Skip to content
FioSec Consulting

Vulnerability Management · Case study

From 100,000 findings to a managed vulnerability program

A new CISO’s first vulnerability scan surfaced more than 100,000 findings. FioSec helped turn the flood into a ranked, risk-based remediation program with routine patching automated, and still works alongside the team every month.

The situation

The organization

A manufacturing organization in Ontario, around 500 employees, with an established IT team. A newly hired CISO had just taken over the security program from their predecessor.

What prompted it

The incoming CISO did exactly the right thing first: got visibility. The organization purchased a vulnerability management platform and deployed it across the environment, and the first full scan returned more than 100,000 findings. The tool had done its job, but the number was paralyzing: every finding looked urgent, the list grew daily as new vulnerabilities were disclosed, and the team had no way to know where to start. The CISO brought in FioSec to turn raw findings into a plan the team could actually execute.

What FioSec did

Each step maps to a layer of the Layered Defence model: vendor-agnostic by design, described by the control it delivers rather than any one product.

  1. Triage before tickets

    A six-figure findings count is normal for a first scan, and much of it collapses under deduplication: one missing operating-system update can appear as dozens of findings across hundreds of machines. We grouped the backlog by root cause, so 100,000 findings became a far shorter list of actual fixes.

  2. Risk-based prioritization

    Severity scores alone do not tell you what an attacker will use. We ranked the deduplicated list on three axes: exploitability, exposure, and asset criticality. That produced a short, defensible fix-these-first list instead of a wall of criticals.

  3. Remediation in waves

    Each wave was scoped to what the team could genuinely complete: the first targeted actively exploited vulnerabilities on exposed systems, and subsequent waves worked down the risk ranking. Progress became visible week over week instead of the backlog feeling bottomless.

  4. Automating the routine

    We implemented patch-automation tooling so routine operating-system and application updates deploy on a schedule, with the fixes that need care, such as legacy systems and upgrades requiring testing, reserved for the team. The backlog now burns down continuously rather than only when someone finds time.

  5. From project to program

    We set remediation targets by severity, established a recurring triage cadence for new findings, and built reporting the CISO can take to leadership: trend lines, not raw counts. The platform the organization had already bought became the heart of an ongoing vulnerability management routine.

The outcome

An unranked backlog of more than 100,000 findings came down to a manageable number for the team: deduplicated to root-cause fixes, ranked by real-world risk, and worked down in planned waves.

Routine patching now runs largely automated, so the team’s manual effort goes to the fixes that genuinely need judgment.

The CISO reports security posture to leadership with trend data, and the conversation shifted from how many findings there are to whether the number is going the right way.

FioSec remains engaged on a monthly touchpoint basis, reviewing new findings, tuning priorities, and supporting the next phase of the program.

Facing something similar?

Tell us where you are today and we’ll help you map the right next step. No obligation.