Vulnerability management is the ongoing cycle of discovering security weaknesses — exposed services, unpatched software, misconfigurations — assessing how exploitable each one actually is in your environment, assigning it an owner, and tracking it until it is fixed or formally accepted. It is distinct from a scan: a scan produces a list, while vulnerability management produces closure.
What is vulnerability management?
Continuously finding weaknesses across your estate, ranking them by real exposure, and driving each one to closure.
What the practice is actually for.
- A finding without an owner and a status is a report line, not a remediation
- External exposure and vulnerable local packages are the same problem seen from two angles
- Cyber insurance renewals increasingly require evidence of an operating programme, not an annual scan
The practical version.
Scan targets and schedules are managed in Odin and run through the built-in HostedScan integration, while the RMM agent contributes per-endpoint software inventory matched against known CVEs. Both feed one risk register with severity, exposure, status, and history — and a risk becomes a ticket in the same queue your technicians already work, so remediation happens where the finding was raised.
Read next.
What is patch management?
The process of finding, approving, deploying, and proving software updates across a fleet.
ReadWhat is network discovery?
The continuous practice of finding every device on a network — including the ones nobody told you about.
ReadWhat is RMM?
Remote monitoring and management — the tooling that lets a small team operate a big endpoint fleet.
ReadReady to run IT on Odin?
Deploy your first agent in minutes. See the platform in action — book a walkthrough or kick the tires on a free trial.