How This Works

Answer 28 questions across eight areas — from asset inventory through scanning, prioritisation, remediation, and reporting. Each takes 10–20 seconds. At the end you'll get a weighted maturity score, a tier band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised vulnerability management practice; which recommendations fit your organisation is your call.

Part 1 — Asset Inventory (The Foundation)

You cannot assess what you don't know you have. A maintained spreadsheet counts; an out-of-date one doesn't.

Findings get fixed when one accountable person owns the asset. "The IT team" is not a name.

Criticality classification is what lets a medium flaw on a vital system outrank a critical flaw on a test box.

A periodic cross-check against what the network actually shows keeps the list honest and surfaces shadow assets.

Part 2 — Scanning Coverage & Cadence

A reliable cadence beats a one-off scan. Monthly is a common operating rhythm; quarterly is a reasonable floor.

Unauthenticated scans see only the outside of each system — typically a small fraction of the real vulnerability picture.

Unscanned assets are unassessed risk. Coverage is the first number a programme should be able to state.

Externally reachable systems are the first thing attackers try; they warrant a faster look.

Part 3 — Prioritisation & Triage

The KEV catalogue lists flaws confirmed as exploited in the wild. A KEV match is the strongest single "fix this now" signal available.

EPSS estimates how likely a flaw is to be exploited soon. It cuts false urgency from high-severity findings nobody is attacking.

Severity is not risk. The same flaw matters differently on an internet-facing payment server and an isolated lab machine.

Triage is what turns a scan report into a work queue. Written rules survive personnel changes; habits don't.

Part 4 — Remediation & SLAs

Even a simple framework (Critical: 30 days, High: 60, Medium: 90) creates accountability. Without one, findings age silently.

A ticket system or a disciplined spreadsheet both work. What matters is an owner, a due date, and a visible status.

"We patched it" and "the scanner no longer detects it" are different statements. Verification catches the fixes that didn't take.

SLAs become real when a breach is visible to someone senior through a defined route — not when it's discovered by accident.

Part 5 — Patch Operations

A predictable rhythm keeps the backlog flat and makes emergency work the exception rather than the norm.

When an actively exploited flaw lands, a pre-agreed fast lane beats improvising the approval chain at midnight.

Testing and rollback planning are what let you patch quickly without breaking the business — the two goals are not in conflict.

Part 6 — Cloud & Container Workloads

Cloud security posture management (CSPM) finds misconfigurations — exposed storage, weak account settings — that network scanners never see. Skip if you run no cloud: answer "Yes" to keep scoring fair.

Container fixes flow through the pipeline, not the patch window. Skip if you run no containers: answer "Yes" to keep scoring fair.

When the next Log4Shell-class flaw is disclosed, dependency visibility is the difference between answering "are we affected?" in hours or in weeks. Skip if you build no software: answer "Yes".

Part 7 — Exceptions & Risk Acceptance

Four written fields beat a silent backlog. The exception record is what answers "why was this open for a year?" when an auditor or insurer asks.

Each review renews, closes, or escalates every entry. Without it, exceptions become permanent by neglect.

Risk accepted for the long haul deserves a named, sufficiently senior signature — a record of who accepted what, and when.

Part 8 — Metrics & Governance

Even a one-page monthly summary builds the habit of visibility. What gets measured gets managed; what doesn't, drifts.

The people who fund the programme should hear about risk in risk language, not scanner language — quarterly is a common rhythm.

An annual health check is how a programme improves deliberately instead of drifting. One afternoon a year, well spent.

Answer all 28 questions to see your report.

Your Vulnerability Management Maturity Results

0 / 68
Asset inventory
0 / 10
Scanning coverage & cadence
0 / 12
Prioritisation & triage
0 / 10
Remediation & SLAs
0 / 10
Patch operations
0 / 6
Cloud & container workloads
0 / 6
Exceptions & risk acceptance
0 / 8
Metrics & governance
0 / 6

Your Recommended Priority Actions

Ready to Close These Gaps?

The free assessment shows where you stand. The paid editions add the working documents — asset register, triage decision tree, SLA tables, exception forms, board-report templates and more — so you have the artefacts, not just the score.

See the Editions + Toolkit →