54 / 63Vulnerability Management

Vulnerability management ranked by what's being exploited, not by score

Canadian vulnerability management that ranks by real exploitation, then tracks every finding to closed.

  • CCIE Security-led team
  • Running Canadian estates since 2021
  • Evidence your auditor can file
THE WORK

Vulnerability management, three pillars, one operator.

One Canadian team runs the vulnerability scanning, ranks the exposure it finds, and proves what got closed.

  1. 1

    Estate and exposure

    What you own, what's reachable from outside, and the assets nobody documented. Discovery runs across internal ranges, external footprint, cloud accounts, and domains, so continuous vulnerability scanning has the real estate to work against instead of the asset register's version of it.

  2. 2

    Exploitability ranking

    Findings ordered by whether attackers are using the flaw right now, whether the affected asset is reachable from where an attacker sits, and what that asset is worth to you. Not by a score calculated centrally on the day the flaw was published.

  3. 3

    Tracked to closed

    Owners, dates, and a retest on every item, so vulnerability remediation ends in evidence rather than a ticket status. Whatever stays open sits on a register with the reason and the person who accepted it recorded next to it.

THE PROOF

Built to last. Evidence over promises.

Canada's Cyber Centre sent 336 pre-ransomware warnings to over 300 organisations, saving up to $18M. Those warnings land because someone acted on one specific, known exposure in time, which is the case for continuous vulnerability scanning in a sentence.

IN PRODUCTION

Exposure Canadian teams actually closed.

Our scanner produced 14,000 findings and 900 of them were rated critical, which meant nothing was critical. SMEnode cut it to 31 things attackers were actively exploiting on systems reachable from the internet. We closed 28 in six weeks. The other three had a documented reason and our auditor accepted it.

SMEnode · Engineering principle
  • CCIE Data Center
  • CCIE Security
  • CCDE Design
  • Canadian data residency
THE DEEP DIVE

Vulnerability management in Canada, made real.

Nobody drowns in vulnerabilities. They drown in a scanner's opinion of them, which isn't the same thing.

Ranking is the problem before patching is.

A scan of any real estate returns thousands of findings, and a large share arrive rated high or critical. That grading comes from a static severity score calculated when the flaw was published, with no knowledge of your network, your controls, or whether anyone has ever exploited it. Rank by that and you spend the quarter patching things nobody attacks while a reachable, actively exploited flaw sits open. Good vulnerability management is a ranking problem before it's a patching problem.

The three signals we rank on.

We rank on three things instead: whether the flaw is being exploited in the wild right now, whether the affected asset is reachable from where an attacker sits, and what that asset is worth to you. The federal picture supports working this way. Canada's Cyber Centre issued 336 pre-ransomware notifications to over 300 Canadian organisations in one year, preventing up to $18M in losses, and 13% of Canadian businesses reporting an incident named ransomware as the method (source: Canadian Centre for Cyber Security and Statistics Canada, 2024 to 2025). Those warnings work because someone acted on a specific, known exposure in time.

Closure is the second thing that fails.

Findings get assigned, a quarter passes, and nobody can say what's fixed, so the next scan produces the same list and everyone stops reading it. We track each finding to an owner and a date, verify the fix rather than trusting a ticket status, and keep an honest register of what's still open with the reason. CVE remediation counts as done when the asset has been retested, not when the ticket closes. That register is what makes the programme defensible to an auditor and, more usefully, to your own board.

Zero-Trust vault
THE METHOD

How our vulnerability scanning and remediation work runs.

Four steps, and step 01 finds things that change the conversation. Most estates contain systems nobody remembered: a forgotten test box with a public IP, a supplier's appliance, a subdomain pointing at a service that was decommissioned two years ago. Scanning what you documented tells you about the systems you were already looking after. We start by establishing what exists, because the exposure that hurts is almost always on something absent from the asset register.

  1. Step 01

    Establish the estate

    Discovery across internal ranges, external footprint, cloud accounts, and domains. You get a list, including the assets that surprise you.

  2. Step 02

    Scan continuously

    Authenticated where we can, on a cadence that matches how fast your estate changes, not on an annual calendar.

  3. Step 03

    Rank by exploitability

    Active exploitation, reachability, and asset value. A short list you can actually action, with the reasoning attached.

  4. Step 04

    Track to closed

    Owner, date, verification, and a standing register of accepted risk with the reason recorded next to it.

QUESTIONS

Vulnerability assessment questions, answered straight.

Answers first, including when a scan is the wrong purchase. An architect takes the call, not a salesperson.

An assessment is a point in time. Management is the loop. The assessment tells you what's exposed this week, which is useful once and stale by the next patch cycle. Management is discovery, ranking, remediation, verification, and doing it again on a cadence, with someone accountable for the list getting shorter. Buying an assessment when you need the loop is the most common mistake in this category.

Because on a real estate that's hundreds of items and you'd never finish. Severity scores are calculated centrally when a flaw is published and know nothing about your network. A flaw rated 9.8 on a system nobody can reach matters less than a 6.5 on your public login page that attackers are exploiting today. Ranking by exploitation and reachability turns an impossible list into a week of work.

More often than annually, less often than you'd fear. External footprint continuously, because that's what changes without anyone telling you. Internal estate monthly for most organisations, weekly if you deploy frequently or handle payment data. Frameworks set floors rather than good practice, and an annual scan mostly documents that you were compliant on one day in March.

Both are available and they're priced differently. Plenty of clients want the ranked list and their own team does the work, which is often right because their engineers know the systems. Where we hold the remediation, we verify each fix rather than closing a ticket on someone's word. What we won't do is hand over a scanner export and call it a service.

When you already know your estate is unpatched, since paying to confirm it is a delay dressed as diligence. When nobody owns remediation, because findings sitting unactioned in writing are worse than not knowing. And when the real requirement is a one-off report for a customer questionnaire, which is a smaller and cheaper piece of work. We'll say which on the first call.

A ranked list, the evidence behind each verified close, and a standing register of what's still open with the reason and the owner beside it. Accepted risk is a decision somebody signs, not a gap you hide. Your auditor gets a document saying what was fixed, what wasn't, and who agreed to carry the rest.

LET'S CONNECT

A senior engineer replies within an hour, 24/7.