode 31, with Tod Beardsley and Bri Cluck. runZero Hour · Podcast Listen → Apr 2026 Quantifying Swiss Cheese, the Bayesian Way A Bayesian treatment of layered defense, measuring control effectiveness as a distribution rather than a yes or no. FIRST VulnCon 2026 · SIRAcon ’26 · YouTube Watch → May 2025 EPSS with Stephen Shaffer A long conversation about EPSS: how it works, where it helps, and where it stops. Hackers On The Rocks · Podcast Watch → Apr 2025 Modeling Asset Risk Using Grouped EPSS How to group and aggregate per-CVE scores up to asset-level exploitation risk. FIRST VulnCon 2025 · YouTube Watch → Aug 2024 Predictive Vulnerability Management: Operationalizing EPSS with Business Context Using EPSS alongside business context to prioritize what actually gets exploited. Nucleus Security · Webinar Watch → Nov 2023 How to Prioritize AppSec Risks: CVSS, EPSS, and Too Much Data Using CVSS and EPSS together to prioritize application-security findings. LeanAppSec Fall 2023 · Endor Labs · with Darren Meyer Watch → Nov 2023 Linking CVSS, AppSec and EPSS for Product Security How severity, exploit probability and AppSec findings fit together when prioritizing product security. Phoenix Security · Livestream · with Francesco Cipollone Watch → Aug 2023 Using Decision Trees for Vulnerability Prioritization With SSVC SSVC decision trees as a prescriptive alternative to CVSS severity scoring. Nucleus Security · Webinar Watch →

Get in touch

Email and Signal are your best chance of getting in touch.