Engineering · 2026-07-21 · 9 min
A Unified Vulnerability Management Program — Discover, Detect, Prioritize, Remediate
48K+ CVEs a year, 5–8 disconnected scanners, and under 25% of findings routed to an owner. One program that unifies discovery, scoring, and remediation across the whole stack — including OT and fielded devices.
Vulnerabilities are discovered faster than most teams can act on them. Tooling is fragmented across web, infrastructure, cloud, and code; findings are duplicated, prioritization is inconsistent, and patch SLAs are missed. A single design that unifies discovery, scoring, and remediation closes the gap between detection and fix.
The numbers make the case:
| Metric | Reality |
|---|---|
| 48K+ | New CVEs published in 2025 |
| 60 days | Average industry MTTR for criticals |
| 5–8 | Disconnected scanning tools per enterprise |
| < 25% | Findings auto-routed to an owner today |
The opportunity: consolidate signals, score risk consistently, and close the loop with patching — at scale.
Four pillars, one continuous loop
A unified program runs as a loop, not a quarterly scan:
Discover → Detect → Prioritize → Remediate → Verify → (loop)
- Discover — maintain a continuously updated inventory of every asset: apps, hosts, containers, cloud, code repos — and, in a manufacturer, the factory floor and fielded devices too.
- Detect — run the right scanner against the right asset: SAST, DAST, SCA, host, container, IaC, cloud posture.
- Prioritize — score every finding using CVSS, EPSS, exploit data, and business context — not just severity (covered in the scoring article).
- Remediate — auto-route to owners, patch through the right channel, and verify the fix landed before closing.
The loop only works if discovery is honest. You cannot remediate an asset you never inventoried — which is exactly why shadow IT and unmanaged OT devices are where breaches start.
Coverage across the whole stack
Every layer has its own attack surface and its own scanning approach. A unified design leaves no asset class uncovered:
| Layer | What it covers |
|---|---|
| Application | Web apps & APIs, mobile apps, source code, 3rd-party libraries |
| Container | Images, Kubernetes clusters, image registries, runtime workloads |
| Infrastructure | Servers (Linux/Win), network devices, endpoints, hypervisors |
| Cloud & SaaS | IaaS misconfig (AWS/Azure/GCP), IaC templates, SaaS posture, identity & access |
| Data & Secrets | Databases, storage buckets, hardcoded secrets, certificates & keys |
| Perimeter | External attack surface, exposed services, DNS hygiene, shadow IT |
In a medical-device manufacturer, two more asset classes matter as much as any above: OT on the factory floor (PLCs, HMIs, SCADA, manufacturing execution systems) and the devices and their embedded applications in the field. Both are hard to scan and harder to patch — the subject of their own article — but they must live in the same inventory, or the program has a blind spot exactly where patient safety and production uptime are on the line.
End-to-end data flow
Fragmented tools become one program when their signals land in one place:
SOURCES PLATFORM DESTINATIONS
SAST/DAST/SCA ┐ ┌ Ticketing (Jira · ServiceNow)
Host & Network ├──► Vulnerability Mgmt ──► ├ Patch Ops (SCCM · Intune · Ansible)
Cloud / IaC │ Platform ├ SIEM/SOAR (Splunk · Sentinel)
Container & Registry ┘ (dedupe · score · route) └ ChatOps (Slack · Teams)
▲ │
└── rescan & verify ─┘ (close-loop feedback)
all findings persist to one Unified Control Repository
The platform deduplicates findings across tools, scores them consistently, routes each to an owner, and — critically — rescans to verify before a finding is closed. Everything persists to one repository, which becomes the single source of truth the control framework extends.
How you know it's working
Measure the program by speed, coverage, and risk reduction — not ticket volume:
| KPI | Target |
|---|---|
| MTTR — critical findings | ≤ 24h |
| Asset scan coverage | 95% |
| Patch deployment success | 98% |
| Open critical YoY reduction | 60% |
| SLA breach rate | < 5% |
| KEV remediation in 7 days | 100% |
The path to implement
- Build one asset inventory across the full stack — including OT and fielded devices.
- Feed all scanners into one platform that deduplicates and scores consistently.
- Auto-route every finding to a named owner through the right channel.
- Close the loop — rescan and verify before any finding is marked resolved.
- Report on speed, coverage, and risk reduction, not raw counts.
Incipient's GovPilot provides the risk scoring, routing, and audit trail; LineageLens supplies the continuously-cataloged asset graph the program depends on. The AI engine reduces the manual load on the security team.