In August 2026 CISA published its Vulnerability Review for Fiscal Years 2024 and 2025 (TLP:CLEAR). Strip away the agency prose and it makes one blunt point, again and again: the attacks that actually cause damage do not begin with an exotic zero-day. They begin with a known, already-catalogued vulnerability sitting on an internet-facing system that the defender never got around to patching. That single finding is the entire premise of external, telemetry-based cyber risk quantification — so it is worth reading closely.
~10%/yr
chance of a ransomware attack per organisation (Cyentia IRIS, cited in the review)
$3.7M
average total financial loss per ransomware incident (Cyentia IRIS)
Edge-first
VPNs, firewalls and file-transfer appliances are the review's most-cited targets
The headline: known beats novel, every time
The review's central message is that most successful compromises exploit vulnerabilities that were already public and already fixable — many of them on CISA's own Known Exploited Vulnerabilities (KEV) catalog. Zero-days exist and matter, but they are the exception. The rule is an unpatched appliance, an exposed admin panel, a forgotten subdomain still running a vulnerable version. Attackers are economically rational: they reach for the cheapest working key, and a published CVE with a public exploit is the cheapest key there is.
This is exactly why Nisura's engine is built on live exploit intelligence rather than a static scanner signature list. Every simulation is priced against the current KEV catalog and EPSS exploitation-probability scores — the same "what is actually being exploited right now" signal the review says defenders should prioritise.
Edge devices are the front door
The review repeatedly names perimeter and edge technology — VPN concentrators, firewalls, and managed file-transfer appliances — as disproportionately targeted. The logic is grim but simple: these boxes are internet-facing by design, they terminate credentials, and a single unpatched one is a straight line into the network. An organisation can run a mature internal patch programme and still be breached through the one appliance nobody owns.
That is why Nisura scans the external attack surface an attacker actually sees — subdomains, exposed services, appliance versions — rather than trusting an internal asset list to be complete. What you can't see, you can't patch; what you can't patch, an attacker will find.
The recurring weakness classes
On the engineering side, the review's top weakness categories are the familiar ones: improper input validation, memory-safety defects, broken access control, and injection. None of these are new, and that is the point. Decades-old bug classes still dominate because the incentive to fix them cheaply has never overtaken the incentive to ship. The review also flags an emerging shift: AI-assisted vulnerability discovery, which lowers the cost of finding these flaws for attacker and defender alike — and compresses the window between disclosure and exploitation.
What the numbers mean for a euro figure
The review cites Cyentia Institute IRIS data putting the annual likelihood of a ransomware attack at roughly 10% per organisation, with an average total loss near $3.7M per incident — the full cost of downtime, recovery, extortion and regulatory fallout, not just the ransom paid. Those are US-weighted figures, so we treat them as a sanity-check anchor, not the driver: Nisura's headline number is computed natively in euros against EU wages, EU margins, and EU regulatory liability (NIS2, GDPR, DORA). When your own modelled likelihood lands near that ~10% industry anchor, that is corroboration — not coincidence.
The through-line from a US federal vulnerability review to a European CFO's risk register is short: the same known, exposed weaknesses that CISA says cause most intrusions map directly onto NIS2 and GDPR liability for EU companies. Quantifying that exposure in money — before an attacker prices it for you — is the whole job.
The takeaway
CISA's data validates a specific, unglamorous discipline: find your own known, exposed vulnerabilities from the outside, weight them by what is actually being exploited, and translate the result into a figure your board can act on. That is not a novel idea — it is the idea the attackers have already priced in. See how the leading CRQ tools compare, or run your own external exposure through Nisura to get the euro number.