Streamlining
Vulnerability Management
A technology firm managing 10,000+ endpoints across on-premise and cloud was losing the vulnerability management battle — not because of missing tools, but because of broken governance, inconsistent reporting, and scan scheduling chaos. Softenger restructured the entire VA-VM program from the ground up.
VA-VM Optimization – 10,000+ Endpoints
10,000+ endpoints — and a VA-VM program that wasn’t keeping pace
Vulnerability management at scale doesn’t fail because organizations lack scanning tools. It fails because the operational discipline around those tools breaks down — remediation progress doesn’t get tracked, SLA commitments drift, reports become inconsistent, scans collide with production operations, and open findings accumulate faster than they get closed.
That was the situation for this technology firm. Across 10,000+ endpoints spanning on-premise infrastructure and cloud environments, the vulnerability program existed but wasn’t functioning as a managed program. Softenger was engaged to restructure it — adding governance, prioritization, automation, real-time visibility, and controlled execution.
Improve tracking of remediation progress and SLA compliance. Address reporting inconsistencies, inventory inaccuracies, and scan scheduling conflicts. Enhance the management of open and closed findings across multiple clients and assets.
Remediation Tracking and SLA Compliance Had Broken Down
Open vulnerabilities were being identified but not systematically tracked to remediation closure. SLA commitments were being missed — and nobody had clear visibility into where the remediation effort stood at any given point.
Remediation Tracking · SLA ComplianceReporting Was Inconsistent and Scans Were Creating Conflicts
Reports to different stakeholders and clients weren’t standardized — creating confusion about actual risk exposure. Scan scheduling was uncontrolled, causing conflicts with production systems and reducing the reliability and completeness of scan results.
Reporting Consistency · Scan SchedulingManaging Open and Closed Findings Across Multiple Clients Was Unmanageable
A multi-client VA-VM environment means each client’s findings need to be tracked separately — open findings, closed findings, exceptions, and risk acceptances all managed per-client. Without automation and proper tooling, this becomes an administrative burden that overwhelms the team.
Multi-Client Management · Findings InventoryFive methods — each one closing a specific gap
The approach wasn’t a single fix. It was five parallel methods, each targeting one of the operational breakdowns that had allowed the vulnerability backlog to accumulate. Governance addressed accountability. Prioritization addressed focus. Automation addressed reporting consistency. Dashboards addressed visibility. CRQ addressed scan chaos.
The order of deployment mattered. Governance came first — bi-weekly calls established accountability before automation was deployed, so that remediation owners were already engaged when reports started arriving. Asset prioritization was set simultaneously, ensuring the first wave of remediation effort landed on the highest-risk assets: PCI systems and IDMZ servers.
Automated reporting and dashboards followed. Splunk and Rapid7 gave every stakeholder a real-time view of the same data — eliminating the reporting inconsistencies that had previously allowed different teams to work from different pictures of the risk landscape.
Governance Calls
Bi-weekly structured calls to monitor remediation progress, enforce SLA accountability, and maintain consistent engagement from asset owners and stakeholders across all client environments.
- Bi-weekly cadence — fixed schedule, mandatory attendance from remediation owners
- Structured agenda: open findings review, SLA compliance status, escalations
- Remediation progress tracked meeting-to-meeting — no drift between calls
- Accountability assigned per finding per owner — no ambiguity about who closes what
- Minutes and action items documented and distributed post-call
Asset Prioritization
High-risk assets identified and placed at the front of the remediation queue — ensuring the most dangerous vulnerabilities in the most critical environments were addressed before lower-priority findings.
- PCI systems prioritized — cardholder data environments treated as critical tier
- IDMZ servers elevated — internet-facing demilitarized zone assets addressed first
- Risk-tiered asset classification applied across 10,000+ endpoint inventory
- Remediation sequencing aligned to risk tier — not first-reported or easiest-to-fix
- Critical asset SLAs set separately from standard-tier SLAs
Automated Reporting
Custom scripts developed to generate client-specific reports automatically — eliminating the manual reporting effort that was creating inconsistencies and delays.
- Custom scripts generating per-client report formats automatically
- Consistent data — same source, same metrics, same definitions across all reports
- Scheduled delivery — reports available before governance calls, not after
- Open and closed findings clearly differentiated per client per report cycle
Splunk & Rapid7 Dashboards
Real-time dashboards built in Splunk and Rapid7 giving all stakeholders a live view of vulnerability status, remediation progress, and SLA compliance across the full endpoint environment.
- Splunk dashboards for aggregated vulnerability data visualization and trending
- Rapid7 for vulnerability scanning results, risk scoring, and finding management
- Single-pane view across all clients and asset types — no siloed reports
- SLA compliance tracking visible in real time — no waiting for report cycle
Controlled Scanning — CRQ Process
A formal Change Request (CRQ) process implemented for all vulnerability scan scheduling — eliminating the conflicts with production systems that had been undermining scan completeness and reliability.
- CRQ approval required before any scan is scheduled — no ad-hoc scanning
- Scan windows coordinated with production operations and maintenance schedules
- Conflict elimination — scans no longer collide with business-critical processes
- Scan coverage and completeness measurably improved under controlled scheduling
Splunk and Rapid7 — what each one does in this program
Both tools were already present in many VA-VM environments. What Softenger added was the operating model that made them produce consistent, actionable data instead of disconnected scan results and manual exports.
Data Aggregation & Visualization
Splunk served as the centralized intelligence layer — aggregating vulnerability data from across the environment and turning it into real-time dashboards that gave every stakeholder an accurate, consistent view of the risk landscape.
- Real-time vulnerability tracking dashboards across all clients and assets
- SLA compliance monitoring — open findings against committed closure dates
- Trending analysis — attack surface trajectory over time
- Custom views per client — each client sees their own data, not the full environment
- Alert generation for findings approaching SLA breach
Vulnerability Scanning & Risk Scoring
Rapid7 was the scanning and finding management engine — providing the vulnerability assessments, risk scores, and findings inventory that fed the governance process, automated reports, and Splunk dashboards.
- Vulnerability scanning across 10,000+ endpoints — on-premise and cloud
- Risk scoring and severity classification per finding per asset
- PCI and IDMZ-specific scan profiles for priority asset environments
- Finding lifecycle management — open, in-remediation, closed, excepted
- Scan scheduling integration with CRQ process for controlled execution
Four outcomes — and what each one means operationally
The 54% attack surface reduction is the headline. The outcomes behind it explain why it’s sustainable — not a one-time scan result, but a program change.
54% Reduction in Attack Surfaces
Prioritized remediation of high-risk findings — led by PCI systems and IDMZ servers — drove a 54% reduction in the total attack surface exposed across the environment.
Strengthened Defences Against Unauthorized Access
Systematic vulnerability closure — tracked to completion through governance calls and Splunk dashboards — measurably reduced exposure to unauthorized access and active cyber threats across the client’s infrastructure.
Data in Transit Secured with Robust Encryption
Encryption standard gaps identified during the VA-VM assessment were addressed as part of the remediation program — securing data in transit across the on-premise and cloud environment.
Demonstrated Commitment to Customer Data Protection
Structured governance, documented remediation progress, and consistent client-specific reporting gave the technology firm a defensible record of its vulnerability management program — material for client assurance and regulatory requirements alike.
Key Takeaway
This project highlights Softenger’s proficiency in managing complex vulnerability assessment and management programs. By implementing robust governance, prioritization, and automation strategies, Softenger enabled the client to achieve greater efficiency, compliance, and security across a large and diverse endpoint environment — delivering a 54% reduction in attack surfaces as the measurable headline outcome.
Every engagement follows
the AOTS framework
The VA-VM program restructuring followed Softenger’s four-phase AOTS model exactly as it was designed to work. The Advise phase identified which of the five operational gaps were primary — the answer was governance, because without remediation accountability the other four fixes would produce data that nobody acted on. Optimize added automation. Transform deployed the full program. Support kept it running and improving.
Vulnerability management programs don’t stay fixed without sustained governance. The bi-weekly cadence is a Support-phase commitment — not a one-time engagement deliverable. The 54% reduction is the result of an ongoing program, not a one-time project close.
Advise
Assessed the existing VA-VM program. Identified the five operational gaps: tracking, reporting, prioritization, visibility, scanning control. Designed the structured program before deploying any method.
Program gap analysis complete. Five-method approach defined. Asset prioritization framework agreed — PCI and IDMZ as critical tier.
Optimize
Automated reporting scripts developed. Splunk and Rapid7 dashboards configured to the client’s specific multi-client environment. CRQ scanning process designed and approved before deployment.
Custom reporting automation live. Dashboards operational. CRQ process approved. Governance call format agreed and first session held.
Transform
Full five-method VA-VM program operational. Remediation effort focused on PCI and IDMZ assets. Attack surface reduction measurable from first full scan cycle under the new program structure.
All five methods running. Priority remediation underway. Reporting consistent. Scanning controlled. 54% attack surface reduction delivered.
Support
Bi-weekly governance calls ongoing. Dashboards maintained current. Automated reports generated each cycle. Scan scheduling managed through CRQ. Program improvement continuous as new assets onboard.
VA-VM program sustained under Softenger governance. SLA compliance maintained. Attack surface reduction defended, not allowed to regress.
The AOTS model is applied to every Softenger engagement
The same four-phase discipline — Advise, Optimize, Transform, Support — structures every engagement Softenger delivers, from VA-VM programs to IT infrastructure management, application services, and SOC operations.
Questions about vulnerability management programs
Tell us about your
vulnerability management
program — and its gaps.
If your organization is scanning but not closing findings, tracking but not enforcing SLAs, or reporting inconsistently to different stakeholders — the program structure is the problem, not the tooling. Softenger has restructured VA-VM programs across complex multi-cloud and on-premise environments. A conversation with one of our cybersecurity specialists starts with understanding your current program state, not with a product recommendation.
🔍 Discuss Your VA-VM Program
ISO 27001 certified. Your information is handled securely and never shared.