
Vulnerability management is the process of identifying, assessing, and remediating vulnerabilities in software, systems, and networks before an attacker can exploit them.
A vulnerability scanner compares the software versions and configurations in your environment against databases containing known vulnerabilities. These vulnerabilities are also referred to as CVEs (Common Vulnerabilities and Exposures, a public registry of documented security flaws and vulnerabilities). The scanner/tool consults these CVEs multiple times a day because, with the rise of AI, new CVEs are added every day. This way, a vulnerability scanner keeps you continuously informed about which vulnerabilities exist within your company.
Not every vulnerability deserves the same attention. A CVSS score (Common Vulnerability Scoring System) indicates how severe a vulnerability is in theory, on a scale of 0 to 10. However, theory and practice can sometimes differ.
That is why a well-structured vulnerability management process also looks at EPSS (Exploit Prediction Scoring System). EPSS represents the probability that a vulnerability will actually be actively exploited within the next thirty days. For example: a vulnerability with a CVSS score of 6.8 that is being actively exploited takes priority over a vulnerability with a critical score that is not being actively exploited. If you treat everything with the same urgency, you effectively end up addressing nothing in time. Therefore, it is important in the vulnerability process that known vulnerabilities are compared using systems like CVSS and EPSS against how severe they are for the company itself. This is why it is important for owners to know their company's risks.
The most obvious solution is often patching. The software vendor has released an update, you install it, and you're done. But not every vulnerability has a patch, and you cannot always roll out every patch immediately. Installing updates can have an impact on your systems (for example, downtime).
Sometimes, the solution is an alternative workaround. Think of closing open ports, isolating the network from the internet, or disabling a service that no one uses. This reduces the chance that vulnerabilities will be exploited.
Most of the vulnerabilities we encounter are not exotic. They are known issues that remain unaddressed because no one is following up on them structurally.
This is by far the most common category. Software that is no longer updated, or for which updates are available but never installed. Often not out of unwillingness, but because the vulnerability management process is not set up.
A system can be fully patched and still have an open door. Default settings that were never changed, users with excessive access rights, or cloud storage that is accidentally publicly accessible. Just a handful of examples. Misconfigurations are often harder to find than a missing patch, but nowadays there is tooling that can map this out effectively. Our vulnerability management service does this as well.
Many companies make limited or no use of MDR (Managed Detection & Response) or a SOC (Security Operations Center). Often, every system has an antivirus scanner, but in this day and age, that is no longer sufficient. If a vulnerability remains unpatched or a system is still misconfigured, you at least want to know when a hacker strikes. That is why good security monitoring is essential. Our MDR service can help you with this.
This is where the confusion usually arises. A scan, a pentest, and vulnerability management may seem similar, but they serve different purposes.
A one-time scan, such as our own free cybersecurity scan, shows what your environment looks like from the outside at this moment: which CVEs are visible, whether your email can be spoofed, and which subdomains and expired certificates are lingering. Valuable as a starting point, but only a snapshot.
Vulnerability management does this continuously. New vulnerabilities emerge daily, configurations change, and employees install new software. An environment that scans clean today could contain a critical vulnerability in two weeks without anyone noticing. Unless you scan your company for this continuously.
A pentest is another tool with a different goal. A pentester actively attempts to break into a select number of systems to see how far an attacker could get in practice. This is, of course, done in consultation and with permission. This provides a company with insights that an automated scan often does not. This is because a pentest combines weak passwords with misconfigurations across different systems to try and gain access. A vulnerability scanner only sees what is misconfigured on the scanned system itself, not the relationships between all these components.
Vulnerability management covers the breadth: your entire infrastructure, continuously. A pentest dives deeper into this. In that sense, a pentest is also a snapshot of what a determined attacker could exploit with time and effort. They complement each other; one does not replace the other. Therefore, the advice is to have your company pentested at least annually and to use vulnerability management 365 days a year.
The honest answer: continuously, or as close to that as possible. Automated scans can run daily or weekly without taking up anyone's time. The National Cyber Security Centre (NCSC) lists continuous vulnerability management as one of the basic measures for digital resilience, precisely because the number of vulnerabilities grows every day.
A fixed monthly report is a realistic rhythm for most SMEs to manage by. It is enough to spot trends and set priorities without it becoming a full-time job. We approach vulnerability management by installing a piece of software on client systems, allowing us to continuously scan the environment and systems.
At MDR Premium service, a vulnerability scan for workstations and servers is included as standard, providing insight into misconfigurations on both endpoints and cloud platforms. Where possible and where permission has been granted, we automatically resolve the vulnerabilities. You also receive a monthly report detailing what was found and what we have done about it.
That fits with how we approach our security: a transparent SOC (Security Operations Center, the team that monitors your environment). You see what is being monitored, what happens when a vulnerability is found, and what it costs you.
Request a free cybersecurity scan
Want to know where you stand before looking into an ongoing process? The cybersecurity scan shows you within a minute which vulnerabilities, open ports, and expired certificates are visible from the outside for your domain. No obligations, no sales pitch afterwards.