Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Vulnerability management

Knowledge hub

Vulnerability management

The loop of finding, prioritising, fixing and checking the fix held.

What it means

Vulnerability management is the loop you keep running. Find issues, decide which to fix first, fix them, then confirm the fix held. Then start again, because the application keeps changing.

It is a process rather than a tool. Tools supply the first step. The rest is decisions, ownership and dates. OWASP splits the work into preparation, identification, reporting and remediation.

Why it matters

Most organisations handle the first step well and the last step not at all. Findings arrive in volume, some get fixed, and almost nobody goes back to confirm the fix works or that the flaw has not returned.

That is where the money leaks. You pay twice for the same work, and the list grows until reading it feels pointless. Ownership is the piece that usually goes missing. A finding assigned to a queue rather than a person waits for somebody to feel responsible, and in a busy quarter nobody does.

How it shows up

Two questions measure the loop. How long does a high severity finding take to reach a release? And when somebody marks a finding fixed, what proved it?

Keep the count of open findings visible, split by severity and by age. A single number hides the problem, and the age column starts the useful argument. Prioritise by what attackers genuinely use rather than by score alone, which is the whole point of the exploited vulnerabilities catalogue CISA maintains. Re-running the original exploit against the fix is the honest version of closed, and Cyberlop dates that capability to 16 November 2026. How the loop closes.

Questions people ask

Vulnerability management, answered

How do we prioritise when everything looks critical?

Sort by what an attacker can actually reach and what the affected system holds, not by the score alone. A critical rating on an internal tool behind a login outranks nothing.

Known exploited flaws go first. Those are the ones somebody is using today.

What is a reasonable deadline for fixing a high severity finding?

Pick numbers you will actually meet and publish them. Many teams land near a week for critical and a month for high, then adjust for how exposed the system is.

A deadline nobody hits teaches everybody to ignore deadlines, which costs more than having none.

Is vulnerability management just running a scanner?

No. A scanner produces the first step and none of the others. Prioritisation, ownership, the fix itself and confirming it held are all human decisions with dates attached.

Teams that buy a tool and skip the process end up with a longer list and the same exposure.

How do we prove a fix actually worked?

Re-run the thing that demonstrated the problem and show the before and after. A closed ticket proves somebody wrote code, not that the flaw is gone.

Cyberlop compares each run to the last and labels findings new, fixed or regressed today. Re-running the original exploit to prove a fix is dated 16 November 2026.

What do we do with findings we are not going to fix?

Accept them on purpose. Record what you accepted, the reason, who signed it off and the date you will look again.

An accepted risk is a decision. A finding quietly ageing in a backlog is the same exposure with nobody's name on it.

What proved your last fix held?

Cyberlop compares each run to the last and labels findings new, fixed or regressed. Re-running the exploit to prove a fix is dated 16 November 2026. Ask us how that will work.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.