Supports stronger vulnerability response capabilities through decision criteria explainable to third parties and automated operations

Hitachi has developed a method for automatically determining vulnerability response prioritization based on business impact, enabling organizations to prioritize responses to critical vulnerabilities even with limited human resources.

As cyberattacks have continued to become more frequent and sophisticated in recent years, rapid response to vulnerabilities has become increasingly important. At the same time, growing efforts to strengthen security response across supply chains have increased the need for operations that enable organizations to demonstrate the rationale behind their vulnerability response decisions to business partners and auditors. Vulnerability assessments have traditionally relied on two frameworks: CVSS*1, which quantifies the technical severity of vulnerabilities, and SSVC*2, which helps determine vulnerability response policies by considering business impact and other factors. While CVSS allows for an objective score-based evaluation of technical severity, it does not adequately reflect the operational or business impact that varies from one system to another, making it difficult to establish response priorities. SSVC, on the other hand, enables evaluation based on business impact but often requires manual assessment and consensus among stakeholders, posing challenges for rapid decision-making and automation.

The newly developed method addresses these challenges by predefining the worst-case impact for each system under the SSVC business impact criteria. When a vulnerability is detected, the method combines the predefined worst-case impact with the technical severity assessed by CVSS to automatically determine the appropriate response priority. This enables consistent prioritization based on both business and technical impact, helping organizations quickly respond to critical vulnerabilities and demonstrate the rationale behind their vulnerability response decisions to third parties, including auditors and business partners. Furthermore, Hitachi has confirmed that, by integrating with a ticketing system*3, the method can automate the entire workflow—from detecting a vulnerability to assigning a response deadline and issuing tickets—and track and visualize progress. This helps organizations accelerate vulnerability response while minimizing workload.

Going forward, Hitachi will further enhance the technologies behind this method as part of the security infrastructure technologies supporting Lumada 3.0, aiming to realize a safe and secure digital society.

*1 CVSS: Common Vulnerability Scoring System. A framework for communicating the severity of vulnerabilities using common metrics. It is maintained by the Forum of Incident Response and Security Teams (FIRST).
*2 SSVC: Stakeholder-Specific Vulnerability Categorization. A framework that determines vulnerability response policies using a decision tree based on branch conditions such as Exploitation (history of exploitation), Exposure (level of exposure), Automatable (automatability of cyberattacks), and Human Impact (the impact on organizational missions and safety). Developed by Carnegie Mellon University and recommended by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
*3 Ticketing system: A system that manages operational tasks, including vulnerability response, by creating tickets and tracking assignees, deadlines, and progress.

Background and issues

Cyberattacks against systems that support companies and social infrastructure have become increasingly frequent and sophisticated in recent years. Advances in AI technology have further accelerated the speed at which attackers can discover and exploit system vulnerabilities, making it even more important for companies to respond to vulnerabilities more quickly. As a result, vulnerability management has become a critical issue that affects business continuity and public trust. Also increasing in importance are operations that enable organizations to explain the rationale behind their decisions on response priorities to business partners and auditors, as evident in the policy for establishing the SCS evaluation system*4 announced by Japan’s Ministry of Economy, Trade and Industry (METI) and National Cybersecurity Office (NCO) to ensure supply chain–wide security.

In response to these demands, CVSS, which evaluates the technical severity of vulnerabilities, cannot adequately reflect business or service impact by itself, limiting its usefulness in determining response priorities. Meanwhile, evaluating business impact in SSVC often requires manual evaluation and coordination among stakeholders depending on the characteristics of the vulnerability. In addition, follow-up activities after decisions are made, including assigning response tasks and tracking response progress, have typically relied on case-by-case handling; this tends to result in inconsistent decision-making, delayed responses, and increased workload.

*4 Supply Chain Security measures evaluation system: A voluntary framework led by METI and NCO to assess and strengthen security measures across the supply chain.

Features of the technology and solutions developed to solve these issues

Hitachi has been working to develop and deploy Security Digital Twin technology*5 to support decision-making on security measures based on business impact. Building on this expertise, Hitachi has now developed a method that automatically determines vulnerability response prioritization. The method combines the SSVC business impact criteria with the CVSS technical assessment and further automates the ticketing system workflow. The key features of the technology are described below.

*5 Development of Security Digital Twin Technology for Planning Security Countermeasures Ensuring Business Continuity - Research & Development : Hitachi

1. Technology for automatically evaluating vulnerability response prioritization based on business impact
This technology predefines the worst-case impact for Human Impact (HI),*6 a business impact criterion in SSVC, before vulnerabilities are detected. Then, when a vulnerability is detected, the technology automatically evaluates and adjusts the HI for that specific vulnerability using CVSS. Specifically, for each target system, the HI associated with the worst-case impact is first assessed by assuming the loss of confidentiality, integrity, and availability (CIA*7). The assessment results are then agreed upon and established in advance by the relevant stakeholders. When a vulnerability is detected, the technology references publicly available vulnerability information, such as the National Vulnerability Database (NVD*8), and automatically determines its impact on CIA based on CVSS impact metrics*9, which indicate the technical severity of the vulnerability. By combining these with the predefined HI associated with the worst-case impact, the method automatically evaluates and adjusts the business impact (HI) for each vulnerability. The resulting HI is then incorporated into the overall SSVC decision process, enabling automatic determination of vulnerability response prioritization based not only on technical severity but also on the potential impact on business operations and services. This approach enables organizations to focus their operational resources on the vulnerabilities that truly need immediate attention, without requiring repeated discussions among stakeholders every time a new vulnerability is detected. In addition, since the evaluation process is consistent and transparent, the rationale behind the response priority can be more readily explained to auditors and business partners.

*6 Human Impact (HI): An SSVC decision criterion that evaluates business impact by combining the potential impact on an organization’s mission and safety.
*7 CIA: The three fundamental principles of information security: confidentiality, integrity, and availability.
*8 NVD: National Vulnerability Database. A vulnerability database operated by the U.S. National Institute of Standards and Technology (NIST).
*9 CVSS impact metrics: CVSS metrics that indicate the impact of a vulnerability on confidentiality, integrity, and availability (none, low, or high).

2. Technology for automating vulnerability management operations through integration with a ticketing system
This technology automates vulnerability management operations by integrating the results of vulnerability response decisions with a ticketing system. Specifically, through a prototype implementation, Hitachi confirmed that the entire process from vulnerability detection to task registration and deadline assignment based on SSVC decisions, including HI, through to the issuance of tickets with deadlines, can be performed automatically. This standardizes the response-request process, which was previously handled individually. It also enables the progress of vulnerability response activities to be centrally managed and visualized within the ticketing system, making it easier to identify delayed responses and operational bottlenecks. The technology thus helps prevent missed responses, reduces workload, and supports both rapid vulnerability response and the continuous improvement of vulnerability management operations.

画像: Figure 1. Comparison between the conventional vulnerability response process and the automated workflow enabled by the newly developed method

Figure 1. Comparison between the conventional vulnerability response process and the automated workflow enabled by the newly developed method

Looking ahead

Going forward, Hitachi will conduct demonstration tests using the prototype to validate the effectiveness of automated operations that achieve both rapid vulnerability response and reduced workload while providing a clear rationale for decisions, with the aim of advancing the technology toward practical deployment. Through these efforts, Hitachi aims to support organizations in strengthening their vulnerability response capabilities by enabling sustainable operations even with limited human resources. Hitachi will further enhance the technologies behind this method as part of the security infrastructure technologies supporting Lumada 3.0, aiming to realize a safe and secure digital society.

Details of these results were published in IEICE Communications Express (IEICE ComEX) in early May 2026.*10

*10 Tsuji et al., “Automating SSVC: A worst-case scenario approach for evaluating human impact of vulnerabilities,” IEICE Communications Express vol. 15, pp. 156–159, 2026.

About Lumada

For more information, use the inquiry form below to contact the Research & Development Group, Hitachi, Ltd. Please make sure to include the title of the article.

https://www8.hitachi.co.jp/inquiry/hitachi-ltd/hqrd/news/en/form.jsp

Related links

This article is a sponsored article by
''.