(but there’s a way…)
(... and make sure you read the last sentence of this piece)
What if you got a doctor's note that read "you have several conditions." No ranking. No sense of which one might kill you. Just a bill and a vague sense of dread. That's what a 20,000-line vulnerability scan report is. You hand it to a client and call it a deliverable, but you've really just handed them your own anxiety with better formatting.
That report used to make VARs money. It doesn't anymore, and here's why.
Tenable, Qualys, and Rapid7 all run direct sales teams now, right alongside their channel programs. Your client can buy the identical scanner from you, from three other resellers, or straight from the vendor. The product is the same everywhere, so the only thing left to negotiate is your margin. You didn't create that problem. You can't solve it either, not from inside a resale model built entirely around software you don't control.
So you pivot to services. You stand up a managed vulnerability practice, promise ongoing remediation, and inherit the scanner's own output as your scope of work. Run the discovery scan and you get thousands of findings, most scored "critical" by a system that has no idea what critical actually means to your client's business. Your engineers now have to work that list by hand, testing whether each patch breaks a production database, negotiating downtime windows, doing the genuinely hard and slow work that automated remediation still can't do reliably. You've sold your team's unbounded labor for a bounded monthly fee. That math only works one way, and it's not the way that keeps your engineers employed.
Here's the part that should bother you more than it probably does. CVSS was never built to answer the one question that actually matters, which is whether a given vulnerability has ever cost anyone real money. It measures theoretical severity, not documented harm. So your team burns its hours on "critical" findings that have never once appeared in an actual breach, while a handful of exposures quietly account for most of the real losses insurers have ever paid out on.
Attackers already know which vulnerabilities work. They've been telling us for years, every time a breach report names the CVE that let them in. We just haven't been listening, because CVSS was never built to hear it.
Root Evidence exists because we decided to listen. We built the FIRE (Financial Risk Exposure) taxonomy by tracking vulnerabilities against documented, verified financial losses, the ones tied to real breaches and real insurance payouts, not theoretical severity scores. Evidence Surface maps a client's actual external attack surface first, because you cannot remediate an asset nobody knew existed, and in our design-partner testing, even mature security teams were unaware of up to 40 percent of their own footprint. Evidence Scan then checks that inventory daily against the FIRE list, so engineers get a list of ten things worth fixing this week, not twenty thousand things that might matter someday. Evidence Reporting turns what your team closed into a dollar figure a CFO can read without a translator sitting next to them.
That last part is the real unlock. You can't tell a client what a software license is worth beyond its sticker price. But you can absolutely tell them what one specific exposure cost a company just like theirs, and then show them your team closed that exact exposure before it became their problem. No other VAR quoting the same scanner can say that sentence, because no other VAR has the loss data to back it up.
I don't expect Tenable or Qualys to hand back the margin they've already taken. They don't need to. Direct sales can ship a scan. It cannot ship an engineer who tests a patch against a client's production database at 2 a.m. Somebody still has to do that work, and it's not going to be the vendor.
Sell that work. Scope it to the vulnerabilities with documented losses behind them, price it like the outcome it actually is, and you'll hold a powerful position in this market.
And by the way, Root Evidence warranties your clients against breaches for up to $5,000,000.