Focus on the exposures that matter most — with clarity on why.
Meridian brings together exposure data from across the technology estate, applies a transparent and explainable prioritisation model, and helps teams progress material exposures through governed validation and remediation.
EXP-0417OpenSSH signal-handler race condition (regreSSHion) on dmz-sftp-01CriticalA continuous approach to exposure management.
Meridian supports a continuous, evidence-led programme across the five stages of CTEM, connecting each decision to the context produced before it.
01ScopeDefine business services, asset criticality and rules of engagement before activity begins.
02DiscoverConsolidate and deduplicate asset and finding data from ServiceNow, Qualys, Wiz, Entra, Defender EASM, CrowdStrike and Argus, while retaining provenance.
03PrioritiseAssess each finding through a deterministic model and elevate material risk as an exposure.
04ValidateValidate exposures in a controlled environment and retain evidence before remediation begins.
05MobiliseAssign accountability, initiate the SLA and verify closure through re-detection.
Integrate the technology landscape. Strengthen the risk view.
Meridian integrates information from the CMDB, security tools and public intelligence feeds to create a consolidated view of the estate while retaining record-level provenance. Connectors can be aligned to the organisation's existing technology landscape.
Every 15 minEvery 4 h, deltaHourlyEvery 2 hAfter each orchestrationEvery 30 minDailyOn commitPublic feeds provide exploitation status, prediction scores and CVSS data. Each CVE retains the corresponding KEV date and EPSS percentile, enabling teams to verify the intelligence independently.
CISA · Every 2 hFIRST.org · DailyNIST · HourlyMITRE · On releaseTransparent prioritisation. Defensible decisions.
Each score combines a CVSS base with named offsets and is capped at ten. Agents may propose relevant context, such as a route to a critical asset, but the deterministic model remains unchanged. The result is consistent, explainable and auditable.
score = clamp(base + Σ offsets, 0, 10)Base is the definition’s CVSS 3.1 score. Offsets are the rows on the right.9.0 – 10L1 · 7 days7.0 – 8.9L2 · 30 days4.0 – 6.9L3 · 90 days0 – 3.9L4 · 365 days| Factor | When it applies | Offset |
|---|---|---|
| Exploited in the wild | On CISA KEV or observed exploited in the wild. | +1.0 |
| Exploit available | A public, functional or weaponized exploit exists. | +0.5 |
| High EPSS | EPSS probability of exploitation is ≥ 15%. | +0.25 |
| Internet-facing | The asset is publicly reachable from the internet. | +0.5 |
| Business-critical asset | Asset criticality is Very High (crown jewel / Restricted data). | +1.0 |
| On a path to a crown jewel | This finding lies on an attack chain reaching a Very-High asset. | +1.0 |
| Low EPSS | EPSS probability of exploitation is below 1%. | −1.5 |
| Low-criticality asset | Asset criticality is Low. | −1.0 |
| Compensating control | A WAF, segmentation or mitigation is in place. | −1.0 |
Governed agents. Human accountability.
Each Meridian agent has a defined purpose, a bounded toolset, an autonomy tier and a complete audit trail. Structural controls establish what the agent can access and where human approval is required.
01Suggest02Approve03Auto