New research into the most prevalent technical vulnerabilities identified in the prior year by will be presented. Findings data is derived from penetration testing by advanced-skillset consultants on funded, fixed-objective engagements, simulating worst-case adversaries/scenarios. Research methodology, key findings, and implications for managing risk will be discussed. Data will be presented on most prevalent categories, risk levels, most-exploited technologies, the ‘top n’ specific vulnerabilities, and other trends. Comparisons with external datasets including the OWASP Top 10 will be analyzed. Finally, lessons learned will be reported, covering data analysis strategies, value of ‘top n’ lists, and future research directions. You’ll come away with strategies to prioritize the most important technical risks to your organization based on empirical data, demonstrate how vulnerability statistical analysis can improve overall security program performance, and how to build a data analytics program to leverage your own vulnerability data.