How to Build a Vulnerability Management Program for Cloud-Hosted Apps
Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.
Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes sure that does not happen to your cloud-hosted applications. Here is a practical structure.
Step 1: Build the inventory
You cannot patch what you do not know about. Maintain an inventory of:
- Virtual machines and containers in Azure and AWS.
- Application dependencies (libraries and frameworks).
- Internet-facing endpoints.
- An owner for every application.
Use Microsoft Defender for Cloud and Amazon Inspector for automated discovery of VMs, containers and functions.
Step 2: Scan continuously
- Infrastructure: Defender for Servers (Microsoft Defender Vulnerability Management) or Amazon Inspector for operating system vulnerabilities.
- Containers: scan images in registries and at runtime.
- Code dependencies: software composition analysis in your CI/CD pipeline (for example GitHub Dependabot).
Step 3: Prioritize by real risk
Do not treat every CVSS 7 the same. Prioritize vulnerabilities that are:
- Listed in CISA's Known Exploited Vulnerabilities catalog.
- On internet-facing systems.
- On systems with access to sensitive data.
Step 4: Set service levels
A common starting point: actively exploited and internet-facing within 72 hours; critical within 14 days; high within 30 days.
Step 5: Measure and report
Track mean time to remediate and the number of overdue vulnerabilities by team. Report monthly to leadership.
Common mistakes
- Scanning without ownership, producing reports nobody acts on.
- Ignoring application libraries because "the OS is patched."
- No exception process — so overdue items are silently accepted.