Skip to main content
Cloud Fortress, por Cloud y Olé
Area 2 · Vulnerabilities and defence

From «we have 4,000 vulnerabilities» to «fix these 12 first»

The SOC's problem is not finding vulnerabilities: it is knowing which ones actually matter and closing them without losing track. This area carries every finding from detection to patch, with the asset's context attached the whole way.

What's included

The full defence cycle

  • Vulnerabilities

    Prioritisation with context

    CVEs cross-referenced with your inventory (VISTA and CPEs), audits, criticality scoring with CVSS and a remediation plan tracked to closure.

    See capability
  • SOC

    Incidents and threat hunting

    End-to-end incident management and proactive hunting for threats that have not tripped any alarm yet.

    See capability
  • Operations

    Monitoring and service desk

    Continuous monitoring and a user service desk, so what gets detected turns into action rather than into a forgotten ticket.

    See capability
  • Surface

    Accounts, backups and AI

    M365 and Google account governance, backup oversight and supervision of the team's use of external AI tools.

How it prioritises

Why two «critical» CVEs are not worth the same

A CVE scoring 9.8 on an isolated lab server is not the same as a 7.5 on the server that exposes your shop to the internet. The scanner gives you the score; Cloud Fortress adds what the scanner does not know: whether the asset is exposed, what it is used for and who answers for it. The list stops being a wall of 4,000 rows and becomes an actual plan of work.

  1. Detect

    Syncs with the CVE/CPE databases and with your scanners.

  2. Cross-reference

    Maps each vulnerability to the exact inventory asset that carries it.

  3. Prioritise

    Combines CVSS with the asset's exposure and business value.

  4. Close

    Opens the remediation task and follows it to the patch, leaving an auditable trail.

The VISTA panel in Cloud Fortress with vulnerabilities prioritised by criticality and the affected asset on every row
Frequently asked questions

Frequently asked questions

  • Does it replace my vulnerability scanner?

    It does not need to. Cloud Fortress works with what you already detect and adds the asset context and the tracking to closure.

  • Does it include applying the patches?

    It coordinates and tracks remediation with tasks and owners; execution depends on your own systems and teams. We go through the detail in the demo.

  • What exactly counts as a vulnerability in the list?

    The unit of work is not the CVE: it is the CVE × package pair. The same CVE appears once per affected package, because what you patch is the package, not the vulnerability. That is what turns «there are 1,646 vulnerabilities out there» into «these 81 are on your production servers».

  • What happens to CVEs that have no score yet?

    They are marked as pending analysis, never as zero. A zero would say «not serious»; a pending says «we do not know yet». It is a design rule of the product: the platform does not give falsely reassuring states.

  • Where do the findings come from?

    Three sources that live in the same list and can be filtered separately: the agent deployed on the endpoints, the public CVE and CPE feeds, and an audit's scanner. We work with what you already detect instead of asking you to change tools.

Understand the risk. Act with confidence.

30 minutes with a scenario close to yours. No canned deck, no strings attached.