← Back to Blog
EPSS Series · Part 3 · May 13, 2025 · 6 min read

Part 3 — From Mental Health Clinics to Tribal Casinos: EPSS in Action Across Industries

Different Industries, Same Dilemma

A mental health clinic and a tribal casino might seem worlds apart in mission and technology. One handles sensitive patient data and life-critical services; the other manages gambling systems, financial transactions, and guest information. Yet on cybersecurity, they share a common challenge: too many vulnerabilities and not enough resources to fix them all immediately.

In any industry, executives face this prioritization dilemma. The Exploit Prediction Scoring System (EPSS) can be a game-changer — an objective, data-driven way to answer the critical question: which vulnerabilities are most likely to be exploited against us?

Case Study 1: A Mental Health Provider Prioritizes Patient Data Security

A regional mental health services provider found itself swamped by software vulnerabilities across several clinics and an online patient portal. With limited IT staff and strict privacy obligations, they needed to avoid wasting effort on low-risk issues while protecting critical systems from ransomware.

The provider integrated EPSS into their vulnerability management process and set simple rules: if EPSS was above ~5%, patch immediately; below 1%, schedule for the next routine update. This data-driven triage let them fix a moderately severe web-server bug with a high 5% EPSS right away, while safely deferring a “critical” database flaw with a near-zero EPSS.

The IT team preempted attacks — notably patching a Windows server vulnerability that EPSS flagged as likely, just weeks before ransomware attackers began exploiting it in healthcare organizations elsewhere. Emergency patching dropped by over 50%, disruption to clinical operations was minimized, and the IT manager could confidently report to the board that they were addressing the vulnerabilities most likely to impact operations rather than trying to boil the ocean.

Case Study 2: A Tribal Casino Levels the Odds

A tribal casino with a resort hotel faced a flood of vulnerabilities across gaming systems, hotel infrastructure, and corporate IT. With a small security team and compliance obligations to tribal gaming authorities, the CISO sought to focus on credible threats and filter out noise.

They pulled EPSS scores into their vulnerability dashboard and set priorities: internet-facing systems above 3% EPSS got immediate attention, internal low-EPSS issues could wait. A flaw in their slot machine management software had a tiny 0.1% EPSS score and was initially logged but not urgently patched. When reports came a month later that hackers had started abusing that exact flaw at another casino, the score spiked and the team patched their machines within days — EPSS acted as an early warning system.

Over six months, the casino experienced no security breaches. Some vulnerabilities labeled “critical” by vendors remained unpatched for a while with no negative impact, because EPSS indicated they were unlikely targets — while every vulnerability EPSS rated as high risk was addressed, and none of those led to compromise.

Universal Takeaways for Executives

The Bottom Line

No matter your sector — healthcare, gaming, finance, education, or government — the core challenge is the same: prioritize the cybersecurity work that will actually prevent incidents. The mental health clinic protected patient data by fixing likely exploits first; the tribal casino safeguarded operations and customer trust by doing the same. Start by empowering your security team with EPSS insights, pilot the model on a subset of systems, and use the outcomes to build support for broader adoption.

Where Outlaw Research Labs Fits

Outlaw Research Labs is an offensive-security specialist — penetration testers, red-team operators, and vulnerability-management consultants who think like adversaries. You don’t need a giant platform, you need expert attackers on your side, armed with tomorrow’s probability data. That’s exactly what our team delivers. Ready to turn overwhelming patch lists into targeted, high-impact action? Let’s talk.