Vulnerability management is the discipline that keeps organisations ahead of attackers, and understanding its full lifecycle is the foundation of a security operations career. Here is a practical guide to the six stages of the lifecycle, exactly as security teams run them.
Stage 1: Discover
Everything starts with knowing what you have. Asset discovery identifies every device, cloud resource and application in the environment. You cannot secure what you do not know exists, so discovery must run continuously – new assets appear constantly, and each one is a potential entry point.
Stage 2: Scan
Scanning finds weaknesses in the discovered assets. Scans vary by depth and frequency: network scans, authenticated scans and cloud scans each see different things. The practical skill is choosing the right scan for the right asset and scheduling it so the environment stays protected without breaking operations.
Stage 3: Prioritise
Not every finding is equal, and teams cannot fix everything at once. Prioritisation ranks findings by severity, exploitability and business impact. This is where analyst judgement matters most: a critical finding on a public-facing system outranks a critical finding on an internal test server.
Stage 4: Remediate
Remediation closes the gaps – patching, configuration changes and compensating controls. The analyst’s job includes tracking remediation to completion, escalating what is blocked and verifying the fix after deployment. Patch cycles and change windows make this the most coordination-heavy stage.
Stage 5: Verify and Report
Re-scan after fixes to confirm they worked, then report to leadership and auditors. Reports should show risk reduction over time, not just raw findings – executives decide budget based on this story. Clear reporting is what turns good analysts into trusted ones.
Building Your Skills in This Field
Every stage is a job skill, and platforms like Qualys automate the workflow while analysts run it. SkilBrill’s Qualys and VMDR training walks you through the full lifecycle with hands-on labs, so you understand the process and can operate the platform that most enterprises use.
