top of page
background.jpg

​

Rapid7 InsightVM | Vulnerability Management Series Issue #04 | Can You Manage a Vulnerability from Start to Finish in Your Own Environment?

Sep 29
4 min read

A critical vulnerability has been announced. The first question arrives:


"Do we have it?"


You check the scan results. Affected systems are identified. The relevant teams are contacted.


But some servers were not included in the latest scan. Authentication failed on others. It is still unclear whether the system deployed last week is in scope. In this situation, how reliable is the answer "We didn't find it"?


A vulnerability being invisible is not the same as it being absent from your environment.

The foundation of a vulnerability management capability is not just managing findings; it is understanding how reliable the visibility behind those findings really is.


First, Know What You Can See


Your organization's infrastructure is constantly changing. New servers go live. Applications move. Network segments are separated. Access rules and service account permissions are updated.


A scan that worked last month may not assess the same scope at the same depth today. That is why a completed scan is not enough on its own:


  • Were the targeted assets accessible?

  • Did credentialed checks succeed?

  • Are the results current?

  • Are any systems outside the scope?


Before asking "How many vulnerabilities did we find?", you should be able to answer "What did we assess, and how reliably?"


This is why asset discovery, Site scope, Scan Engine placement and scan access in InsightVM operations are not just setup considerations. They are operational components that need to be checked as the infrastructure changes.


Why Does Credentialed Scanning Matter?


Seeing the services a system exposes and gathering operating system and installed software information through authorized access do not provide the same depth of assessment. With appropriate permissions, credentialed scanning helps examine version, package and configuration information on the system in greater detail.


But configuring credentials does not mean authentication succeeds on every asset. A password may have changed. Permissions may have been revoked. An access rule may be blocking the scan. In such a case, interpreting a drop in findings as an improvement can be misleading.


You may be seeing fewer vulnerabilities because you are able to check fewer things.


A sound operation evaluates scan access and authentication status alongside vulnerability results.


Can You Manage a Vulnerability from Start to Finish in Your Own Environment? – Rapid7 InsightVM Vulnerability Management Series Issue #04, Zero Second

The Same Vulnerability, Different Operational Decisions


You have established visibility. You know which systems contain the critical vulnerability. Now consider how the same finding can face different conditions across different teams.


One server can be updated immediately. Another is waiting for application compatibility testing. A third requires a planned version migration because of vendor support requirements. A single CVE can lead to three different work schedules.


Prioritization now goes beyond ranking scores. Exploit intelligence, asset accessibility, business criticality and a feasible solution are considered together.


Systems with technically identical vulnerabilities do not necessarily need identical remediation plans.


Active Risk, solution-focused remediation and ownership tracking, which we covered in the first three articles, complement one another here. Each answers a different part of the same question:


Where is it present, why is it a priority, what will be done, and how will the outcome be validated?


Can You Explain the Drop on the Dashboard?


Last month, you had 8,000 findings. This month, you have 5,000. At first glance, that looks like a good result. But what caused the change?


  • Applied patches and upgrades?

  • Decommissioned systems?

  • Assets that fell out of scan scope?

  • Checks that could not be performed because authentication failed?


Looking only at the total count without making this distinction can hide the true state of operations. The value of dashboards and reporting lies as much in explaining what a number means as in displaying it.


What scope was assessed? Which risks were remediated? Which tasks were verified? Where do visibility or remediation gaps remain?


What a management meeting needs is more than a downward-trending chart. It needs an understanding of the technical outcomes behind that decline.


A Remediated Vulnerability Can Reappear


You remediated a vulnerability and verified the outcome. A few weeks later, the same finding appeared again.


A new server may have been created from an old virtual machine image. An application may have been rolled back to a previous version. A corrected configuration may have been changed again. This time, the work involves more than reopening the same ticket.


You need to identify the process that brought the vulnerability back.


While remediation fixes the current system, understanding why the vulnerability recurred helps prevent new systems from going live with the same problem. This is where continuous assessment delivers lasting value: you can recheck the outcome of work you thought was complete over time.


A Working Capability, Not Just a Report


When the next critical vulnerability is announced, your organization will need more than another scan. It will need to know that the scope is current, assess the reliability of the results, choose the right action, assign ownership and verify remediation.


The lasting organizational value of an investment in Rapid7 InsightVM lies in bringing these steps together within a repeatable operation. That way, the questions that follow "Do we have it?" do not go unanswered either.


Finding a vulnerability gives you information. Managing it from start to finish gives your organization the ability to act.


Zero Second | Rapid7 – Vulnerability Management.

Rapid7 InsightVM | Vulnerability Management Series Issue #04, prepared by Zero Second.

Comments


bottom of page