
Threat Exposure Risk: technical risk multiplied by business risk
Contents
A CVSS 10.0 vulnerability on a private test box and a CVSS 6.0 vulnerability on the production system holding customer data are not the same problem, and the second one is closer to real harm. Technical severity and business consequence are different measurements.
Threat Exposure Risk (TER) crosses those two on a single table and lands every finding in one of five bands, S through D.
Appendix: the bands, and the axes of the map
Table 1: TER bands and deadlines
| Band | Deadline (from discovery) | Typically |
|---|---|---|
| S | 7 days | Top two TDL ranks on a high-BI asset |
| A | 14 days | Mid TDL on high BI, or top TDL on medium BI |
| B | 21 days | Top TDL on low BI, mid TDL on medium BI, TDL1 on high BI |
| C | 28 days | Mid TDL on low BI, or TDL1 on medium BI |
| D | 35 days | TDL1 on low BI |
| (none) | No deadline | Info-level findings |
Table 2: the table that turns TDL and BI into a band
| TDL \ BI | 5 (low) | 6–10 (medium) | 11–13 (high) |
|---|---|---|---|
| TDL5 / TDL4 | B | A | S |
| TDL3 / TDL2 | C | B | A |
| TDL1 | D | C | B |
Table 3: the axes of the TER map
| Axis | Meaning |
|---|---|
| Horizontal | BI score (5–13; further right means a more important asset) |
| Vertical | Effective TDL (TDL1–TDL5; higher means more severe) |
| Colour | TER band (S/A/B/C/D, chosen for colour-vision accessibility) |
How TDL is derived is covered in What is the Threat Discovery Level (TDL)?, and how BI is derived in What is a Business Impact (BI) Score?.
The values in this post were checked against PentaTrail's own routines (asm_get_band and asm_finding_sla_days) on 2026-08-17.
Visualize your attack surface with PentaTrail CTEM/ASM
From discovery to vulnerability validation and remediation — all powered by the CTEM framework.
Get Started





