TL;DR: Enterprise vulnerability management works best when asset discovery, authenticated scanning, risk-based prioritisation, and workflow automation are unified into one operating model, according to Nucleus. That shift matters because raw vulnerability counts do not reduce risk unless teams can map findings to ownership, exploitability, and remediation paths.
NHIMG editorial — based on content published by Nucleus: enterprise vulnerability management requirements and evaluation guidance
By the numbers:
- 28 new vulnerabilities were added to the CISA Known Exploited Vulnerabilities list during February 2026.
- 89% (25/28) of those February 2026 CISA KEV additions had CVSS scores over 7.0.
- 10 new vulnerabilities were rated critical at 9.0+ and 15 fell in the 7.0-8.9 range.
Questions worth separating out
Q: What breaks when enterprise vulnerability management relies on manual asset discovery?
A: Manual discovery leaves blind spots, especially in cloud, container, and short-lived environments where assets appear and disappear faster than periodic reviews can track them.
A: Prioritise by combining exploitability, asset criticality, compensating controls, and process ownership.
Q: What do security teams get wrong about vulnerability remediation automation?
A: They often automate ticket creation but not end-to-end closure.
Practitioner guidance
- Unify asset sources before tuning remediation Merge scanners, CMDB records, cloud inventories, and container data into one deduplicated asset graph so owners, environment tags, and exposure status stay aligned across platforms.
- Use authenticated scanning for depth, not just coverage Reserve credentialed scanning for systems where package state, configuration drift, and patch validation matter, and scope the scanner with least-privilege RBAC plus monitored credentials.
- Prioritise by exploitability and business criticality Rank findings using active exploitation signals, internet exposure, asset importance, and compensating controls so remediation queues reflect real risk rather than raw severity.
What's in the full article
Nucleus's full article covers the operational detail this post intentionally leaves for the source:
- Examples of how the platform unifies scanner output, CMDB data, and cloud inventories into one operational view
- Detailed comparison of scan methods, including authenticated, agent-based, and cloud posture checks
- Workflow examples for routing remediation into ITSM and DevOps systems with SLA tracking
- Deployment and performance considerations for regulated environments, including GovCloud and air-gapped options
👉 Read Nucleus's analysis of enterprise vulnerability management requirements →
Enterprise vulnerability management: are your controls keeping up?
Explore further
Enterprise vulnerability management is really an exposure governance problem, not a scanning problem. The article correctly treats asset discovery, prioritisation, and workflow as one system because point tools cannot reduce risk on their own. The named concept here is exposure governance, meaning the ability to continuously know what exists, what matters, and what was actually fixed. That is why remediation speed only matters after ownership and context are already reliable.
A question worth separating out:
Q: How do IAM and PAM controls support vulnerability management programmes?
A: IAM and PAM support the programme by controlling who can run scans, approve changes, access remediation systems, and manipulate evidence. If those roles are overbroad or poorly reviewed, vulnerability tooling itself becomes a privileged access pathway. Governance should therefore cover scanner accounts, remediation operators, and the audit trail around both.
👉 Read our full editorial: Enterprise vulnerability management depends on visibility, context, and automation