Board language when the severity number goes missing
On April 15, 2026 NIST moved every backlogged CVE published before March 1, 2026 into the Not Scheduled queue, roughly 29,000 records that will not receive a CVSS score, a CPE, or a CWE going forward. NVD now enriches only entries that appear in the CISA Known Exploited Vulnerabilities catalog, software used by the federal government, or software designated critical under Executive Order 14028, per the NIST notice, and analysis puts the prioritized set at roughly 15 to 20 percent of anticipated volume (Cloud Security Alliance research note). Two months later, on June 10, 2026, CISA issued BOD 26-04 and replaced CVSS as a required federal input with an exploitation and exposure model. The severity number your board learned to ask for is missing from a growing share of the queue, and the federal government stopped requiring it.
That is where the executive translation problem stopped being a style preference. If leadership still asks for the count of criticals, most operational teams cannot honestly answer against the current queue, and the answer they can give reflects a scoring system that was already a poor proxy for business risk. Verizon's 2026 DBIR put exploitation of vulnerabilities at 31 percent of initial-access breaches, up from about 20 percent, while the surveyed population fully remediated only 26 percent of CISA KEV entries. That is a real case for changing how the queue gets talked about, and "talk about it differently" is where most program guidance stops.
What already exists, and what is still open
Boards are not new to cyber governance and the toolbox is real. The 2026 NACD-ISA Director's Handbook on Cyber-Risk Oversight, fifth edition, publishes fifteen board-level tools including a metrics rubric and an example briefing. FAIR is now a family: FAIR quantifies loss, FAIR-CAM models controls, and FAIR-MAM builds SEC-defensible materiality estimates for Item 1.05 filings, which the Corporation Finance Division's May 2024 Gerding statement narrowed to incidents disclosed within four business days of the materiality determination. Gartner's Sam Olyaei and Tom Scholtz have argued that boards should read cyber like a quarterly filing, a balance-sheet snapshot for posture and an income-statement view for expected loss (Cybersecurity Insiders coverage). The mismatch between CVSS severity and validated exploitability is well studied; Picus's 2026 vulnerability prioritization write-up reports that only about 2.3 percent of CVSS 7 and higher vulnerabilities see actual exploitation attempts, while 28 percent of exploited CVEs carry only medium scores. And per the VulnCheck 1H 2026 report, the median time from CVE publication to KEV evidence dropped from 120 days in 2025 to 80 days.
What is still open is the mile between an operational patch queue and the specific paragraph a director will read on a Tuesday. NACD publishes metric menus and briefing shapes, not a fill-in narrative. FAIR-MAM sizes a loss after materiality has been called, not the weekly translation between "twelve reachable exposures on customer authentication" and a governance sentence. Gartner's financial-format guidance is directional and paywalled, and no free reference implementation ships with it. That is the seam this playbook lives in.
The exposure statement in five parts
Every exposure the board should know about fits into five short answers, in order: what is exposed, why it matters to the business, how likely exploitation is, what has already been done, and what decision is needed today. If no decision is needed, the item collapses into a single sentence and moves to the appendix.
Four of those parts remain answerable without a CVSS score, and the fifth (exploitation likelihood) has better proxies than severity anyway: CISA KEV as evidence attackers are using the bug now, an EPSS band as a probabilistic signal about the next thirty days, a named adversary campaign against the exact technology in your stack, and a BAS-validated exploit path against your own environment that reflects your controls rather than an average. Severity was a poor language for exposure well before the NVD change, because it treated the score as the risk and the environment as noise.
Before and after, in one board sentence
Try a rewrite. A month ago the report sentence read "this month, 312 criticals, up from 287." The rewritten version reads "this month, twelve reachable exposures on customer authentication systems, eight patched, three mitigated by a compensating control and validated, one needing a maintenance-window decision today." Both are shorter than the meeting they are read in, and the first tells directors nothing they can decide.
The second names an asset class the business recognizes (customer authentication), scopes the exposure population (twelve, not three hundred), reports state, and puts one governance decision on the table. Nowhere in it is a number that only NVD can supply, which is why it works whether the underlying CVEs have a CVSS or not.
A translation table for the words boards did not learn
The five-part sentence rides on a shared vocabulary, and most director-facing decks use the wrong one. Four terms carry the weight, and each one wants a plain-English definition that a director can chair a discussion around.
- KEV. Attackers are provably using this now. Not "critical." Used.
- Internet-facing. Reachable from outside your network without being inside it first. Not "external." Reachable without a foothold.
- Compensating control. Temporary protection while the fix is scheduled, applied and verified against the specific technique. Not "mitigated." Named and tested.
- Validation. We ran the attack path against this environment and observed the outcome. Not "assessed." Executed.
Standardizing these four matters because they are already the vocabulary a director carries into audit and risk conversations. Give a board "KEV, internet-facing, compensating control in place, validated" and they can chair the discussion; give the same board a CVSS number and they will ask what it means, because a rating is a number and a number is not a decision.
What to say when there is no score
NVD's triage guarantees the question will land during the Q and A: "What is the CVSS on this?" Give the honest sentence and move on. Something like "NVD stopped scoring this class of CVE in April; here is what we know: reachable on four of our public gateways, EPSS band 0.62, no KEV listing yet, no confirmed active exploitation in our sector, and we ran BAS against the specific technique and blocked it at the WAF. Our team recommends patching in the next window and holding the compensating control." That is a complete answer without a severity number, and the board's job in that moment is not to score the bug; it is to accept, defer, or accelerate the recommended action, which the paragraph above lets them do.
Control language versus panic language
"Widespread exposure to a critical vulnerability" is panic language. "Twelve reachable exposures, eight patched, three mitigated and validated, one open pending window" is control language, and both can describe the same environment. The difference is not tone or presentation, it is whether the program actually knows the numbers it is stating: control language is what a program says when its data model tracks exposure and state, and panic language is what it says when the data model only tracks asset counts and CVE counts. If directors keep asking "how bad is it really," the words are doing too much work and the counts underneath are not enough.
The one-slide format
Every board update this playbook produces sits on one slide. A headline sentence at the top in the five-part form, at most three follow-on items in the middle written the same way (each roughly three sentences long), and the one governance decision reserved for the bottom right, awaiting a vote or explicit acceptance. CVE identifiers, CVSS scores, and per-asset tables belong in an appendix that no director should have to open. If a topic cannot survive that compression it is not ready to present; if it survives and still needs escalation, that is what the board slot is for.
Three moves for next quarter's board slot
- Take one recurring board slot next quarter and rewrite it in the five-part form. That exercise alone will surface the assets, controls, and validation gaps you rely on but have not been naming.
- Run a mock question-and-answer against the "what if they ask" list, especially the no-CVSS answer. If it takes more than a paragraph, the language is not there yet.
- Retire the appendix slide that ranks top items by CVSS, and replace it with KEV coverage and validation status on the exposures the business already cares about.
This piece owns communication. The scoring philosophy underneath it lives in same CVE, different risk, and the operating model that produces the state words above lives in remediation is an operating model, not a scanner output.
CVEasy AI's CTEM platform is the local-first control loop this playbook assumes, so the exposures, states, and validations underneath the five-part sentence come from the same environment they describe. TRIS™ is how the platform ranks that queue when the board asks which twelve.