Thousands of scan findings. And nobody tells you what to tackle first?
After every scan a raw list lands on the table, and everything feels "critical". The planned VAS module is designed to prioritize findings by risk, make remediation trackable and show progress in a verifiable way, on COD's living asset base, multi-tenant and on-premises. (in preparation)
Example view of the vulnerability module (illustration): scan overview, remediation status and severity distribution.
Know the feeling?
Thousands of findings, but nobody says what comes first
The pain: After every scan run a raw list with many findings lands on the table. By pure severity everything feels "high" or "critical", and the team works the list from top to bottom, without knowing which vulnerabilities are actually being exploited.
The consequence: Scarce admin time evaporates on noise instead of risk. The truly dangerous vulnerability may stay open for a long time while the team patches the uncritical.
How COD solves it: The plan is for VAS to enrich every finding with context: severity, CVE references, affected assets and detection quality. Using the probability of exploitation (EPSS), it is meant to push forward what is most likely to be exploited. The intent: work on risk instead of list length, with noise defused in a documented way via note and override.
Between "detected" and "done" lies an uncontrolled gap
The pain: The scanner finds the vulnerability, then the manual work begins: copying findings into Excel, distributing them by mail, following up in meetings. Whether a finding is open, in progress or resolved, nobody knows for sure.
The consequence: Remediations peter out unnoticed, the same vulnerabilities stay open. That is a time sink through duplicate follow-up and at the same time a security and liability risk.
How COD solves it: The plan is to create a remediation ticket directly from a finding and track it through its lifecycle, with an SLA as a stored deadline. For every finding it should be consistently visible what is open, in progress or resolved: for team, management and audit, without maintaining separate spreadsheets.
"Is it getting better?" And there is no evidence
The pain: Whether in an audit, under NIS2 pressure or in the quarterly review: what is asked for is proof that vulnerability management works. Today that means comparing scanner exports by hand and copying numbers into slides.
The consequence: Manual work before every meeting, error-prone copy-paste evaluations and in the worst case an audit finding because effectiveness cannot be demonstrated.
How COD solves it: Planned are audit-ready reports and a delta comparison of two scan states (new vs. resolved) intended to show whether the attack surface is growing or shrinking. A configurable dashboard with severity distribution and trend is meant to make the development over time visible: security as a curve instead of a claim.
Why COD, not just a feature
VAS is planned as part of the COD platform, not as another island scanner: it is meant to work on the same living asset base your operations already run on, so that finding and asset belong together instead of sitting in separate tools, multi-tenant and on-premises. The structural advantage of a platform that a pure scanner does not have.
Frequently asked questions
See the risk before it becomes an incident.
We'll show you the intended scope of the vulnerability module, with no commitment - or download the VAS datasheet (in preparation) directly as a PDF.