Skip to main content
Cloud Fortress, por Cloud y Olé
Capability

Vulnerability management that knows what matters

A scanner tells you what is broken. Cloud Fortress tells you what to fix first and why: it cross-references every CVE with the asset that carries it, its real exposure and its business value.

What it is

The problem is not the list, it is the order

Vulnerability management is the process of finding, prioritising and fixing the weaknesses in your technology surface before somebody exploits them. In theory it is an orderly cycle; in practice most teams drown at the first step. A scanner returns thousands of CVEs, each with its CVSS score, and that score is only half the story: it says how serious the vulnerability is in the abstract, not how dangerous it is to you.

A critical vulnerability on a powered-down lab server matters far less than a medium one on the system that exposes your billing to the internet. Without that context —is the asset exposed? what is it used for? who answers for it?— prioritisation is done by eye, and the result is an endless backlog where the urgent and the irrelevant share a screen.

How Cloud Fortress does it

CVSS + exposure + business value

  1. Detect and normalise

    Syncs with the CVE/CPE databases and with your scanners to gather every finding in one place.

  2. Cross-reference the inventory

    Each CVE is linked to the exact asset that carries it (VISTA and CPEs), with its owner and its criticality.

  3. Prioritise with context

    On top of the CVSS score it adds real exposure and asset value. What genuinely puts you at risk rises to the top.

  4. Close the loop

    Opens the remediation plan, assigns an owner and follows each vulnerability to the patch, leaving an auditable trail.

The Cloud Fortress remediation plan with each task, its owner and its tracking status through to the patch

The cycle does not end at the list: every finding is followed to the patch, with an owner and an auditable trail.

The difference in one line
A scanner tells you what is broken. Cloud Fortress tells you what to fix first, and why.
Frequently asked questions

Frequently asked questions

  • Does it prioritise by CVSS alone?

    No. CVSS is the starting point; real exposure and asset value go on top. That is why two «criticals» can end up in very different places on the list.

  • Do I need to change scanner?

    No. We work with what you already detect; what we add is the context and the closing of the loop. Findings from the agent, from public feeds and from an audit's scanner live in the same list and can be filtered by source.

  • What counts as a vulnerability: the CVE or the package?

    The package. The unit of work is the CVE × package pair, because what gets patched is the package and one CVE can affect several. That is why the list does not say «there are 1,646 vulnerabilities out there» but «these 81 are on your production servers».

  • What happens to a CVE with no CVSS score yet?

    It shows as pending analysis, never as zero. A zero would say «not serious» and a pending says «we do not know yet»: those are different things, and confusing them is exactly how a critical ends up at the bottom of the backlog.

  • How do I know which specific machines have the vulnerable package?

    Because the CVE is cross-referenced with your organisation's software inventory. Nobody has to go looking: the finding arrives saying which endpoints have the affected package installed, who answers for them and whether they are exposed to the internet.

See it running with your data in front of you

30 minutes with a scenario close to yours. No canned deck, no strings attached.