Introduction
In cybersecurity, we live in a world flooded with data: incident reports, threat intelligence feeds, vulnerability alerts, compliance metrics. Yet much of this information remains fragmented and unstructured, making it difficult to analyze, compare, or leverage for informed decision-making.
This lack of consistency poses a critical question: How can we make better security decisions when our data speaks different languages?
The answer lies in taxonomy, a structured approach to categorizing and describing not only incidents but also risk profiles. While several taxonomies exist in our industry, such as MITRE ATT&CK and ISO standards, one framework stands out for its versatility and practical value: VERIS (Vocabulary for Event Recording and Incident Sharing).
What is VERIS?
VERIS, originally created by Verizon, is an open and community-driven framework designed to standardize how cybersecurity incidents are recorded and shared. It is a set of metrics that provides a common language for describing security incidents in a structured and repeatable way. and learn from our experiences to better manage risk.
VERIS was developed to address one of the most critical and persistent challenges in the security industry: the lack of quality, consistent information. Without structured data, organizations struggle to analyze patterns, share insights, and improve their security posture.
VERIS solves this by helping organizations collect useful incident-related information and share it anonymously and responsibly with the wider community. The ultimate goal is to create a foundation for constructive and cooperative learning, enabling the industry to measure and manage risk more effectively.
The VERIS Model at a Glance
At its core, VERIS organizes incidents into four key dimensions:
Actors: Who initiated the incident (external, internal, partner).
Actions: What was done (hacking, malware deployment, social engineering).
Assets: What was affected (servers, endpoints, cloud environments).
Attributes: Which security properties were compromised (confidentiality, integrity, availability).
Each of these dimensions is supported by detailed enumerations for precise categorization. For example, actor motives may include Activist, Auditor, Competitor, Customer, Force Majeure, Former Employee, Nation-State, Organized Crime, and more. The same level of granularity applies to actions, assets, and attributes, ensuring consistency across reports.
From there, Impact is captured as an essential outcome in VERIS to measure business or operational consequences. This includes elements such as loss categorization, estimated loss amount, currency, and impact ratings.
This structured approach transforms unstructured narratives into clear, comparable data that can be aggregated and analyzed across thousands of incidents, enabling better insights and more accurate risk assessments.
Beyond Incident Reporting: VERIS for Risk Management
While VERIS is widely recognized as a framework for reporting, its potential goes far beyond that. When organizations code incidents using VERIS, they create a rich dataset that supports data-driven risk analysis.
Here is how VERIS can strengthen risk management:
Quantify Likelihood and Impact
Historical incident patterns inform probability estimates, making risk assessments more evidence-based and reliable.
Prioritize Security Investments
By analyzing which assets, actors, and actions appear most frequently, organizations can align resources with real-world threats.
Monitor Emerging Trends
VERIS enables tracking of patterns such as increases in phishing attacks or shifts in insider threats, providing early warning signals for strategic decisions.
Align with Risk Frameworks
VERIS complements standards like ISO 27005, NIST RMF, and FAIR by providing real incident data to inform scenarios and metrics.
The result is a shift from reactive incident response to proactive, strategic risk management.
In practice, some companies such as CSFaaS leverage VERIS not only for incident classification but also as a foundation for profiling contextual information. This approach enables deeper analysis of risk exposure, trend correlations, and predictive modeling that integrates seamlessly with cybersecurity governance programs.
Practical Applications of VERIS
Incident Documentation
Standardize how your teams record incidents to improve consistency and clarity.
Risk Dashboards and KPIs
Use VERIS-coded data to power meaningful metrics and integrate them into GRC tools or SIEM dashboards.
Threat Intelligence and Collaboration
Share structured, anonymized data with industry partners, regulators, and ISACs to enhance collective defense.
How to Get Started
You do not need a complete transformation to adopt VERIS. Start small:
Explore the VERIS GitHub Repository for schema and resources.
Explore the VERIS website https://verisframework.org/
Begin coding your incidents using the core VERIS elements.
Consider tools like the CSFaaS to simplify adoption.
Even partial implementation provides significant value by improving structure and comparability.
Final Thoughts
In an era where cyber threats evolve rapidly, structured data is essential. VERIS provides a foundation for standardization, enabling organizations to transform chaos into clarity and turn isolated incident reports into actionable intelligence.
If you are still treating incidents as standalone stories, it is time to rethink your approach. VERIS can help you bridge the gap between incident response and strategic risk management.
Have you used VERIS in your organization, either for reporting or risk analysis? What benefits or challenges have you seen?
Share your experience in the comments. Let us learn together.
