Lesson 12 — Prioritising Recommendations
Not every security recommendation carries the same level of real-world risk.
This lesson shows how to combine severity, internet exposure, attack paths, business criticality, data sensitivity and remediation effort to decide what should be fixed first.

What you will learn
This lesson explains how to rank recommendations by genuine operational risk.
Recommendation prioritisation workflow
Prioritisation decision matrix
| Factor | Why it matters | Priority signal |
|---|---|---|
| Internet exposure | Publicly reachable resources can be attacked directly. | Raise priority when an exposed service has weak configuration or vulnerabilities. |
| Attack path | The finding may form part of a realistic route to a high-value target. | Raise priority when the recommendation enables attacker movement. |
| Business criticality | Failure or compromise may affect customers, revenue or operations. | Prioritise production and mission-critical systems. |
| Data sensitivity | The resource may contain confidential, regulated or customer information. | Raise priority when compromise could expose sensitive data. |
| Identity privilege | Privileged identities can provide broad access across the environment. | Prioritise recommendations affecting administrative access or trusted identities. |
| Exploitability | Known exploitation or simple attack techniques increase likelihood. | Raise priority when exploitation is active, public or easy. |
| Remediation effort | Some fixes are quick while others need testing and change windows. | Use effort to plan sequencing, not to excuse critical exposure. |
| Secure Score impact | Score gain helps measure posture improvement. | Use as one input, not the sole priority measure. |
Risk before points
Agent Foskett investigation: “The highest score wasn’t the highest risk…”
Key takeaways
- Recommendation priority should be based on risk, not only Secure Score impact.
- Internet-facing resources deserve additional scrutiny because they can be attacked directly.
- Attack paths reveal how individual weaknesses can combine into a realistic compromise route.
- Business criticality and data sensitivity must influence priority.
- Privileged identities and excessive permissions can significantly increase impact.
- Known exploitation and ease of attack should raise urgency.
- Quick wins are valuable, but they should not displace critical remediation.
- Remediation effort helps sequence work but should not justify leaving severe exposure untreated.
- Every prioritised recommendation needs an owner, due date and validation criteria.
- The goal is measurable risk reduction, not simply a higher dashboard percentage.
Learning objectives
After completing this lesson, you should be able to rank security recommendations using risk, exposure, business context and operational effort.
Why prioritisation matters
Large environments can contain hundreds or thousands of recommendations that cannot all be addressed at once.
Severity
Severity is an important input, but it does not fully describe business impact or environmental context.
Risk level
Risk level can incorporate contextual signals such as exposure, sensitivity, connections and attack paths.
Secure Score impact
Potential score gain helps identify posture opportunities but should never be the only ranking method.
Internet exposure
Publicly reachable resources usually carry more immediate risk than isolated internal systems.
Public IP addresses
A public IP can create a direct entry point when services, ports or authentication controls are weak.
Attack paths
Attack paths show how attackers could combine weaknesses, permissions and exposed resources to reach valuable targets.
Crown jewels
Crown jewels are the systems, identities and data whose compromise would create the greatest organisational impact.
Business criticality
Production systems, customer portals and core business platforms should receive higher priority than non-critical test assets.
Data sensitivity
Resources containing personal, financial, regulated or confidential data require stronger urgency.
Identity privilege
Recommendations affecting administrators, service principals or highly privileged roles can create broad compromise risk.
Lateral movement
Weak controls that help attackers move between resources should be treated as important escalation opportunities.
Exploitability
Known exploitation, public proof-of-concept code and simple attack techniques increase urgency.
Vulnerability severity
Critical and high-severity vulnerabilities deserve attention, especially when internet exposure or privilege is present.
Active threats
Current attack activity, threat intelligence or evidence of probing should immediately influence priority.
Production versus development
Development systems may be lower priority, but only after confirming they do not expose production credentials, data or network paths.
Compliance obligations
Regulatory or contractual requirements may impose remediation deadlines independent of Secure Score.
Resource ownership
A recommendation cannot move efficiently without a clearly identified owner.
Remediation effort
Estimate time, skills, testing, downtime and dependency requirements before scheduling work.
Operational impact
A security fix can affect availability, performance or compatibility and may require formal change control.
Change windows
High-impact changes should be aligned with maintenance windows, but interim controls may be needed before then.
Compensating controls
Temporary restrictions, network isolation or monitoring can reduce risk while permanent remediation is prepared.
Quick wins
Low-effort fixes with meaningful risk reduction can create momentum and should be completed promptly.
Do not chase easy points
Easy score gains can distract teams from smaller findings that represent serious exposure.
Prioritisation tiers
A practical model can use critical, high, medium and low tiers with defined response expectations.
Critical priority
Use critical priority for active exploitation, severe internet exposure, attack paths to crown jewels or imminent business impact.
High priority
Use high priority for serious weaknesses on important systems where exploitation is plausible.
Medium priority
Use medium priority for meaningful risk that is contained, less exposed or dependent on additional conditions.
Low priority
Use low priority for limited-impact findings, isolated systems or issues already controlled by strong compensating measures.
Backlog management
Maintain a central remediation backlog with recommendation, resource, owner, priority, due date and status.
Due dates
Due dates should reflect risk and operational reality rather than a single blanket timeframe.
Service-level targets
Define expected response and remediation windows for each priority tier.
Ageing
Old high-risk recommendations should be escalated because unresolved exposure often becomes normalised.
Recurring findings
Repeated recommendations may indicate insecure templates, weak policy enforcement or configuration drift.
Resource groups
Group similar resources when the same control, owner and remediation method apply.
Bulk remediation
Bulk action can be efficient, but should be tested to avoid widespread disruption.
Dependency mapping
Understand application, identity, network and data dependencies before changing critical resources.
Threat modelling
Consider how an attacker would discover, access, exploit and move from the affected resource.
Likelihood
Estimate how likely exploitation is given exposure, controls, complexity and attacker interest.
Impact
Estimate operational, financial, legal, reputational and data consequences.
Risk equation
A simple model combines likelihood and impact, then adjusts for exposure and control strength.
Stakeholder input
Resource owners, security teams and business leaders may all be needed for accurate prioritisation.
Executive reporting
Executives need visibility into critical risks, overdue actions, attack paths and trend direction.
Technical reporting
Technical teams need affected resources, evidence, owner, required action, due date and validation steps.
Metrics
- Open critical and high-priority recommendations
- Internet-facing affected resources
- Active attack paths
- Overdue remediation actions
- Mean time to remediate
- Recurring recommendations
- Unowned findings
- Temporary compensating controls
- Risk reduction achieved
Reprioritisation
Priority should be reviewed when exposure, ownership, threat intelligence, business use or assessment data changes.
Validation
After remediation, confirm the configuration, service health, reassessment result and attack-path status.
What Agent Foskett checked
Agent Foskett checked score impact, internet exposure, vulnerability severity, privilege, attack paths and business impact.
Best practices
- Start with internet exposure and attack paths.
- Identify crown jewels and sensitive data.
- Include identity privilege and lateral movement.
- Use Secure Score as one input only.
- Balance risk with remediation effort.
- Assign an accountable owner.
- Set risk-based due dates.
- Escalate ageing high-risk findings.
- Review priorities when context changes.
- Validate actual risk reduction after remediation.
Related Agent Foskett resources
Continue learning
How should Microsoft Defender for Cloud recommendations be prioritised?
Microsoft Defender for Cloud recommendations should be prioritised using a combination of risk, severity, internet exposure, attack paths, business criticality, data sensitivity, identity privilege, exploitability and remediation effort.
Prioritising Recommendations Lesson
This Agent Foskett lesson explains risk-based prioritisation, Secure Score limitations, attack paths, crown jewels, public exposure, vulnerabilities, business impact, remediation backlogs, ownership, due dates and validation.
