Cybersecurity

Vulnerability Management

Know what you run.

Vulnerability management is the ongoing practice of knowing what software and devices you run, which of them have known weaknesses or have fallen out of vendor support, and closing those gaps on an agreed schedule. It is a programme rather than a scan. happier IT runs it for Canadian organizations of roughly 15 to 200 people as part of managed IT.

Who it's for

The gap is almost never the scanning.

Scanning tools are cheap and good. What is usually missing is a list of what you own, an owner for each finding, and a date.

You have a scan report and nothing else. Two hundred pages, colour-coded, delivered once, with no owner and no follow-up. A scan with no process attached is a document rather than a control.

Nobody holds a current list of what you run. Not just servers: the browsers, the plugins, the free tool someone downloaded for one project, the software a department bought on a card. See shadow IT.

Something is out of support and everyone knows. A server, a database version, or an application that only runs on an operating system the vendor stopped updating. It needs a written exception with a date and a plan, not a shrug.

Patching happens when someone remembers. Windows updates largely install themselves. The gaps live in third-party software, browsers, PDF readers, remote-access tools, drivers, and in firmware on firewalls, switches and the storage box in the cupboard.

Scan versus programme

A scan tells you what is wrong today. A programme decides who fixes it, by when, what happens when something cannot be fixed, and how you evidence any of it a year later.

The scan is the cheap part, and it is the part most quotes are actually for.

What's included

What the programme consists of.

Six pieces of machinery and two pieces of paperwork. The paperwork is what auditors and insurers actually ask to see.

  • An asset inventory that stays current

    Every device, server, cloud service and significant application, with an owner and a support status. Built once from your network and your identity directory, then maintained automatically rather than re-created annually in a spreadsheet.

  • Authenticated scanning

    Scanning with credentials sees what is genuinely installed instead of inferring it from the outside. It is the difference between a list of maybes and a list of facts, and it removes most of the false findings that make people stop reading reports.

  • A patch cadence you agreed to

    Critical items on a short clock, everything else on a monthly cycle, inside a maintenance window you chose rather than one we assumed. See <a href="/glossary/patch-management/">patch management</a> for the mechanics.

  • Third-party software and firmware included

    Browsers, PDF readers, Java, conferencing clients, drivers, and the firmware on firewalls, switches, access points and network storage. This is where most real exposure sits and where most patching programmes quietly stop.

  • Risk ranking that reflects your environment

    CVSS, the common vulnerability scoring system, a 0 to 10 severity score published with each issue, is an input, not a verdict. A 9.8 on a system nothing can reach matters less than a 6 on your remote access. We rank on reachability first.

  • An exception register with review dates

    When something genuinely cannot be patched, it gets written down: what it is, why, what compensating control is in place, who accepted the risk by name, and when it comes back for review. This document is what an auditor is really asking for.

  • End-of-support tracking, a year ahead

    A rolling list of what falls out of vendor support in the next twelve months, with a rough cost against each, so replacements land in a budget cycle instead of in an emergency purchase order.

  • Evidence you can hand to somebody

    A monthly report: what was found, what was fixed inside the agreed window, what is open and why, and what changed in the exception register. Written to be forwarded to an insurer or a client without editing.

How it works

Inventory, first pass, then a rhythm.

The first pass is the only large piece of work. After that it is a monthly hour and a quarterly conversation.

  1. Find out what you run

    Discovery across the network and the cloud tenancy, reconciled against your asset list and your invoices. It routinely turns up systems nobody had on any list, which is a useful outcome on its own.

  2. Close the first wave

    The backlog is always largest at the start. We work through it by reachability rather than by score, anything internet-facing first, then anything holding data that matters, inside agreed windows, with the disruptive items scheduled rather than sprung.

  3. Run the cycle, and keep the register honest

    Monthly scanning and patching, a report you can read, and a quarterly review of the exceptions so that "we cannot patch that yet" does not silently become permanent.

What it costs

Inside managed IT. Standalone, priced per asset.

The scanning licence is a small cost. The work is the reconciliation, the scheduling and the register.

Vulnerability management is part of happier IT’s managed IT There is no version of us managing your IT that does not include it, because patching is not an optional extra on a system we are responsible for.

What genuinely costs money is what the programme finds: hardware out of support, an application that needs replacing, a server that must be rebuilt. We will put those in a budget with dates rather than presenting them as urgent purchases.

What we will not do

We will not hand you a scan output and call it a service. A PDF with 400 findings and no owner transfers work to you and calls it visibility.

If a quote you are comparing us against is priced per scan, ask who triages the results and who schedules the fixes. That answer is the actual product.

Why us for this

This is the practice a penetration test measures.

A penetration test is an examination. Vulnerability management is the year of work the examination is testing. Organizations that do the second one well find their test reports get shorter and more interesting, which is the outcome you are paying for.

happier IT’s security operations centre in Canada, staffed by our own employees, watches for signs that a known weakness is being used rather than merely present. A CVE, a Common Vulnerabilities and Exposures identifier, the public reference number for each published weakness, moves up our queue when it starts being used, not when it is published. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

Routine patching runs monthly inside a window we agree with you; anything critical goes out of band inside 72 hours, with notice before we touch it.

Go deeper

Questions

What people ask before they sign anything.

What is vulnerability management?

It is the continuous cycle of identifying what you run, finding the known weaknesses in it, deciding which ones matter in your environment, fixing them on an agreed schedule, and recording the ones you consciously chose not to fix. The word "continuous" is doing the work in that sentence, an annual scan is a snapshot, and software changes every week.

How is a vulnerability scan different from a penetration test?

A scan is an automated inventory of known weaknesses, run often and cheaply; a test is a person attempting to use them, run once or twice a year at real cost. Scanning belongs to the monthly operating rhythm and should be owned by whoever runs your IT. Testing is an independent check on that rhythm. Buying a test while nobody is scanning is paying a specialist to do a scan.

How quickly should patches be applied?

It depends on exposure, and the timescale should be written down rather than assumed. Internet-facing systems, remote access, firewalls, anything with a public login, warrant the shortest clock. Internal workstations sit comfortably on a monthly cycle. Rather than quoting a standard your organization has not adopted, we agree your windows in writing and then report against them. Where you have no standard of your own to work to, ours is monthly for routine patching and 72 hours out of band for critical items.

What if we cannot patch something?

Then it becomes an exception, which is a legitimate outcome rather than a failure. Plenty of organizations run an application the vendor no longer updates because the business genuinely depends on it. The response is to isolate it on the network, restrict who can reach it, monitor it more closely, name the person who accepted the risk, and set a date to revisit. What is not acceptable is nobody knowing it is there.

Do we still need this if we have EDR?

Yes, because they answer different questions. Endpoint detection and response notices something happening on a machine now. Vulnerability management reduces the number of ways that something could start in the first place. The first is a smoke alarm; the second is not leaving the pan unattended. Most organizations that get hurt had one of the two.

What does vulnerability management cost?

The number worth planning for is not the service, it is the replacement of whatever the first pass finds out of support.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.