Managed vulnerability management: from scan list to closed gap
ANOMAL runs vulnerability management as an ongoing service with continuous internal and external scanning. We prioritise by real exploitability rather than raw CVSS scores. We coordinate remediation with the responsible teams, including ticket ownership and SLAs, and verify remediation through re-scans. Monthly reporting delivers evidence for ISO 27001, FINMA and ISG. We quote scope and scan cadence per customer.
Why scan reports alone are not enough
A scanner produces lists with hundreds or thousands of findings per month. Without prioritisation and steering, most of it sits untouched while exactly the gaps that get exploited stay open. Vulnerability management as a service closes this loop: from discovery through prioritisation to verified remediation. Findings additionally feed as context into detection at SOC as a Service Switzerland.
Continuous discovery, internal and external
- External scanning of the publicly reachable attack surface, complementing the continuous monitoring under Attack Surface Management.
- Internal scanning of servers, clients, network devices and, where sensible, cloud workloads.
- Authenticated scanning for reliable results beyond a purely network-based view.
- Asset reconciliation so new systems are automatically pulled into scope.
Prioritisation by real exploitability
A raw CVSS score says little about whether a gap is actively exploited or even reachable. ANOMAL therefore prioritises using several combined signals.
- EPSS (Exploit Prediction Scoring System) as a probability of actual exploitation.
- CISA KEV (Known Exploited Vulnerabilities) as a signal for already observed attacks.
- Exposure: is the system internet-reachable, internally segmented or isolated?
- Business context: system criticality, affected data, proximity to regulated processes.
The goal is a short, reliable list of findings that carry risk.
Remediation steering with your teams
- Assignment of every prioritised finding to an owner in your organisation.
- Agreed SLAs per criticality level, monitored by ANOMAL.
- Ticket ownership in your existing system (e.g. common ITSM platforms). All tracking stays in this system.
- Escalation path for overdue critical findings.
- Verification re-scan after reported remediation, before a finding counts as closed.
Reporting and audit evidence
Monthly reporting shows open and closed findings, SLA adherence and trends over time. Audits regularly require these records for ISO 27001, FINMA requirements and ISG reporting duty. We provide documented evidence.
From gap list to detection context in the SOC
Known, still-open vulnerabilities provide valuable context for SOC operations. In SOC as a Service Switzerland, we prioritise exploit attempts against known critical vulnerabilities above identical attempts against patched systems. Vulnerability management provides a list of findings and active input for 24/7 detection.
How this compares to neighbouring topics
| Service | Focus | Rhythm |
|---|---|---|
| Vulnerability Management | Systematically finding, prioritising and getting known vulnerabilities (CVEs) remediated. | Continuous, with monthly reporting. |
| Penetration testing | Targeted, manual attack attempt on a defined scope, including chaining multiple vulnerabilities. | Point-in-time, see Penetration testing Switzerland. |
| Attack Surface Management | Continuous view of the externally visible, often unknown attack surface. | Ongoing, see Attack Surface Management. |
| Red Team | Realistic, covert attack over an extended period including detection and response testing. | Project-based, see Red Team Assessment. |
We quote scope, scan frequency and included systems individually; we offer no fixed standard package.
Frequently asked questions
Isn't a vulnerability scan alone enough?
A scan delivers a list. Without prioritisation by EPSS, KEV, exposure and business context, and without remediation steering, the value stays low. The service therefore covers the full loop through to the verified re-scan.
Who remediates the identified vulnerabilities?
Your IT team or providers remediate the vulnerabilities. ANOMAL prioritises, assigns owners, monitors SLAs and verifies remediation via re-scan.
How does this differ from a penetration test?
Vulnerability management is an ongoing service for known vulnerabilities; a penetration test is a point-in-time, manual attack attempt. They complement each other. See [Penetration testing Switzerland](/en/services/penetration-testing-switzerland).
What evidence do we get for audits?
Monthly reporting documents open and closed findings plus SLA history. You can use these records for ISO 27001, FINMA and the ISG reporting duty.
What does managed vulnerability management cost?
Costs depend on scope and scan cadence. We provide a quote for each customer. You can find general cost context on [SOC cost Switzerland](/en/soc/soc-cost-switzerland).
Related terms
- Vulnerability Management Vulnerability management is the ongoing process of finding weaknesses, assessing them by risk, and verifying their remediation.
- CVE CVE is the global directory of publicly known security vulnerabilities where each vulnerability receives its own identifier.
- Exploit An exploit is code or a method that deliberately exploits a security vulnerability to compromise a system or gain higher privileges.
- Telemetry Pipeline A telemetry pipeline collects, filters, and routes logs and events before they are analysed in the SIEM or SOC.