Software ships with flaws. The vendor issues a patch. That cycle repeats for every operating system, application and piece of firmware you own, indefinitely. Vulnerability management is simply the process of keeping up with it deliberately rather than hoping.
It is not the same as patching. Patching is one of the outcomes. The process is knowing what you have, knowing what is wrong with it, deciding what matters, fixing that, and being able to show you did.
“The sort of things we have seen over the last six to nine months, like the big vulnerabilities and the big incidents, a lot of them come down to people not patching properly. And I know it is really boring, but it is really important.”
— Ian Levy, then Technical Director, UK National Cyber Security Centre
A six-step process that works
1. Know what you have
You cannot assess what you have not listed. That means everything with an address on your network, not just the laptops: servers, cloud services, printers, IP phones, door entry systems, CCTV, machinery, and anything a department bought directly without telling anyone.
The forgotten device is the one that matters. Firmware on a printer or a camera goes years without attention because nobody thinks of it as a computer.
2. Scan for known weaknesses
Scanning software compares the versions you are running against published vulnerability databases. If you have a server on a version with a known flaw, it says so. This can be done manually by an engineer, or continuously by a monitoring platform.
Our clients have this running automatically, so the alert reaches us rather than waiting for somebody to remember to look.
3. Rank what you find
A scan produces more findings than anyone can act on at once, and they are not equally urgent. Most tools score severity using the Common Vulnerability Scoring System, which is a reasonable starting point.
Then apply your own context. A critical flaw in software running on every machine in the business outranks a critical flaw in something one person opens twice a year. Severity and exposure are different questions.
4. Fix it
Usually that means applying an update. Sometimes it means replacing hardware the manufacturer no longer supports, which is a budget conversation rather than a technical one. Occasionally no patch exists yet, and the answer is to isolate the affected system from the rest of the network until one does.
Then scan again. A fix you have not verified is an assumption.
5. Write it down
Record when you assessed, what you found and what you did about it. This is tedious and it is the part that gets skipped, but it is what turns your effort into something you can show an insurer, an auditor or a client. It is also what makes the next round faster.
6. Book the next one
New vulnerabilities are published continuously and every update you apply can introduce new ones. A single assessment tells you about one particular afternoon. The value is in the cycle, not the scan.
Where this usually goes wrong
Not in the scanning. Scanning is the easy part, and plenty of businesses have a tool producing reports nobody reads. It goes wrong at step four, where findings need someone with the time and the authority to actually change things, and at step six, where the cycle quietly stops after the first round.
If you are considering Cyber Essentials, this process covers a good deal of what the assessment asks about. And if you want to know what an attacker would find rather than what a scanner reports, that is a penetration test — a different exercise with a different answer.
Getting started
The first step is the inventory, and it is the one you can do without buying anything. Once you know what you have, the rest becomes a routine rather than a project. We are happy to take the whole thing on, or just to help you get the first list together.
