decision

Security decisions need residual risk in the open

Security work is a sequence of tradeoffs under incomplete information. Argumont compares remediation options against exploitability, impact, exposure, and operational disruption.

What this decision type is

A cybersecurity decision might choose which vulnerability to fix first, whether to shut a system down, which control to buy, or whether a finding is actually reachable. Severity labels from scanners are inputs, not verdicts.

Argumont is decision support. It does not replace incident command, penetration testing, or a security program.

Common mistakes

Treating CVSS as the decision. A critical finding on an unreachable host can lose to a medium finding on the payment path.

Another mistake is scoring 'do nothing' as irresponsible by default. Sometimes monitoring plus compensation is the least-bad option this week.

What evidence matters

Reachability, identity of the asset, data classification, detection coverage, and the real cost of the proposed fix including downtime. Screenshots of scanner output are not the same as exploitability.

How Argumont evaluates it

Roles argue for the preferred remediation, try to defeat it, and search for an alternative such as isolation, WAF rules, or scheduled maintenance. Risks are recorded by category, including security, operational, and regulatory.

Example criteria

Exploitability

How easily an attacker can use the weakness.

Impact

Business and data impact if exploited.

Exposure

How reachable the asset is from untrusted networks.

Detection

Whether misuse would be noticed in time.

Remediation cost

Effort, money, and freeze windows.

Residual risk

What remains after the chosen control.

Common risks

Change-induced outage

The fix causes more damage than the finding.

Paper compliance

A control exists in policy and not in production.

Example decision

Patch this week with a production freeze, isolate the service, or accept residual risk until the next window. The analysis should not hide the accept option.

Questions

Will Argumont tell us we are secure?
No. It compares options and records uncertainty. Security is not a badge you earn from a verdict.

Related pages

use case

Evaluate risk

Risk work is a decision among mitigate, transfer, accept, and avoid. Argumont keeps residual risk on the page so a funded control cannot pretend to have closed ...

industry

Cybersecurity

A remediation plan is a decision: what to fix first, what to accept, and which vendor actually reduces residual risk. Status green is not that analysis.

role

Security teams

A finding is not a decision. The decision is patch, isolate, accept, or stop. Argumont compares those treatments without pretending a verdict makes a system saf...

feature

Risk analysis

Argumont treats risk as something you can score alongside other criteria. Volume of imagined disasters is not the same as residual risk after a mitigation.

hub

Decisions

These pages are not a directory of keywords. Each one describes a kind of choice, the evidence it needs, how Argumont scores it, and where to go next.

Challenge your remediation plan

Argumont challenges assumptions, researches evidence, compares competing approaches, and identifies the strongest decision.

Challenge your remediation plan