Detection & Response

Vulnerability Management VULN

A system that continuously scans your servers, devices and applications for known vulnerabilities and missing patches and ranks them by risk. The answer to "What do you have, and how exposed is it?"

When you need it

  • If you do not know exactly how many servers/devices you have
  • If you have internet-facing services
  • If your patch process is irregular

When you do not need it

  • In a very small, fully SaaS team, the vulnerability module of the endpoint agent (EDR) may be enough instead of a separate scanner.

Agent or scan engine in the internal network + scanning from the internet for the external surface. Results must be tied to the patch process (SLA).