Vulnerability Management SLAs: Design, Enforcement, and Rollout Without Burnout

The SLA layer of a working VMP: Critical/High/Medium/Low durations, the automation that creates tickets and enforces the clock, the exception process, and the rollout approach that avoids engineering burnout in environments with heavy technical debt.

October 7, 2026 · 10 min · 1934 words · Javier Pulido

Vulnerability Prioritization Beyond CVSS: The Rules-Based Model I Actually Use

Why CVSS on its own produces the wrong queue, and the rules-based prioritization model I use to turn CVSS + EPSS + context tags into a Critical/High/Medium/Low tier that engineering can actually work.

September 24, 2026 · 9 min · 1900 words · Javier Pulido

Vulnerability Scanner Architecture: What to Scan, How to Dedupe, When to Build

The scanner-architecture decisions behind a working vulnerability management program built without enterprise tooling — coverage, deduplication, enrichment, and the one scanner I ended up building myself.

September 5, 2026 · 10 min · 1946 words · Javier Pulido

Why Most Vulnerability Management Programs Fail (And What Actually Works)

The design mistakes that quietly break vulnerability management programs — noise, ownership confusion, unrealistic SLAs, no shared accountability — and the shared-responsibility model that fixes them.

August 22, 2026 · 8 min · 1649 words · Javier Pulido