
Vulnerabilities and hardening, tracked over time
Blackfort Vulnerability Management
Keep vulnerabilities and hardening gaps visible and track progress over time — operated by us, optionally on the basis of different scan engines.
A scan gives you a snapshot. What is missing is the trend: which vulnerabilities are new, which have been open for months, how does hardening compare to last quarter? Blackfort Vulnerability Management continuously matches your software inventory against public vulnerability data, checks every system against the matching CIS policy and tracks progress. We run it.
Core Capabilities
Continuous vulnerability matching
The software and package inventory actually installed is matched continuously against public vulnerability data — each finding with severity and affected version.
Hardening checks against CIS
Every system is checked against the CIS policy matching its operating system: a compliance score per system, plus every individual finding with the setting that is missing.
The trend over time
Progress over time is recorded so you can show that something is moving.
Engine as needed
Depending on your environment and requirements we deploy a suitable scan engine and operate it for you. Which one, and where it runs, is agreed in the initial call.
Typical Use Cases
- Vulnerability management without a dedicated team
- Demonstrable hardening against recognised benchmarks
- Progress evidence for audits and management reports
- A basis for risk-based prioritisation
Request This Product
Interested in Blackfort Vulnerability Management? Talk to us about your requirements and receive a tailored proposal.
Send RequestRegulatory Context
Addresses the management of technical vulnerabilities under ISO/IEC 27001 Annex A.8.8, the detection and evidence side of patch and change management under BSI IT-Grundschutz OPS.1.1.3 and requirements from Section 30(2) BSIG (Germany). You provide the evidence in the end; the product supplies what it is built from.
Real-World Scenarios
The server nobody has touched
A service running for years becomes visible in the inventory match with open vulnerabilities — including the package versions responsible.
Audit preparation
Instead of yesterday's scan report there is a record over several months: what was found, what is closed, what stayed open.
Frequently Asked Questions
Which scan engine is used?
That depends on your environment and requirements; we agree it in the initial call and operate the chosen solution for you. Where it runs — with us in Germany, on your premises, or as the vendor's cloud service — is part of that agreement and is recorded in the data processing agreement.
How is this different from a vulnerability scan?
A scan is a one-off check. This is continuous operation: recurring matching, hardening checks, trend and assessment.
Does the product prioritise by business relevance?
It rates by severity and affected version. Ordering by the business relevance of the asset is a separate undertaking — the Blackfort Threat Exposure Filter is intended for that.
Does this replace our patch management?
No. We make vulnerabilities and hardening gaps visible and track progress. Closing them remains a process in your operation; we support it on request.
Kontakt aufnehmen
Ready to strengthen your security?
Find out more about Blackfort Vulnerability Management and how it can improve your security posture.