Guidance
Vulnerability management
Advice, guidance and other resources for managing vulnerabilities.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Advice, guidance and other resources for managing vulnerabilities.
Page 1 of 12

All systems contain vulnerabilities. They may take the form of a configuration issue for system administrators to resolve, software defects requiring a vendor update, or even a vulnerability which the vendor doesn’t yet know exists, for which a mitigation isn't available.
This makes vulnerability management a critical control for organisations.
An effective vulnerability management process allows your organisation to understand, and validate on a regular basis, which vulnerabilities are present in your technical estate, where updates are failing, and to actively reduce the impact of both. It also allows you to react quickly when a critical vulnerability is disclosed, by helping you understand your organisation’s exposure to it.
Managing vulnerabilities isn’t always straightforward for an organisation, partly because some may view it as a distraction from activities such as building new systems or solving pressing user needs. But vulnerability management should be seen as a process to validate (and where necessary remediate) how well your organisation’s software update process and security configuration controls are working.
This assumes that system and software updates are a ‘business as usual’ control, rather than exceptional or on demand, and we recognise that for many organisations that might not currently be the case. We know that not all organisations update by default because of concerns that updates may ‘break’ systems, or that additional testing is needed.


