The objective
Build a decision system, not a scanning schedule
A mature vulnerability-management programme should answer five questions: what do we own, where are the weaknesses, which findings create meaningful risk, who will treat or accept each risk, and how do we prove that exposure has been reduced?
The goal is not to eliminate every finding at once. It is to make defensible decisions, reduce the most dangerous exposure first, and improve the organisation's ability to discover and remediate risk over time.
Operating principle
01 · Lifecycle
Eight stages from discovery to governance
- 1
Identify assets. Inventory servers, endpoints, cloud workloads, applications, network devices, software, and exposed services. Assign an owner and business criticality.
- 2
Discover weaknesses. Combine authenticated scans, cloud and endpoint tooling, configuration review, vendor advisories, CVEs, threat intelligence, and targeted security testing.
- 3
Validate findings. Remove duplicates and false positives, confirm the affected component and reachability, and record the controls that alter real exposure.
- 4
Prioritise risk. Rank findings using technical severity, known exploitation, business impact, internet exposure, privilege requirements, and compliance obligations.
- 5
Plan treatment. Select patching, configuration change, service removal, segmentation, compensating controls, replacement, or time-bound risk acceptance.
- 6
Remediate safely. Coordinate testing, dependencies, maintenance windows, change approval, monitoring, and rollback with the responsible teams.
- 7
Verify closure. Rescan or validate the asset, confirm stability, retain evidence, and reopen the work if the vulnerable condition remains.
- 8
Report and govern. Track exposure, ageing, ownership, remediation performance, accepted risks, and recurring control gaps.
02 · Prioritisation
Move beyond CVSS-only queues
- Known-exploited vulnerabilities and credible active threat activity.
- Internet-facing systems and externally reachable management interfaces.
- Identity, remote-access, security-management, and other high-trust platforms.
- Assets holding sensitive data or supporting critical business services.
- Weaknesses enabling privilege escalation, credential access, or lateral movement.
- Findings that have exceeded their treatment target or exception expiry.
Every prioritised finding needs an accountable owner, an agreed due date, a treatment decision, and the evidence required for closure.
03 · Rollout
A 30-60-90 day implementation plan
| Phase | Focus | What good looks like |
|---|---|---|
| First 30 days | Establish ownership, policy, an asset baseline, initial scanning, quick wins, treatment targets, and a simple risk register. | The organisation knows its priority assets, immediate exposures, responsible owners, and closure workflow. |
| Days 31–60 | Expand authenticated coverage, enrich findings with business context, build repeatable patching and reporting, and verify completed work. | The programme operates on a measurable rhythm instead of a one-time assessment. |
| Days 61–90 | Integrate with change, incident, configuration, and risk management; automate reliable steps; challenge assumptions with independent testing. | Vulnerability management becomes an integrated, evidence-driven security process. |
Automation boundary
04 · Cadence
Scan according to exposure and change
| Environment | Risk-based starting point |
|---|---|
| Internet-facing systems | Weekly or continuous monitoring |
| Cloud workloads | Continuous posture and vulnerability monitoring |
| Internal servers | Monthly |
| Endpoints | Monthly or continuous agent-based assessment |
| Regulated environments | At least the applicable mandated frequency |
| Major change or credible new exposure | Immediate targeted assessment and verification |
Increase frequency when exposure, asset value, threat activity, or change rate increases. A schedule is a baseline, not a reason to wait when new risk appears.
05 · Exceptions
Handle difficult cases explicitly
When no patch exists
Identify affected assets, confirm exposure, apply temporary controls such as segmentation or feature restrictions, increase monitoring, hunt for exploitation evidence, and track vendor guidance until a verified fix is available.
When the business cannot patch
Turn the delay into a formal, time-bound risk decision. Record the reason, compensating controls, residual risk, accountable approver, revised date, and expiry. Reassess when threat activity or exposure changes.
When a scanner reports a false positive
Validate the version, service reachability, configuration, and scanner evidence. Retain enough evidence to explain why the finding was closed or downgraded.
06 · Measurement
Use metrics that support decisions
- Open critical and high-risk vulnerabilities.
- Mean time to remediate and treatment-target compliance.
- Vulnerability age and backlog trend.
- Asset inventory and authenticated-scan coverage.
- Failed verification and reopened findings.
- Accepted risks approaching expiry.
- Exposure trends by business service, owner, and platform.
Closing perspective