Definition · Known Vulnerabilities (CVEs)

What is Vulnerability Management?

Vulnerability management is the continuous cycle of finding security weaknesses in an organisation’s systems, deciding which ones matter most, fixing them, and verifying the fixes. It is one of the longest-established security disciplines, and a requirement of most compliance frameworks, including Cyber Essentials, ISO 27001, and PCI DSS.

The vulnerability management cycle

  1. Discover — scan systems to identify software versions and configurations
  2. Assess — match findings against known vulnerabilities (CVEs) and misconfiguration baselines
  3. Prioritise — rank by severity (CVSS), exploit availability, and asset criticality
  4. Remediate — patch, reconfigure, or apply compensating controls
  5. Verify — re-scan to confirm the fix, and repeat the cycle

The asset inventory problem

Traditional vulnerability management scans a list of known assets — which means unknown assets are never scanned. Forgotten subdomains, shadow IT, and unmanaged cloud services sit outside the programme entirely. External attack surface management addresses this by discovering internet-facing assets outside-in, feeding the inventory that vulnerability scanning depends on.

Beyond patching

Modern practice, formalised in frameworks like CTEM, extends vulnerability management beyond software patching to cover misconfigurations, exposed services, weak TLS, and identity weaknesses — exposures that never receive a CVE number but are exploited just as readily.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.