Types of vulnerability
Vulnerabilities can be software flaws (a bug in code that allows unauthorised access), misconfigurations (a storage bucket left public, a default password), missing patches, weak authentication, or process and human weaknesses that attackers exploit through social engineering.
Vulnerability, threat and risk
A vulnerability is a weakness. A threat is someone or something that could exploit it. Risk is the combination: how likely the weakness is to be exploited and how much damage it would cause. A vulnerability with no realistic threat carries little risk.
Vulnerability management
Managing vulnerabilities is a continuous cycle: discover assets, scan for weaknesses, prioritise by real risk, fix or mitigate, and verify the fix. Scanning, attack surface management and pentesting all feed this cycle.
Where it shows up in compliance
ISO 27001 (Annex A 8.8), the ENS, NIS2 and SOC 2 all require organisations to manage technical vulnerabilities and to fix them within defined timeframes.




