Build a remediation programme IT will actually finish
Scanning is easy. Getting patches, config changes and ownership decisions through change windows is the hard part — and it is mostly a process problem.
Security teams are rarely short of findings. They are short of a defensible way to decide what to fix, who owns it, and how to prove the exposure fell. Remediation fails in the gaps between scanners, ITSM and change boards.
Four design rules that change completion rates
- One owner per asset class. “IT” is not an owner. Name a person or a queue that can push a change.
- SLAs by risk class, not by CVE count. Days for exploitable internet-facing issues; weeks for lower-risk internal noise.
- Tickets in the systems people already open. Email PDFs of scanner exports and you have already lost.
- Exceptions with expiry. Accepted risk without a review date is deferred work wearing a suit.
What “done” should look like
A closed finding is not a closed ticket — it is a re-scan that no longer sees the condition, or a documented compensating control with an owner. Build verification into the workflow or the backlog silently refills.
Where InsightVM fits
InsightVM gives you continuous discovery and risk ranking. The programme around it — asset groups, remediation projects, ITSM integration and reporting — is what turns that into a falling exposure curve. That programme is what we run for clients who cannot staff a full VM function in-house.
Related: Managed Vulnerability Management · Infrastructure Support