Multi-CloudHow-To & HardeningRetrospectives

How to Build a Vulnerability Management Program for Cloud-Hosted Apps

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.

Equifax was breached through a known vulnerability in a web framework that had a patch available for two months. A vulnerability management program makes sure that does not happen to your cloud-hosted applications. Here is a practical structure.

Step 1: Build the inventory

You cannot patch what you do not know about. Maintain an inventory of:

  • Virtual machines and containers in Azure and AWS.
  • Application dependencies (libraries and frameworks).
  • Internet-facing endpoints.
  • An owner for every application.

Use Microsoft Defender for Cloud and Amazon Inspector for automated discovery of VMs, containers and functions.

Step 2: Scan continuously

  • Infrastructure: Defender for Servers (Microsoft Defender Vulnerability Management) or Amazon Inspector for operating system vulnerabilities.
  • Containers: scan images in registries and at runtime.
  • Code dependencies: software composition analysis in your CI/CD pipeline (for example GitHub Dependabot).

Step 3: Prioritize by real risk

Do not treat every CVSS 7 the same. Prioritize vulnerabilities that are:

  1. Listed in CISA's Known Exploited Vulnerabilities catalog.
  2. On internet-facing systems.
  3. On systems with access to sensitive data.

Step 4: Set service levels

A common starting point: actively exploited and internet-facing within 72 hours; critical within 14 days; high within 30 days.

Step 5: Measure and report

Track mean time to remediate and the number of overdue vulnerabilities by team. Report monthly to leadership.

Common mistakes

  • Scanning without ownership, producing reports nobody acts on.
  • Ignoring application libraries because "the OS is patched."
  • No exception process — so overdue items are silently accepted.
cloud vulnerability management programEquifax2017

More on this story