Blog

Vulnerability Management

Finding, prioritizing and fixing vulnerabilities.

All posts120PCI DSS25Vulnerability Management35Security Posture25Compliance35
2026
Vulnerability Management
Choosing a Vulnerability Scanner: What to Look For
Choosing a vulnerability scanner? The criteria that matter, from asset coverage and credentialed scans to KEV and EPSS data, integrations and pricing.
April 14, 2026 · 9 min readRead →
Vulnerability Management
Vulnerability Management for OT and IoT Devices
How to run OT and IoT vulnerability management safely: passive discovery, vendor-approved patches, ISA/IEC 62443, segmentation and consequence-based priorities.
February 24, 2026 · 9 min readRead →
2025
Vulnerability Management
Living With End-of-Life Software You Can't Retire
Windows 10 support ends October 14, 2025. How to manage end-of-life software you can't retire: inventory, isolation, ESU, compensating controls and sign-off.
October 7, 2025 · 8 min readRead →
Vulnerability Management
Shifting Left: Catching Vulnerabilities in the CI/CD Pipeline
How to shift left with CI/CD vulnerability scanning: SAST, SCA, secrets, IaC, container and DAST checks, plus gating policies developers will actually accept.
September 2, 2025 · 8 min readRead →
Vulnerability Management
Taming False Positives in Vulnerability Scans
Why vulnerability scan false positives happen and how to cut them with validation, credentialed scanning, tuning and an exception process with expiry dates.
June 3, 2025 · 8 min readRead →
Vulnerability Management
Writing a Vulnerability Disclosure Policy
How to write a vulnerability disclosure policy: scope, safe harbor, reporting, timelines, security.txt, ISO/IEC 29147 and the EU Cyber Resilience Act.
March 25, 2025 · 9 min readRead →
2024
Vulnerability Management
An Emergency Patching Playbook for Zero-Days
A zero-day emergency patching playbook: triggers, triage, exposure lookup, interim mitigations, emergency change, compromise checks, validation and updates.
October 29, 2024 · 8 min readRead →
Vulnerability Management
Agent-Based vs. Agentless Scanning: Pros and Cons
Agent-based vs. agentless scanning compared: network scans, endpoint agents and cloud snapshot scanning, with pros, cons and why most programs use a mix.
August 27, 2024 · 8 min readRead →
Vulnerability Management
Edge Devices Are the New Front Door: Patching VPNs and Firewalls
Why VPNs and firewalls are prime targets, and how to handle edge device patching: firmware discipline, config backups, off-box logging and end-of-life hardware.
June 18, 2024 · 9 min readRead →
Vulnerability Management
The NVD Backlog: What It Means for Your Vulnerability Program
The NVD backlog leaves many new CVEs without CVSS scores or CPE data. Here's how it affects scanners and prioritization, and how to keep your program working.
May 7, 2024 · 8 min readRead →
Vulnerability Management
Vulnerability Management vs. Continuous Threat Exposure Management (CTEM)
Vulnerability management vs. CTEM explained: how Gartner's five-stage model differs from scan-and-patch, and how small teams can adopt it without a platform.
April 16, 2024 · 8 min readRead →
Vulnerability Management
Compensating Controls When You Can't Patch
Compensating controls for systems you can't patch: segmentation, virtual patching, disabling services, access limits, monitoring and documented risk acceptance.
January 9, 2024 · 7 min readRead →
2023
Vulnerability Management
CVSS 4.0: What's New and Should You Switch?
CVSS 4.0 brings new metrics, drops Scope and replaces Temporal with Threat. Here's what changed from CVSS 3.1 and how to plan a sensible switch to version 4.0.
November 28, 2023 · 8 min readRead →
Vulnerability Management
Cloud Misconfigurations Are Vulnerabilities Too
Cloud misconfigurations are vulnerabilities too. See the common ones and how to manage them with owners, SLAs, CIS Benchmarks and policy-as-code guardrails.
October 3, 2023 · 8 min readRead →
Vulnerability Management
Using SBOMs to Find Vulnerable Components Faster
Learn how to use an SBOM to find vulnerable components faster: generate SBOMs, store them centrally, match them against vulnerability data and apply VEX.
September 12, 2023 · 9 min readRead →
Vulnerability Management
Setting Remediation SLAs That Teams Actually Meet
How to set vulnerability remediation SLAs your teams will meet: risk-based tiers, clear clock rules, exceptions that expire, escalation and useful reports.
July 18, 2023 · 9 min readRead →
Vulnerability Management
Vulnerability Management Metrics That Matter
The vulnerability management metrics that show real progress: time to remediate by tier, SLA compliance, scan coverage, KEV fix time and risk trend.
June 6, 2023 · 8 min readRead →
Vulnerability Management
Using EPSS to Decide What to Patch First
EPSS estimates how likely a CVE is to be exploited in the next 30 days. Learn how to read EPSS scores and combine them with CVSS and KEV to prioritize patching.
May 9, 2023 · 7 min readRead →
Vulnerability Management
Managing Vulnerabilities in Container Images and Kubernetes
A practical guide to container vulnerability management: image scanning, base images, rebuilds, the CIS Kubernetes Benchmark and admission control.
March 28, 2023 · 8 min readRead →
Vulnerability Management
Securing Your Open-Source Dependencies
How to secure open-source dependencies with SCA, lockfiles, update bots, OpenSSF Scorecard and SLSA, and how to handle malicious packages and license risk.
February 7, 2023 · 9 min readRead →
2022
Vulnerability Management
Building a Patch Tuesday Process That Scales
Build a Patch Tuesday process that scales: a monthly cadence, triage, test-pilot-broad rings, out-of-band updates, reboot windows and reporting that works.
December 13, 2022 · 9 min readRead →
Vulnerability Management
Vulnerability Scanning vs. Penetration Testing: What's the Difference?
Vulnerability scanning vs. penetration testing: how they differ in purpose, depth, frequency and cost, when you need each, and how they work together.
October 25, 2022 · 8 min readRead →
Vulnerability Management
Asset Inventory: You Can't Patch What You Don't Know About
Why asset inventory is the foundation of vulnerability management, what CIS Controls v8 Controls 1 and 2 require, and how to build and reconcile an inventory.
September 13, 2022 · 8 min readRead →
Vulnerability Management
Risk-Based Vulnerability Management: Why CVSS Alone Isn't Enough
Risk-based vulnerability management goes beyond CVSS scores. Learn how to combine CISA KEV, EPSS, asset criticality and exposure to decide what to fix first.
July 12, 2022 · 9 min readRead →
Vulnerability Management
How to Use CISA's Known Exploited Vulnerabilities (KEV) Catalog
A practical guide to CISA's Known Exploited Vulnerabilities (KEV) catalog: what BOD 22-01 requires, how entries are chosen, and how any organization can use it.
June 21, 2022 · 7 min readRead →
2020
Vulnerability Management
Who Owns the Fix? Defining Roles in Vulnerability Management
Define roles in vulnerability management with a simple RACI: who finds, fixes, verifies and accepts risk, plus escalation paths and handling ownerless assets.
December 15, 2020 · 9 min readRead →
Vulnerability Management
Proving the Fix: Rescanning and Verifying Vulnerability Remediation
A closed ticket isn't proof. Learn how to verify vulnerability remediation with rescans, authenticated checks, clear closure criteria and honest reporting.
October 20, 2020 · 8 min readRead →
Vulnerability Management
Building an Intake Process for Vendor Security Advisories
Build an intake process for vendor security advisories: pick sources, match them to your inventory, triage, assign owners and track every advisory to closure.
September 8, 2020 · 8 min readRead →
Vulnerability Management
Third-Party Application Patching: The Gap in Most Patch Programs
Third-party application patching is where most patch programs fall short. Learn why browsers, readers and runtimes get missed and how to close the gap.
August 4, 2020 · 8 min readRead →
Vulnerability Management
What CISA's 15- and 30-Day Remediation Deadlines Can Teach Private Companies
CISA's BOD 19-02 sets 15- and 30-day remediation deadlines for internet-facing systems. Here's what private companies can borrow from the federal model.
June 30, 2020 · 8 min readRead →
Vulnerability Management
Managing Web Application Vulnerabilities Alongside Infrastructure Findings
Web application vulnerability management differs from patching servers. Learn how to handle DAST, SAST and SCA findings, route them to developers and retest.
May 26, 2020 · 8 min readRead →
Vulnerability Management
SSVC: A Decision-Tree Approach to Vulnerability Prioritization
SSVC uses decision trees, not scores, for vulnerability prioritization. Learn its decision points and outcomes, how it compares with CVSS, and a worked example.
April 21, 2020 · 8 min readRead →
Vulnerability Management
Patching a Remote Workforce: Keeping Laptops Updated Off the Corporate Network
Patching a remote workforce: how to keep laptops updated off the corporate network with cloud update delivery, split tunneling, deadlines and reporting.
March 24, 2020 · 8 min readRead →
Vulnerability Management
Building a Vulnerability Management Program From Scratch
Build a vulnerability management program from scratch: policy, asset inventory, scanning, prioritization, remediation and metrics, plus a 90-day plan.
February 4, 2020 · 9 min readRead →
Vulnerability Management
How to Read a CVSS v3.1 Score (and What It Doesn't Tell You)
Learn how to read a CVSS v3.1 score and its vector string metric by metric, what changed from v3.0, and what the number can't tell you about your risk.
January 21, 2020 · 9 min readRead →