Skip to content

Vulnerability Management

Turn a scanner's output into a process that actually closes things.

What this is

Vulnerability management is asset discovery, authenticated scanning, prioritisation, remediation and verification, run as a cycle. The scanning is the easy part. The capability is the operating process around it: who owns a finding, what the deadline is per severity, and what happens when the deadline passes.

Most organisations that say they have a problem here do have a scanner. What they have is a report with thousands of findings, no owner per system, and no agreed definition of critical — so nothing is prioritised and nothing is closed.

When you need it

If more than one of these is true, this is usually the right place to start.

  • Scan reports produced monthly that nobody reads, because the total never falls.
  • No reliable asset inventory, so scan coverage is unknown and the report may simply be missing systems.
  • Unauthenticated scanning only, which finds a fraction of what an authenticated scan would.
  • Patching that happens when there is time, with no deadline tied to severity and no exception process.

What the scope covers

  • Asset discovery and inventory, including the external attack surface and the systems no team admits to owning.
  • Authenticated scanning across servers, endpoints, network devices and cloud workloads, with coverage stated as a number.
  • Risk-based prioritisation using exploitability and exposure, not the raw severity score.
  • Remediation workflow into your existing ticketing, with ownership, deadlines and an exception process that requires a named approver.
  • Verification and reporting: confirming a fix landed, and reporting the trend rather than the total.

What you receive

DeliverableWhat it contains
Asset inventoryDiscovered assets reconciled against your records, with ownership assigned and the unclaimed ones escalated.
Scanning designScope, credentials, schedule and the coverage figure — with what is deliberately excluded and why.
Prioritisation modelHow severity, exploitability and exposure combine into a remediation deadline, agreed with the teams who will meet it.
Operating processOwnership, SLA per severity, exception workflow, and the monthly report that shows trend and ageing rather than a raw count.

Reference architecture

A reference, not a template. Your estate decides which parts apply and in what order they arrive.

Vulnerability management reference architecture: discovery, control and visibility layersDiscovery: Asset Inventory, Authenticated Scanning, Attack Surface. Control: Risk Scoring, Patch Orchestration, Exception Workflow. Visibility: SLA Dashboards, Trend Reporting, TicketingDiscoveryAsset InventoryAuthenticated ScanningAttack SurfaceControlRisk ScoringPatch OrchestrationException WorkflowVisibilitySLA DashboardsTrend ReportingTicketing
Vulnerability management reference architecture: discovery, control and visibility layers

How success is measured

Targets are agreed with you before the work starts, and reported against for its duration.

  • Scan coverage against the reconciled asset inventory, not against the scanner's own target list.
  • Mean time to remediate by severity, and the ageing profile of what remains open.
  • Number of open exceptions and their age — the figure that shows whether the process is being used or bypassed.

Questions we are asked

  • We already scan. Why is this different?

    Scanning produces findings; management closes them. The difference is coverage you can prove, an owner per system, deadlines tied to severity, and an exception route that is recorded rather than informal. Without those, a scanner is a report generator.

  • Why does authenticated scanning matter so much?

    An unauthenticated scan sees what an unauthenticated attacker sees from the network. It cannot see installed software versions or missing patches on a hardened host, so it under-reports substantially — and the gap is invisible unless you compare the two.

  • How should we prioritise when everything is critical?

    By exploitability and exposure rather than by score. An internet-facing service with a known exploited vulnerability outranks a higher-scored issue on an internal host with no known exploit. That reordering is usually what makes the backlog tractable.

  • Is this the same as penetration testing?

    No. Vulnerability management is continuous, broad and automated. A penetration test is periodic, narrow and human, and it finds classes of problem — chained logic flaws, business logic abuse — that no scanner finds. They answer different questions.

  • What about systems we cannot patch?

    They exist in every estate: unsupported operating systems, medical or industrial equipment, applications certified against one version. They go through the exception process with compensating controls and a named approver, so the risk is accepted deliberately rather than by silence.

  • Can you run this for us?

    Yes — it is one of the capabilities most often delivered as a managed service, because the value is in running the cycle consistently rather than in any single scan. The process and the ownership model stay yours either way.

Continue reading

  • Cybersecurity

    The full domain, and the other capabilities within it.

  • Network Security

    Segmentation, next-generation firewalling and network detection designed as one control set — so a compromised host stays a compromised host.

  • Endpoint Security & XDR

    EDR deployment, detection engineering and automated containment across endpoints, servers and identities — tuned to your estate, not to a vendor demo.

Start with an assessment

The fastest way to a useful answer is a short, scoped look at what you already have.