← Cybersecurity & OT Security Studio
Concept Explainer · Vulnerability Management

Vulnerability Management vs. Patch Management

Patching is one way to fix a vulnerability. Vulnerability management is the entire program that decides whether patching is even the right fix.

"We have a patch management process" is one of the most common statements made in a security review, and it's routinely treated as proof that vulnerabilities are handled. It isn't. Patch management is the specific, mechanical process of testing and deploying vendor-released software updates — one remediation option. Vulnerability management is the broader, continuous program that discovers assets, scans them for weaknesses, assesses and prioritizes those weaknesses by real-world risk, remediates them by whatever means actually fixes the problem, and then verifies the fix worked. Patching is one branch inside that remediate step — not the whole program, and not even the only way to remediate.