VVenstap
Category

Vulnerability Management

13 articles

False Positives in Vulnerability Scanning: Causes and Fixes

False positives quietly undermine trust in scanning programs and waste remediation effort. Here is why they happen, how to tell them apart from real findings, and how to reduce them.

Asset Inventory: The Overlooked Foundation of Vulnerability Management

You cannot secure what you don't know exists. Asset inventory is unglamorous work that determines whether every downstream part of a vulnerability program actually works.

Why Vulnerability Counts Are a Misleading Metric

Total open vulnerability count is one of the most commonly reported security metrics and one of the least useful. Here is why, and what to measure instead.

Turning Scan Results Into Action: A Triage Framework

A scan report full of findings is not the same as a remediation plan. Here is a repeatable triage framework for turning raw results into assigned, tracked, closeable work.

Common Vulnerability Scanning Mistakes and How to Avoid Them

Most scanning programs don't fail because of bad tools — they fail because of avoidable process mistakes. A rundown of the most common ones and concrete fixes for each.

How Often Should You Run Vulnerability Scans

There is no single correct scan frequency — the right cadence depends on exposure, asset criticality, and compliance obligations. Here is a practical framework for setting it deliberately.

Authenticated vs Unauthenticated Scanning Explained

The single biggest lever for improving scan accuracy is whether you scan with credentials or without. Here is what each approach actually sees, and why relying only on one leaves real gaps.

The Case for Continuous Vulnerability Scanning

Periodic scanning leaves predictable gaps between assessments. Here is why continuous or near-continuous scanning has become the practical baseline, and what it actually requires to run well.

Understanding CVSS Scores and Their Limitations

CVSS is the industry-standard way to score vulnerability severity, but treating it as a complete risk measure leads to bad prioritization decisions. Here's what it captures and what it doesn't.

Building a Vulnerability Management Program from Zero

A step-by-step approach for organizations standing up their first formal vulnerability management program, from inventory to reporting, without over-engineering the first ninety days.

How to Prioritize Vulnerabilities When You Can't Fix Everything

Most security teams cannot remediate every finding a scan produces. Here is a practical framework for deciding what actually gets fixed first, and why severity alone is not enough.

Vulnerability Scanning vs Penetration Testing: What's the Difference

Vulnerability scanning and penetration testing get used interchangeably, but they answer different questions, run on different cadences, and require different skill sets.

What Is Vulnerability Management? A Practical Overview

A grounded look at what vulnerability management actually involves day to day, beyond the marketing definition — the recurring cycle, the roles, and where programs typically break down.