Agent Foskett Academy • Microsoft Defender for Cloud • Module 2 • Lesson 12

Lesson 12 — Prioritising Recommendations

Not every security recommendation carries the same level of real-world risk.

This lesson shows how to combine severity, internet exposure, attack paths, business criticality, data sensitivity and remediation effort to decide what should be fixed first.

The biggest Secure Score increase is not always the biggest reduction in risk.
Agent Foskett Prioritising Recommendations lesson
What you will learn

This lesson explains how to rank recommendations by genuine operational risk.

Risk-based priority
Attack paths
Business criticality
Remediation effort

Recommendation prioritisation workflow

Collect open recommendations ↓ Confirm assessment freshness ↓ Identify affected resources ↓ Check recommendation severity ↓ Review internet exposure ↓ Check attack-path membership ↓ Assess identity privilege and permissions ↓ Review data sensitivity ↓ Confirm business criticality ↓ Check exploitability and known vulnerabilities ↓ Estimate remediation effort and operational impact ↓ Assign priority and owner ↓ Set due date and validation criteria ↓ Track progress through closure

Prioritisation decision matrix

FactorWhy it mattersPriority signal
Internet exposurePublicly reachable resources can be attacked directly.Raise priority when an exposed service has weak configuration or vulnerabilities.
Attack pathThe finding may form part of a realistic route to a high-value target.Raise priority when the recommendation enables attacker movement.
Business criticalityFailure or compromise may affect customers, revenue or operations.Prioritise production and mission-critical systems.
Data sensitivityThe resource may contain confidential, regulated or customer information.Raise priority when compromise could expose sensitive data.
Identity privilegePrivileged identities can provide broad access across the environment.Prioritise recommendations affecting administrative access or trusted identities.
ExploitabilityKnown exploitation or simple attack techniques increase likelihood.Raise priority when exploitation is active, public or easy.
Remediation effortSome fixes are quick while others need testing and change windows.Use effort to plan sequencing, not to excuse critical exposure.
Secure Score impactScore gain helps measure posture improvement.Use as one input, not the sole priority measure.

Risk before points

Recommendation A High Secure Score gain Hundreds of low-risk development resources No internet exposure No sensitive data No attack-path involvement Recommendation B Small Secure Score gain One internet-facing production server Critical vulnerability Privileged access path Customer data Correct decision Recommendation B is addressed first because attackers target exposure and impact, not the largest score increase.

Agent Foskett investigation: “The highest score wasn’t the highest risk…”

The cloud team created a remediation sprint ↓ They sorted recommendations by Secure Score impact ↓ The largest scoring opportunity was selected first ↓ Two weeks were spent correcting low-risk development resources ↓ The Secure Score improved ↓ Management believed risk had reduced significantly ↓ Agent Foskett reviewed the remaining findings ↓ One internet-facing production VM still had a critical vulnerability ↓ The VM held a privileged service account ↓ The resource appeared in an attack path ↓ Its Secure Score contribution was small ↓ Its real-world risk was high ↓ The team changed the prioritisation model ↓ Internet exposure, exploitability and business impact were added ↓ The VM was patched and access was restricted ↓ The attack path disappeared ↓ The organisation reduced actual risk ↓ not just the number on the dashboard
The team had improved the metric before reducing the most serious exposure.

Key takeaways

  • Recommendation priority should be based on risk, not only Secure Score impact.
  • Internet-facing resources deserve additional scrutiny because they can be attacked directly.
  • Attack paths reveal how individual weaknesses can combine into a realistic compromise route.
  • Business criticality and data sensitivity must influence priority.
  • Privileged identities and excessive permissions can significantly increase impact.
  • Known exploitation and ease of attack should raise urgency.
  • Quick wins are valuable, but they should not displace critical remediation.
  • Remediation effort helps sequence work but should not justify leaving severe exposure untreated.
  • Every prioritised recommendation needs an owner, due date and validation criteria.
  • The goal is measurable risk reduction, not simply a higher dashboard percentage.

Learning objectives

After completing this lesson, you should be able to rank security recommendations using risk, exposure, business context and operational effort.

Why prioritisation matters

Large environments can contain hundreds or thousands of recommendations that cannot all be addressed at once.

Severity

Severity is an important input, but it does not fully describe business impact or environmental context.

Risk level

Risk level can incorporate contextual signals such as exposure, sensitivity, connections and attack paths.

Secure Score impact

Potential score gain helps identify posture opportunities but should never be the only ranking method.

Internet exposure

Publicly reachable resources usually carry more immediate risk than isolated internal systems.

Public IP addresses

A public IP can create a direct entry point when services, ports or authentication controls are weak.

Attack paths

Attack paths show how attackers could combine weaknesses, permissions and exposed resources to reach valuable targets.

Crown jewels

Crown jewels are the systems, identities and data whose compromise would create the greatest organisational impact.

Business criticality

Production systems, customer portals and core business platforms should receive higher priority than non-critical test assets.

Data sensitivity

Resources containing personal, financial, regulated or confidential data require stronger urgency.

Identity privilege

Recommendations affecting administrators, service principals or highly privileged roles can create broad compromise risk.

Lateral movement

Weak controls that help attackers move between resources should be treated as important escalation opportunities.

Exploitability

Known exploitation, public proof-of-concept code and simple attack techniques increase urgency.

Vulnerability severity

Critical and high-severity vulnerabilities deserve attention, especially when internet exposure or privilege is present.

Active threats

Current attack activity, threat intelligence or evidence of probing should immediately influence priority.

Production versus development

Development systems may be lower priority, but only after confirming they do not expose production credentials, data or network paths.

Compliance obligations

Regulatory or contractual requirements may impose remediation deadlines independent of Secure Score.

Resource ownership

A recommendation cannot move efficiently without a clearly identified owner.

Remediation effort

Estimate time, skills, testing, downtime and dependency requirements before scheduling work.

Operational impact

A security fix can affect availability, performance or compatibility and may require formal change control.

Change windows

High-impact changes should be aligned with maintenance windows, but interim controls may be needed before then.

Compensating controls

Temporary restrictions, network isolation or monitoring can reduce risk while permanent remediation is prepared.

Quick wins

Low-effort fixes with meaningful risk reduction can create momentum and should be completed promptly.

Do not chase easy points

Easy score gains can distract teams from smaller findings that represent serious exposure.

Prioritisation tiers

A practical model can use critical, high, medium and low tiers with defined response expectations.

Critical priority

Use critical priority for active exploitation, severe internet exposure, attack paths to crown jewels or imminent business impact.

High priority

Use high priority for serious weaknesses on important systems where exploitation is plausible.

Medium priority

Use medium priority for meaningful risk that is contained, less exposed or dependent on additional conditions.

Low priority

Use low priority for limited-impact findings, isolated systems or issues already controlled by strong compensating measures.

Backlog management

Maintain a central remediation backlog with recommendation, resource, owner, priority, due date and status.

Due dates

Due dates should reflect risk and operational reality rather than a single blanket timeframe.

Service-level targets

Define expected response and remediation windows for each priority tier.

Ageing

Old high-risk recommendations should be escalated because unresolved exposure often becomes normalised.

Recurring findings

Repeated recommendations may indicate insecure templates, weak policy enforcement or configuration drift.

Resource groups

Group similar resources when the same control, owner and remediation method apply.

Bulk remediation

Bulk action can be efficient, but should be tested to avoid widespread disruption.

Dependency mapping

Understand application, identity, network and data dependencies before changing critical resources.

Threat modelling

Consider how an attacker would discover, access, exploit and move from the affected resource.

Likelihood

Estimate how likely exploitation is given exposure, controls, complexity and attacker interest.

Impact

Estimate operational, financial, legal, reputational and data consequences.

Risk equation

A simple model combines likelihood and impact, then adjusts for exposure and control strength.

Stakeholder input

Resource owners, security teams and business leaders may all be needed for accurate prioritisation.

Executive reporting

Executives need visibility into critical risks, overdue actions, attack paths and trend direction.

Technical reporting

Technical teams need affected resources, evidence, owner, required action, due date and validation steps.

Metrics

  • Open critical and high-priority recommendations
  • Internet-facing affected resources
  • Active attack paths
  • Overdue remediation actions
  • Mean time to remediate
  • Recurring recommendations
  • Unowned findings
  • Temporary compensating controls
  • Risk reduction achieved

Reprioritisation

Priority should be reviewed when exposure, ownership, threat intelligence, business use or assessment data changes.

Validation

After remediation, confirm the configuration, service health, reassessment result and attack-path status.

What Agent Foskett checked

Agent Foskett checked score impact, internet exposure, vulnerability severity, privilege, attack paths and business impact.

Best practices

  • Start with internet exposure and attack paths.
  • Identify crown jewels and sensitive data.
  • Include identity privilege and lateral movement.
  • Use Secure Score as one input only.
  • Balance risk with remediation effort.
  • Assign an accountable owner.
  • Set risk-based due dates.
  • Escalate ageing high-risk findings.
  • Review priorities when context changes.
  • Validate actual risk reduction after remediation.

Continue learning

Next, learn how to carry out recommendation remediation using manual, scripted and policy-based methods.

How should Microsoft Defender for Cloud recommendations be prioritised?

Microsoft Defender for Cloud recommendations should be prioritised using a combination of risk, severity, internet exposure, attack paths, business criticality, data sensitivity, identity privilege, exploitability and remediation effort.

Prioritising Recommendations Lesson

This Agent Foskett lesson explains risk-based prioritisation, Secure Score limitations, attack paths, crown jewels, public exposure, vulnerabilities, business impact, remediation backlogs, ownership, due dates and validation.