All terms

Enterprise AI

Vulnerability management

Also known as: vuln management, patch management

Vulnerability management is the ongoing process of finding, assessing, prioritising and fixing security weaknesses across software, systems and infrastructure. It combines scanning and asset inventory with a risk based decision on what to patch first. Patch management is the remediation part of that wider cycle.

What it is

It is a continuous loop rather than a one off audit: discover assets, scan them, rank findings by exploitability and business impact, remediate or accept the risk, then verify the fix. Findings come from automated scanners, penetration tests, vendor advisories and bug reports. Good programmes track each issue to closure with an owner and a deadline.

Why it matters

Unpatched software is one of the most common routes to a breach, and a compromised website can be defaced, injected with spam links or used to serve malware, all of which damage rankings, trust and revenue. Downtime or a security incident also removes pages from search results and breaks the crawling and citation that AI assistants rely on. For regulated or enterprise buyers, a documented programme is often a condition of sale.

How it works

Practitioners maintain an asset inventory, run scheduled and event driven scans, and score findings using severity plus context such as internet exposure and known exploitation. Service level targets set how quickly each severity band must be fixed, and tickets flow into the same backlog engineering already uses. Exceptions are recorded with a compensating control and a review date.

When it applies

It applies continuously for any organisation running websites, applications, servers or endpoints, and intensifies when a widely exploited vulnerability is disclosed.

Examples

  • A CMS plugin vulnerability is disclosed and the team patches all client sites within the 48 hour window set for critical, internet facing issues.
  • A quarterly external scan finds an exposed staging environment indexed by search engines, which is then locked behind authentication.
  • A risk exception is logged for a legacy reporting server that cannot be patched, with network segmentation applied until it is retired.

How it is measured

  • Mean time to detect and mean time to remediate by severity
  • Percentage of assets scanned within the last scan cycle
  • Open vulnerabilities past their remediation service level target
  • Patch coverage rate across production systems

Related terms in Enterprise AI

Primary research · August 2026

How ChatGPT Shortlists Software Brands

An audit across 10 categories and 60 buying questions. I recorded what ChatGPT reads, throws away and links to when a buyer asks it which software to buy, and what that decides.

60
Questions asked
10
Software markets
2,680
Results read
367
Links shown
Free35 pages · PDF · 536 KBDiscovery Digest every Friday

Free download

Get the full report

35 pages · PDF · 536 KB. Enter your details and it downloads straight away.

How ChatGPT Shortlists Software Brands downloads straight away. No spam, unsubscribe anytime.