2026
Vulnerability Management
Choosing a Vulnerability Scanner: What to Look For
Choosing a vulnerability scanner? The criteria that matter, from asset coverage and credentialed scans to KEV and EPSS data, integrations and pricing.
Vulnerability Management
Vulnerability Management for OT and IoT Devices
How to run OT and IoT vulnerability management safely: passive discovery, vendor-approved patches, ISA/IEC 62443, segmentation and consequence-based priorities.
2025
Vulnerability Management
Living With End-of-Life Software You Can't Retire
Windows 10 support ends October 14, 2025. How to manage end-of-life software you can't retire: inventory, isolation, ESU, compensating controls and sign-off.
Vulnerability Management
Shifting Left: Catching Vulnerabilities in the CI/CD Pipeline
How to shift left with CI/CD vulnerability scanning: SAST, SCA, secrets, IaC, container and DAST checks, plus gating policies developers will actually accept.
Vulnerability Management
Taming False Positives in Vulnerability Scans
Why vulnerability scan false positives happen and how to cut them with validation, credentialed scanning, tuning and an exception process with expiry dates.
Vulnerability Management
Writing a Vulnerability Disclosure Policy
How to write a vulnerability disclosure policy: scope, safe harbor, reporting, timelines, security.txt, ISO/IEC 29147 and the EU Cyber Resilience Act.
2024
Vulnerability Management
An Emergency Patching Playbook for Zero-Days
A zero-day emergency patching playbook: triggers, triage, exposure lookup, interim mitigations, emergency change, compromise checks, validation and updates.
Vulnerability Management
Agent-Based vs. Agentless Scanning: Pros and Cons
Agent-based vs. agentless scanning compared: network scans, endpoint agents and cloud snapshot scanning, with pros, cons and why most programs use a mix.
Vulnerability Management
Edge Devices Are the New Front Door: Patching VPNs and Firewalls
Why VPNs and firewalls are prime targets, and how to handle edge device patching: firmware discipline, config backups, off-box logging and end-of-life hardware.
Vulnerability Management
The NVD Backlog: What It Means for Your Vulnerability Program
The NVD backlog leaves many new CVEs without CVSS scores or CPE data. Here's how it affects scanners and prioritization, and how to keep your program working.
Vulnerability Management
Vulnerability Management vs. Continuous Threat Exposure Management (CTEM)
Vulnerability management vs. CTEM explained: how Gartner's five-stage model differs from scan-and-patch, and how small teams can adopt it without a platform.
Vulnerability Management
Compensating Controls When You Can't Patch
Compensating controls for systems you can't patch: segmentation, virtual patching, disabling services, access limits, monitoring and documented risk acceptance.
2023
Vulnerability Management
CVSS 4.0: What's New and Should You Switch?
CVSS 4.0 brings new metrics, drops Scope and replaces Temporal with Threat. Here's what changed from CVSS 3.1 and how to plan a sensible switch to version 4.0.
Vulnerability Management
Cloud Misconfigurations Are Vulnerabilities Too
Cloud misconfigurations are vulnerabilities too. See the common ones and how to manage them with owners, SLAs, CIS Benchmarks and policy-as-code guardrails.
Vulnerability Management
Using SBOMs to Find Vulnerable Components Faster
Learn how to use an SBOM to find vulnerable components faster: generate SBOMs, store them centrally, match them against vulnerability data and apply VEX.
Vulnerability Management
Setting Remediation SLAs That Teams Actually Meet
How to set vulnerability remediation SLAs your teams will meet: risk-based tiers, clear clock rules, exceptions that expire, escalation and useful reports.
Vulnerability Management
Vulnerability Management Metrics That Matter
The vulnerability management metrics that show real progress: time to remediate by tier, SLA compliance, scan coverage, KEV fix time and risk trend.
Vulnerability Management
Using EPSS to Decide What to Patch First
EPSS estimates how likely a CVE is to be exploited in the next 30 days. Learn how to read EPSS scores and combine them with CVSS and KEV to prioritize patching.
Vulnerability Management
Managing Vulnerabilities in Container Images and Kubernetes
A practical guide to container vulnerability management: image scanning, base images, rebuilds, the CIS Kubernetes Benchmark and admission control.
Vulnerability Management
Securing Your Open-Source Dependencies
How to secure open-source dependencies with SCA, lockfiles, update bots, OpenSSF Scorecard and SLSA, and how to handle malicious packages and license risk.
2022
Vulnerability Management
Building a Patch Tuesday Process That Scales
Build a Patch Tuesday process that scales: a monthly cadence, triage, test-pilot-broad rings, out-of-band updates, reboot windows and reporting that works.
Vulnerability Management
Vulnerability Scanning vs. Penetration Testing: What's the Difference?
Vulnerability scanning vs. penetration testing: how they differ in purpose, depth, frequency and cost, when you need each, and how they work together.
Vulnerability Management
Asset Inventory: You Can't Patch What You Don't Know About
Why asset inventory is the foundation of vulnerability management, what CIS Controls v8 Controls 1 and 2 require, and how to build and reconcile an inventory.
Vulnerability Management
Risk-Based Vulnerability Management: Why CVSS Alone Isn't Enough
Risk-based vulnerability management goes beyond CVSS scores. Learn how to combine CISA KEV, EPSS, asset criticality and exposure to decide what to fix first.
Vulnerability Management
How to Use CISA's Known Exploited Vulnerabilities (KEV) Catalog
A practical guide to CISA's Known Exploited Vulnerabilities (KEV) catalog: what BOD 22-01 requires, how entries are chosen, and how any organization can use it.
2020
Vulnerability Management
Who Owns the Fix? Defining Roles in Vulnerability Management
Define roles in vulnerability management with a simple RACI: who finds, fixes, verifies and accepts risk, plus escalation paths and handling ownerless assets.
Vulnerability Management
Proving the Fix: Rescanning and Verifying Vulnerability Remediation
A closed ticket isn't proof. Learn how to verify vulnerability remediation with rescans, authenticated checks, clear closure criteria and honest reporting.
Vulnerability Management
Building an Intake Process for Vendor Security Advisories
Build an intake process for vendor security advisories: pick sources, match them to your inventory, triage, assign owners and track every advisory to closure.
Vulnerability Management
Third-Party Application Patching: The Gap in Most Patch Programs
Third-party application patching is where most patch programs fall short. Learn why browsers, readers and runtimes get missed and how to close the gap.
Vulnerability Management
What CISA's 15- and 30-Day Remediation Deadlines Can Teach Private Companies
CISA's BOD 19-02 sets 15- and 30-day remediation deadlines for internet-facing systems. Here's what private companies can borrow from the federal model.
Vulnerability Management
Managing Web Application Vulnerabilities Alongside Infrastructure Findings
Web application vulnerability management differs from patching servers. Learn how to handle DAST, SAST and SCA findings, route them to developers and retest.
Vulnerability Management
SSVC: A Decision-Tree Approach to Vulnerability Prioritization
SSVC uses decision trees, not scores, for vulnerability prioritization. Learn its decision points and outcomes, how it compares with CVSS, and a worked example.
Vulnerability Management
Patching a Remote Workforce: Keeping Laptops Updated Off the Corporate Network
Patching a remote workforce: how to keep laptops updated off the corporate network with cloud update delivery, split tunneling, deadlines and reporting.
Vulnerability Management
Building a Vulnerability Management Program From Scratch
Build a vulnerability management program from scratch: policy, asset inventory, scanning, prioritization, remediation and metrics, plus a 90-day plan.
Vulnerability Management
How to Read a CVSS v3.1 Score (and What It Doesn't Tell You)
Learn how to read a CVSS v3.1 score and its vector string metric by metric, what changed from v3.0, and what the number can't tell you about your risk.