What it is and what it does
Vulnerability management is the operating process for finding, prioritizing and resolving weaknesses. Patching is one treatment. Some equipment cannot be patched quickly, so the business may need isolation, vendor support or another compensating control. CISA: Known Exploited Vulnerabilities Catalog.
What that means for your business
A critical office server may be patched within days while a production controller needs a maintenance window and vendor validation. Both require an owner, a deadline and a documented risk decision.
Is this a baseline system?
Inventory, supported software and timely remediation of important weaknesses are baseline. Manufacturing exceptions need operations involvement because an unsafe or unplanned change can also stop production.
Will insurance ask about it?
Applications may ask about patching, vulnerability scanning and unsupported systems. Provide timeframes, coverage and exception handling rather than a simple yes answer.
See the insurance sources and how to interpret the levels.
Minimum operating position
Asset inventory, update responsibility, severity-based deadlines, failed-installation follow-up and an exception register.
When the business needs stronger protection
Authenticated scanning, internet-exposure review, prioritization using known exploitation, coordinated plant testing and executive review of overdue critical risk.
Evidence to request from IT
- Coverage report matched to the asset inventory.
- Overdue critical findings with owners and dates.
- Plant exceptions with compensating controls and approval.
What belongs in the budget
Include scanning, deployment tools, engineering validation, maintenance windows and replacement of unsupported systems. The cheapest patching service may exclude the systems carrying the largest consequence.
A documented incident
Equifax, 2017: a known web flaw was not patched
The FTC alleged that Equifax failed to patch a known application vulnerability before attackers exploited it and accessed sensitive information. FTC: Equifax security failures and settlement, 2019.
What this case shows: Finding weaknesses is not enough. The operating process must assign, verify and escalate remediation, including exceptions.
Sources and scope
The baseline and stronger-protection positions are editorial planning guidance. Confirm your company’s required controls and insurance answers with the accountable IT owner and broker.