Vulnerability Management
Risk-based vulnerability prioritisation — patch the 5% that actually matter.
Cisco Vulnerability Management (formerly Kenna.VM) is a SaaS solution that uses real-world exploit data and predictive modelling to give each vulnerability a true risk score — so security teams prioritise the vulnerabilities that pose real risk and confidently deprioritise the vast majority that do not. It aligns Security, IT, and business leaders around a risk-based approach. Faltrox operates it as your vulnerability-prioritisation engine.
Overview
What Vulnerability Management is
There are millions of vulnerabilities across an enterprise and patching every one is impossible — security teams struggle to know which to prioritise while IT faces endless patch lists with no guidance. Cisco Vulnerability Management solves the prioritisation problem with data science: it translates enterprise vulnerability data and real-world exploit activity into a real risk score for each finding.
Risk scoring powered by machine learning and patented predictive modelling reveals the true risk profile of every vulnerability, so you focus remediation on the small percentage that attackers actually exploit and deprioritise the rest with confidence. Delivered as SaaS, it aligns Security, IT, and business leaders around a shared, risk-based view and reduces remediation effort while lowering business risk. Faltrox operates it — ingesting your scanner data, tuning the model to your environment, and driving the remediation that matters.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Enterprise Vulnerabilities
Ingests findings across your infrastructure, applications, and scanners into one risk view.
Real Risk Scoring
Scores each vulnerability by true risk using data science and predictive modelling.
Real-World Exploit Data
Weights scoring by actual exploit activity in the wild, not just theoretical severity.
Remediation Focus
Surfaces the small share that pose real risk and deprioritises the vast majority that do not.
Business Alignment
Aligns Security, IT, and business leaders around a shared risk-based approach.
Remediation Efficiency
Reduces remediation effort and resource allocation by guiding where to act.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Ingest
It ingests vulnerability findings from your scanners and asset data across the enterprise into one SaaS platform.
- 02
Score
Data science, machine learning, and predictive modelling translate that data and real-world exploit activity into a real risk score per vulnerability.
- 03
Prioritise
It surfaces the vulnerabilities that pose genuine risk and lets you confidently deprioritise the majority that do not.
- 04
Guide
Actionable intelligence guides remediation effort and resource allocation for Security and IT.
- 05
Operate
Faltrox tunes the model to your environment, drives the prioritised remediation, and reports risk posture to leadership.
Capabilities
Key capabilities
Risk-Based Prioritisation
A real risk score per vulnerability, powered by data science and patented predictive modelling.
Real-World Exploit Data
Scoring weighted by actual exploit activity in the wild, not just CVSS severity in isolation.
Predictive Modelling
Machine learning predicts which vulnerabilities are likely to be weaponised so you act ahead of exploitation.
Confident Deprioritisation
Lets teams safely deprioritise the vast majority of findings that pose no real risk.
Enterprise-Scale SaaS
A scalable SaaS platform that ingests findings across the whole enterprise.
Business-Risk Alignment
Aligns Security, IT, and business leaders around one risk-based view of remediation.
Remediation Efficiency
Reduces remediation effort and optimises resource allocation by focusing on what matters.
Executive Reporting
Translates technical findings into a business-risk posture leadership can understand and act on.
Works with
Part of the platform
Cisco products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Cisco Vulnerability Management for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How is this different from a vulnerability scanner?
A scanner finds vulnerabilities; Cisco Vulnerability Management prioritises them. It ingests findings from your scanners and applies data science and real-world exploit data to score each by true risk, so you know which of the millions to fix first rather than facing an undifferentiated list.
02Why not just patch by CVSS severity?
CVSS severity in isolation over-flags — many "critical" vulnerabilities are never exploited, and some lower-scored ones are actively weaponised. This platform weights scoring by real-world exploit activity and predictive modelling, so you focus on the small share that attackers actually use.
03Can we safely ignore most vulnerabilities?
That is precisely the value — it lets you confidently deprioritise the vast majority that pose no real risk, so limited remediation capacity goes to the findings that genuinely reduce breach likelihood. Faltrox operates that judgement with you.
04Does it help beyond the security team?
Yes — it aligns Security, IT, and business leaders around a shared risk-based approach and reports posture in business terms, so remediation priorities are agreed across teams rather than argued over patch by patch.
05How does Faltrox operate it?
We ingest your scanner and asset data, tune the risk model to your environment, drive the prioritised remediation with your IT team, and report risk posture to leadership — running it as a managed vulnerability-prioritisation service.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us