# Managed vulnerability management

> Find the hole before anyone uses it.

Vulnerability management finds every weakness in your estate and tells you which one to close first.

**Key points**

- Continuous scanning, not an annual snapshot
- Every finding validated by an analyst before it reaches you
- Ranked by what is reachable, and tracked to a proven fix

## We look everywhere a weakness can open

### Network and endpoints

Servers, workstations and network devices, internal and external, with authenticated scans where they tell you more than an outside view can.

### Applications and APIs

Your public web estate, its business logic, and the REST and GraphQL interfaces behind it that rarely appear on an asset list.

### Cloud and containers

AWS, Azure and Google configuration alongside the images you ship, so a weakness introduced by a deployment is found in days rather than at the next audit.

## What we scan, and how often

- **External perimeter** — Everything reachable from the internet, weekly — including the forgotten host, the stale DNS record and the management interface that was only ever meant to be reachable from the office.
- **Internal network and endpoints** — Servers, workstations and network devices scanned with credentials, so the answer is what is actually installed rather than what a service banner claims.
- **Web applications and APIs** — The public web estate and the interfaces behind it, tested for their own class of weakness rather than for missing patches — which is the half a patch cycle never reaches.
- **Cloud accounts** — Instances, images and managed services across all three providers, including the hosts a deployment created last week that nobody added to an asset list.
- **Container images** — What you ship, checked in the registry and again in the pipeline, so a base image three versions behind is caught before it is running in production.
- **Newly published weaknesses** — When something serious is published we do not wait for the next cycle. Your estate is queried against it that day, and you hear from us only if it applies to you.
- **The fix, afterwards** — Nothing is closed on our say-so. A follow-up scan proves it, and anything that cannot be fixed is recorded with whatever you are doing instead.

## How it runs

1. **Discover** — We map every asset first, then scan continuously — run on Qualys, which we license and operate — so new systems and new weaknesses surface as they appear rather than when somebody remembers to look.
2. **Validate and rank** — An analyst confirms each finding and ranks it by what is reachable and what it would reach. A critical on an isolated test box does not outrank a medium on your gateway.
3. **Close** — You get practical fix guidance in the order it is worth working through, and nothing is marked resolved until a follow-up scan proves it.

## What you get

**One ranked list, and proof each line is closed** — Every finding with what it affects, what it would take to reach it, and what closes it — ordered by what an attacker gets to first rather than by scanner severity. The list is the same one we work from, so there is no second version where the numbers are better.

---

Canonical: https://centio.bg/uslugi/vulnerability-management