CiscoEndpoint & Threat Protection

    Vulnerability Management

    Risk-based vulnerability prioritisation — patch the 5% that actually matter.

    Cisco Vulnerability Management (formerly Kenna.VM) is a SaaS solution that uses real-world exploit data and predictive modelling to give each vulnerability a true risk score — so security teams prioritise the vulnerabilities that pose real risk and confidently deprioritise the vast majority that do not. It aligns Security, IT, and business leaders around a risk-based approach. Faltrox operates it as your vulnerability-prioritisation engine.

    Overview

    What Vulnerability Management is

    There are millions of vulnerabilities across an enterprise and patching every one is impossible — security teams struggle to know which to prioritise while IT faces endless patch lists with no guidance. Cisco Vulnerability Management solves the prioritisation problem with data science: it translates enterprise vulnerability data and real-world exploit activity into a real risk score for each finding.

    Risk scoring powered by machine learning and patented predictive modelling reveals the true risk profile of every vulnerability, so you focus remediation on the small percentage that attackers actually exploit and deprioritise the rest with confidence. Delivered as SaaS, it aligns Security, IT, and business leaders around a shared, risk-based view and reduces remediation effort while lowering business risk. Faltrox operates it — ingesting your scanner data, tuning the model to your environment, and driving the remediation that matters.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Enterprise Vulnerabilities

    Ingests findings across your infrastructure, applications, and scanners into one risk view.

    02

    Real Risk Scoring

    Scores each vulnerability by true risk using data science and predictive modelling.

    03

    Real-World Exploit Data

    Weights scoring by actual exploit activity in the wild, not just theoretical severity.

    04

    Remediation Focus

    Surfaces the small share that pose real risk and deprioritises the vast majority that do not.

    05

    Business Alignment

    Aligns Security, IT, and business leaders around a shared risk-based approach.

    06

    Remediation Efficiency

    Reduces remediation effort and resource allocation by guiding where to act.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Ingest

      It ingests vulnerability findings from your scanners and asset data across the enterprise into one SaaS platform.

    2. 02

      Score

      Data science, machine learning, and predictive modelling translate that data and real-world exploit activity into a real risk score per vulnerability.

    3. 03

      Prioritise

      It surfaces the vulnerabilities that pose genuine risk and lets you confidently deprioritise the majority that do not.

    4. 04

      Guide

      Actionable intelligence guides remediation effort and resource allocation for Security and IT.

    5. 05

      Operate

      Faltrox tunes the model to your environment, drives the prioritised remediation, and reports risk posture to leadership.

    Capabilities

    Key capabilities

    Risk-Based Prioritisation

    A real risk score per vulnerability, powered by data science and patented predictive modelling.

    Real-World Exploit Data

    Scoring weighted by actual exploit activity in the wild, not just CVSS severity in isolation.

    Predictive Modelling

    Machine learning predicts which vulnerabilities are likely to be weaponised so you act ahead of exploitation.

    Confident Deprioritisation

    Lets teams safely deprioritise the vast majority of findings that pose no real risk.

    Enterprise-Scale SaaS

    A scalable SaaS platform that ingests findings across the whole enterprise.

    Business-Risk Alignment

    Aligns Security, IT, and business leaders around one risk-based view of remediation.

    Remediation Efficiency

    Reduces remediation effort and optimises resource allocation by focusing on what matters.

    Executive Reporting

    Translates technical findings into a business-risk posture leadership can understand and act on.

    Works with

    Part of the platform

    Cisco products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Cisco Vulnerability Management for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How is this different from a vulnerability scanner?

    A scanner finds vulnerabilities; Cisco Vulnerability Management prioritises them. It ingests findings from your scanners and applies data science and real-world exploit data to score each by true risk, so you know which of the millions to fix first rather than facing an undifferentiated list.

    02Why not just patch by CVSS severity?

    CVSS severity in isolation over-flags — many "critical" vulnerabilities are never exploited, and some lower-scored ones are actively weaponised. This platform weights scoring by real-world exploit activity and predictive modelling, so you focus on the small share that attackers actually use.

    03Can we safely ignore most vulnerabilities?

    That is precisely the value — it lets you confidently deprioritise the vast majority that pose no real risk, so limited remediation capacity goes to the findings that genuinely reduce breach likelihood. Faltrox operates that judgement with you.

    04Does it help beyond the security team?

    Yes — it aligns Security, IT, and business leaders around a shared risk-based approach and reports posture in business terms, so remediation priorities are agreed across teams rather than argued over patch by patch.

    05How does Faltrox operate it?

    We ingest your scanner and asset data, tune the risk model to your environment, drive the prioritised remediation with your IT team, and report risk posture to leadership — running it as a managed vulnerability-prioritisation service.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us