Skip to content

Vulnerability Management

Definition

Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.

Also known asVMVulnerability management processVulnerability remediation

Updated:

Fix firstsorted by risk
1CVE-2024-21762vpn.beispiel-gmbh.atKEV
2CVE-2024-21410mail.beispiel-gmbh.atKEV
3TLS 1.0 enabledshop.beispiel-gmbh.atMedium

Visuals show sample data.

How blacklens.io covers this

Vulnerability management is the ongoing process of detecting vulnerabilities in servers, applications, network devices and cloud resources, prioritising them by risk, fixing them and evidencing the fix. The process is cyclical: new systems, new software versions and newly published vulnerabilities (CVEs) every day ensure it is never finished.

Why vulnerability management matters

A large share of successful attacks exploits vulnerabilities for which a patch already existed at the time of the attack. The gap is rarely in knowing that a vulnerability exists but in deciding which of the hundreds or thousands of findings must be fixed first and who does it. Regulations such as NIS2 and DORA and standards such as ISO 27001 therefore explicitly require a documented process for handling vulnerabilities, not just an occasional scan.

How vulnerability management works

  1. Inventory: Which systems and technologies are in use? Without a current inventory every scan remains incomplete.
  2. Detection: Network and web scans, authenticated checks on hosts, configuration audits in the cloud and matching of the technology inventory against new CVEs.
  3. Prioritisation: The CVSS score describes theoretical severity. For the order of remediation, additional questions count: is the vulnerability actually being exploited (EPSS, CISA KEV)? Is an exploit public? Is the system reachable from the internet? How critical is it for the business?
  4. Remediation: Patch, change configuration, shut down the service or accept the risk with justification. Ownership must be clear, usually via tickets in Jira or ServiceNow.
  5. Evidence: A retest confirms the fix; reports document the status for audit, management and insurers.

How blacklens.io implements vulnerability management

blacklens.io brings external, internal (Sentry agent) and cloud findings together in one workflow. The vulnerability feed comprises more than 200,000 tests with daily updates. Every finding carries EPSS score and percentile, CISA KEV status with due date and ransomware flag, exploit and PoC availability, CVSS v3/v4 and the fixed version. The status workflow (opened, in progress, snoozed, risk accepted, closed) closes findings automatically after a successful re-scan; snoozed findings reopen after 30 days. New CVEs are checked in real time against the technology inventory and verified automatically in the Threat Center.

Is the CVSS score enough for prioritisation?

No. CVSS rates severity assuming the worst case but says nothing about whether anyone is actually exploiting the vulnerability. Combining CVSS, EPSS, CISA KEV, exploit availability and reachability typically shrinks the list of urgent findings to a small fraction.

How often should you scan?

Externally reachable systems continuously, internal systems at least weekly, complemented by a real-time match of the technology inventory against newly published CVEs. A quarterly scan gives attackers far too much time.

What is the difference between vulnerability management and a pentest?

Vulnerability management is automated, broad and continuous. A penetration test is manual, deep and point-in-time: it finds logic flaws and chains vulnerabilities that no scanner detects. The two complement each other; PTaaS joins the results in one workflow.

See which of these apply to your company.

The free exposure check shows in seconds which systems, technologies and dark web traces of your company are publicly visible.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings