Skip to main content

Mitigation Optimization

Focus on high-impact fixes to reduce cyber risk as efficiently as possible.

Updated over 5 months ago

Overview

The Mitigation Optimization funnel helps you get the most value from your mitigation work by prioritizing the findings that have the biggest impact. This article explains how the funnel works, what each stage represents, and why Critical to Block findings should be addressed first.
It’s a focused, strategic way to reduce cyber risk with minimal effort and maximum effect.


Understanding the Funnel

The funnel filters your findings in three stages:

1. Overall Findings

This is the full set of open, relevant findings that could be exploited.
Included findings:

  • Status is not Fixed, Not relevant, or a pre-open status (e.g., Draft, Not approved, Awaiting approval, Approved).
    These are all the potential weak points still awaiting action.


2. Attack Route Findings

This subset includes only the findings that appear on attack routes in the Mitigation Graph.

  • These findings are critical because they connect threat actors to your business assets.

  • Mitigating these disconnects the path, making it harder for an attacker to reach high-value targets.

  • This group is shown as a percentage of Overall Findings in the funnel.


3. Critical to Block Findings

This is the most important set.

  • These findings, if fixed, cut off the most high-risk paths in the mitigation graph.

  • They offer the best risk reduction-to-effort ratio — meaning: fewer fixes, greater impact.

  • Shown as a percentage of Attack Route Findings.

Fixing these first delivers the fastest and most meaningful exposure reduction.


Important notes

  • This funnel only includes findings with full status and risk context — ensure your Mitigation Graph is populated and findings are validated.

  • Critical to Block is calculated automatically based on real attack routes and business asset impact.


Wrap-up / Next Steps

The Mitigation Optimization funnel doesn’t just show you what’s broken — it shows you what to fix first. Focus on the findings that truly move the needle. That way, you can protect more with less effort, and show real results, faster.

Did this answer your question?