Skip to content
Tier 1 · Critical

Critical

Stop active bleeding

Tier 1 covers conditions an attacker can act on now. The defining property is not severity score but reachability: the vulnerability is exposed to an untrusted network, exploitation is understood and tooled, and success grants meaningful access. These are the findings that show up in breach post-mortems.

The test for this tier

Could an external attacker use this to gain access, escalate privilege, or take data — today, without an insider and without a chain of unlikely events?

See the full decision procedure
Remediate within
24–72 hours
Escalation
CISO and executive sponsor notified at 48 hours
Owned by
Security operations, with a named engineering owner per finding
Budgeted from
Unplanned work — Tier 1 pre-empts sprint commitments

Where CVSS fits

Findings in this tier typically score 7.0 – 10.0 — but the score is an input, never the decision. A CVSS 9.8 with no reachability does not belong in Tier 1, and a CVSS 6.5 in the CISA KEV catalog on an internet-facing host does. How Beacon relates to CVSS, EPSS and KEV.

12 finding classes

Tier 1 findings by domain

Tier sets the deadline; domain sets the owner. Each entry links to its full definition, detection guidance, and remediation steps.

Network

NETWhat can be reached, and from where?

Identity & Access Management

IAMWho can act, and how strongly is that proven?

Data Protection

DATWhat happens to the data if everything else fails?

Processing Protection

PRCIs the compute that runs the business trustworthy and available?