incipient.ai
← Intelligence Hub

Engineering · 2026-07-21 · 9 min

A Unified Vulnerability Management Program — Discover, Detect, Prioritize, Remediate

48K+ CVEs a year, 5–8 disconnected scanners, and under 25% of findings routed to an owner. One program that unifies discovery, scoring, and remediation across the whole stack — including OT and fielded devices.

Vulnerabilities are discovered faster than most teams can act on them. Tooling is fragmented across web, infrastructure, cloud, and code; findings are duplicated, prioritization is inconsistent, and patch SLAs are missed. A single design that unifies discovery, scoring, and remediation closes the gap between detection and fix.

The numbers make the case:

MetricReality
48K+New CVEs published in 2025
60 daysAverage industry MTTR for criticals
5–8Disconnected scanning tools per enterprise
< 25%Findings auto-routed to an owner today

The opportunity: consolidate signals, score risk consistently, and close the loop with patching — at scale.

Four pillars, one continuous loop

A unified program runs as a loop, not a quarterly scan:

Discover → Detect → Prioritize → Remediate → Verify → (loop)
  • Discover — maintain a continuously updated inventory of every asset: apps, hosts, containers, cloud, code repos — and, in a manufacturer, the factory floor and fielded devices too.
  • Detect — run the right scanner against the right asset: SAST, DAST, SCA, host, container, IaC, cloud posture.
  • Prioritize — score every finding using CVSS, EPSS, exploit data, and business context — not just severity (covered in the scoring article).
  • Remediate — auto-route to owners, patch through the right channel, and verify the fix landed before closing.

The loop only works if discovery is honest. You cannot remediate an asset you never inventoried — which is exactly why shadow IT and unmanaged OT devices are where breaches start.

Coverage across the whole stack

Every layer has its own attack surface and its own scanning approach. A unified design leaves no asset class uncovered:

LayerWhat it covers
ApplicationWeb apps & APIs, mobile apps, source code, 3rd-party libraries
ContainerImages, Kubernetes clusters, image registries, runtime workloads
InfrastructureServers (Linux/Win), network devices, endpoints, hypervisors
Cloud & SaaSIaaS misconfig (AWS/Azure/GCP), IaC templates, SaaS posture, identity & access
Data & SecretsDatabases, storage buckets, hardcoded secrets, certificates & keys
PerimeterExternal attack surface, exposed services, DNS hygiene, shadow IT

In a medical-device manufacturer, two more asset classes matter as much as any above: OT on the factory floor (PLCs, HMIs, SCADA, manufacturing execution systems) and the devices and their embedded applications in the field. Both are hard to scan and harder to patch — the subject of their own article — but they must live in the same inventory, or the program has a blind spot exactly where patient safety and production uptime are on the line.

End-to-end data flow

Fragmented tools become one program when their signals land in one place:

SOURCES                         PLATFORM                    DESTINATIONS
SAST/DAST/SCA        ┐                                  ┌   Ticketing (Jira · ServiceNow)
Host & Network       ├──►  Vulnerability Mgmt  ──►      ├   Patch Ops (SCCM · Intune · Ansible)
Cloud / IaC          │        Platform                  ├   SIEM/SOAR (Splunk · Sentinel)
Container & Registry ┘        (dedupe · score · route)   └   ChatOps (Slack · Teams)
                              ▲                    │
                              └── rescan & verify ─┘  (close-loop feedback)
                    all findings persist to one Unified Control Repository

The platform deduplicates findings across tools, scores them consistently, routes each to an owner, and — critically — rescans to verify before a finding is closed. Everything persists to one repository, which becomes the single source of truth the control framework extends.

How you know it's working

Measure the program by speed, coverage, and risk reduction — not ticket volume:

KPITarget
MTTR — critical findings≤ 24h
Asset scan coverage95%
Patch deployment success98%
Open critical YoY reduction60%
SLA breach rate< 5%
KEV remediation in 7 days100%

The path to implement

  1. Build one asset inventory across the full stack — including OT and fielded devices.
  2. Feed all scanners into one platform that deduplicates and scores consistently.
  3. Auto-route every finding to a named owner through the right channel.
  4. Close the loop — rescan and verify before any finding is marked resolved.
  5. Report on speed, coverage, and risk reduction, not raw counts.

Incipient's GovPilot provides the risk scoring, routing, and audit trail; LineageLens supplies the continuously-cataloged asset graph the program depends on. The AI engine reduces the manual load on the security team.

Talk to us about unified vulnerability management →