Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Vulnerabilities

Managing vulnerabilities continuously

Almost every organisation scans. Few can say what share of their critical vulnerabilities was fixed within the deadline they set themselves. It is that gap — between producing reports and reducing exposure — that this case addresses.

The challenge

The report is not the result

A one-off scan has two flaws: it only sees what it was pointed at, and it photographs a moment. Whatever is missing from the inventory does not exist for it — and it is almost always in the forgotten assets that the oldest vulnerabilities sit.

The second trap is prioritising by score alone. Thousands of "critical" vulnerabilities saturate the teams, when only a fraction is genuinely exploitable in your context: reachable from outside, with no compensating control in place, and with exploit code in circulation. Sorting on that changes the order of work completely.

The third is the absence of an owned deadline. Without a remediation commitment per severity level, fixing depends on everyone's availability, and the debt accumulates without anyone being able to see it. Our role is to install that cycle and make it measurable.

What is at stake
  • Assets missing from the inventory, therefore never examined
  • Thousands of undifferentiated alerts, teams saturated
  • Internet-facing vulnerabilities fixed last
  • No remediation deadline committed to or tracked
  • Unable to demonstrate control during an audit
Diagram

A cycle, not a campaign

Vulnerability management cycle 1Assetinventory2Continuousdetection3Prioritise byexploitability4Fix withindeadline5Verify& evidence6Steer thedebtContinuous cycle
The inventory determines what is detected, exploitability determines the order, the deadline determines the outcome. Steering closes the loop and feeds the inventory.
Our approach

How we proceed

We start with the exposed perimeter, where the risk is most direct and the gain quickest.

01

Inventory and scope

A census of the assets — Internet-facing, internal, cloud — and of their owner. Without an identified owner, a vulnerability has nobody to fix it.

02

Continuous detection

Putting the coverage in place: regular discovery of the exposed perimeter, authenticated scanning internally, and integration of the sources already present rather than one more tool.

03

Prioritisation rule

Defining the sorting rule specific to your context: exposure, criticality of the asset, existence of exploit code, compensating controls in place. It produces a short, defensible queue rather than a ranking by score.

04

Deadlines and remediation

Committing to deadlines per severity level, a handling path with the teams who fix, and a documented exception procedure for what cannot be fixed.

05

Measurement and steering

Tracking the debt and adherence to deadlines, verifying the applied fixes by retest, and a dashboard readable by the executive team as well as by auditors.

Services involved

Several disciplines, a single point of contact

Offensive testing qualifies what is genuinely exploitable, integration installs the chain, monitoring keeps it alive.

Deliverables
  • Inventory of assets and their owners
  • Documented detection coverage
  • Prioritisation rule fitted to your context
  • Committed remediation deadlines and exception procedure
  • Debt dashboard and retest report
Frequently asked questions

Frequently asked questions

They answer two different questions. A penetration test demonstrates in depth what an attacker can reach at a given moment; vulnerability management maintains broad coverage over time. Either one without the other leaves a blind spot.

No, and claiming otherwise guarantees failure. The aim is that whatever is genuinely exploitable is fixed within the agreed deadline, and that the rest is known, owned and tracked. A documented exception beats an ignored line.

By looking at exposure before score. A medium-severity vulnerability on an Internet-facing server comes before a critical one on an isolated workstation. The rule is defined once with you, then applied automatically.

ISO 27001, the Swiss ICT Minimum Standard and DORA all require documented, demonstrable vulnerability management. The dashboard and the retest evidence are directly the items the auditor expects.

What share of your critical vulnerabilities is fixed on time?

If the answer does not come immediately, a stocktake of the exposed perimeter is the right starting point.