AsteronAsteron

    Vulnerability management for European healthtech

    Asteron turns findings from scanners, penetration tests, suppliers and external reports into controlled remediation. We validate what matters, prioritise it using product and business context, assign accountable owners and follow each material vulnerability through remediation, exception or verified closure — from €1,900 per month.

    See pricing and scope
    • One controlled vulnerability register
    • Priority based on context, not CVSS alone
    • Owners, deadlines and exceptions tracked
    • From €1,900 per month

    Scanning finds vulnerabilities. Management gets them resolved.

    Security tools are good at producing findings. They are less good at deciding whether a finding is real, whether it affects the deployed product, how urgently it should be addressed or who should own the decision. When several scanners, penetration tests and supplier alerts operate independently, the result is often a growing collection of tickets rather than a controlled security process.

    Vulnerability management is the continuous process of receiving or identifying weaknesses, validating them, determining their actual risk, coordinating remediation and retaining evidence of the final decision. A scanner is one source of information. It is not a vulnerability-management programme by itself.

    One controlled backlog

    Findings from agreed sources are consolidated, deduplicated and given a consistent status. Product, engineering and management teams work from the same record rather than separate reports and tool queues.

    Defensible priorities

    Technical severity is combined with exploitability, system exposure, affected data, product reach, business impact and existing controls. The company can explain why one issue is urgent and another is being monitored or deferred.

    Evidence of closure

    A finding is not closed simply because a ticket changed status. Remediation is verified where possible, while accepted risks and compensating controls retain an owner, rationale and review point.

    When healthtech teams need managed vulnerability operations

    The need usually appears when vulnerability information is arriving faster than the company can consistently validate, prioritise and follow it through.

    Several tools produce separate queues

    Cloud, dependency, application and infrastructure tools may all identify issues using different severity models. Without consolidation and deduplication, teams waste time investigating the same underlying weakness more than once.

    Testing findings lose momentum

    A penetration test receives immediate attention when the report arrives, but remediation may slow once product deadlines return. Significant findings need owners, target dates, verification and management escalation when deadlines are missed.

    Healthtech context changes the priority

    A vulnerability affecting authentication, tenant isolation, health-data access or a critical integration may require a different response from the same technical score in an isolated internal system. Where relevant, service availability and clinical or operational impact also influence the decision.

    Exceptions are agreed informally

    Some vulnerabilities cannot be fixed immediately because of supplier dependencies, product constraints or availability risk. An informal decision to “accept for now” is not enough: the rationale, compensating controls, accountable owner and review date need to remain visible.

    Not every company needs a fully managed service. A small team with one product, low finding volume and a capable internal security owner may run the process itself. Asteron becomes useful when the workflow crosses several tools, products, owners or customer and regulatory expectations.

    How the operating cycle works

    1. Establish scope, sources and decision rules

      At the start, Asteron agrees which products, environments and finding sources belong in the service. Sources may include existing vulnerability scanners, cloud and dependency tools, penetration tests, supplier advisories, responsible-disclosure reports and internal technical reviews.

      We also agree internal owners, escalation thresholds, target-date logic, exception authority and what evidence is required before closure. Tool availability and integrations depend on the client’s existing environment and the agreed scope.

    2. Validate and prioritise

      New findings are reviewed for relevance, duplication and available context. Where practical, false positives and non-applicable findings are removed before they consume engineering time.

      Priority considers known or practical exploitation, external exposure, affected data and privileges, product or tenant reach, service criticality, existing controls and remediation complexity. A CVSS score may inform the assessment, but it does not make the business decision on its own.

    3. Drive remediation or a documented exception

      Validated findings receive an accountable internal owner and target date. Asteron follows progress, records dependencies and escalates material or overdue risks through the agreed governance route.

      If immediate remediation is not proportionate or technically possible, the company may use a compensating control or accept residual risk. The client remains responsible for that decision; Asteron ensures the rationale, owner and review conditions are recorded.

    4. Verify, close and report

      Where the agreed scope and available tools allow, remediation is retested or otherwise verified before closure. Findings that depend on a future release, supplier action or temporary control remain visible until their closure conditions are met.

      Reporting shows open material risk, ageing, overdue actions, accepted exceptions and trends. The objective is to help engineering act and management decide, not to generate a larger dashboard.

    Priority is more than a severity score

    CVSS describes technical severity under defined assumptions. It does not automatically show whether the vulnerable component is exposed, whether the affected functionality is enabled, whether exploitation is occurring or what the consequence would be for this particular healthtech product.

    Asteron uses technical data together with product and business context. Known exploitation, including relevant entries in the CISA Known Exploited Vulnerabilities catalogue, is an important urgency signal, but it is considered alongside the affected asset and the company’s actual exposure.

    • Known or credible exploitation
    • Internet and customer exposure
    • Affected data and privileges
    • Authentication or tenant boundaries
    • Product and user reach
    • Availability or operational impact
    • Existing compensating controls
    • Supplier and remediation dependencies
    • Fix complexity and release timing
    • Accepted residual risk

    Choosing the right security service

    Vulnerability Management is one of several recurring services that support a healthtech security programme. Each has a distinct purpose.

    Vulnerability Management

    Purpose. Operate the continuous lifecycle from finding intake to remediation, exception or verified closure.

    Best fit. Several finding sources or owners require recurring triage, coordination and reporting.

    Price. from €1,900 per month

    Penetration Testing

    Purpose. Use expert-led testing to identify exploitable weaknesses within an agreed scope at a point in time.

    Best fit. A product release, customer requirement, risk decision or recurring assurance programme requires independent technical testing.

    Price. from €5,900 depending on target type

    Compliance Operations

    Purpose. Keep evidence, reviews, audits, questionnaires, policies and regulatory-change actions current throughout the year.

    Best fit. An existing management system needs recurring operational ownership.

    Price. €2,400/month up to 50 employees; €3,900/month for 51–150; from €6,500/month for complex environments

    These services complement each other but remain commercially separate. Penetration testing creates findings, Vulnerability Management drives them through the remediation lifecycle, and Compliance Operations retains the evidence required for management-system, customer and audit activity. Any combined scope is confirmed in the proposal.

    Vulnerability Management pricing and scope

    Asteron Vulnerability Management
    from €1,900 / month

    The monthly fee depends on the products and environments covered, existing tools, expected finding volume, reporting cadence, number of internal owners and the level of remediation coordination and verification required.

    A standard scope may include

    • Intake from agreed finding sources
    • Validation and deduplication
    • Context-based prioritisation
    • Owner and target-date tracking
    • Exception and closure evidence
    • Management reporting and escalation

    Scope, source integrations, responsibilities, reporting cadence, final monthly price and engagement term are confirmed in the proposal.

    Prices exclude VAT where applicable.

    Responsibilities and boundaries

    Asteron leads

    • Finding intake and consolidation
    • Validation and deduplication
    • Context-based priority recommendations
    • Owner and target-date follow-up
    • Exception and closure records
    • Verification coordination
    • Management reporting and escalation

    Your company owns

    • Access to relevant tools and product context
    • Internal engineering and infrastructure owners
    • Implementation of fixes and compensating controls
    • Release and operational decisions
    • Formal acceptance of residual risk
    • Supplier and product-owner coordination where required
    • Notification of material architecture or product changes

    Asteron operates the vulnerability workflow but does not normally implement code, infrastructure or production changes. Scanner and platform licences, penetration testing, source-code review, 24/7 monitoring and incident-response execution remain separate unless explicitly included in the proposal.

    If a finding indicates active exploitation or a potential incident, it leaves the normal remediation workflow and is escalated through the agreed incident route. A separate Incident Response Retainer starts from €2,400 per month.

    Frequently asked questions

    What is vulnerability management?

    Vulnerability management is the continuous process of identifying or receiving weaknesses, validating them, prioritising their actual risk, coordinating remediation and retaining evidence of closure or risk acceptance.

    Is vulnerability scanning the same as vulnerability management?

    No. Scanning identifies possible weaknesses. Vulnerability management adds validation, context, ownership, remediation follow-up, exception handling, verification and management reporting.

    How is vulnerability management different from penetration testing?

    Penetration testing is an expert-led assessment performed against an agreed scope at a point in time. Vulnerability management is the recurring process that handles findings from tests, scanners, suppliers and other sources until they are resolved or formally accepted.

    Which findings can Asteron manage?

    The service can include findings from agreed scanners, cloud and dependency tools, penetration tests, supplier advisories, responsible disclosures and internal reviews. Exact sources and integrations are confirmed during scoping.

    Do you prioritise vulnerabilities using CVSS?

    CVSS is an input, not the final priority. Asteron also considers exploitability, exposure, affected data, product reach, service impact, existing controls and remediation dependencies.

    Who implements the fixes?

    The client’s engineering, infrastructure or supplier teams normally implement remediation. Asteron provides prioritisation, coordination, follow-up and closure evidence but does not take production access unless separately agreed.

    How are accepted risks and exceptions handled?

    The exception records the rationale, accountable decision-maker, compensating controls and review conditions. It remains visible until it expires, is replaced or the underlying vulnerability is resolved.

    How is remediation verified?

    Where the agreed scope and available tools allow, remediation is retested or otherwise checked before closure. The verification method depends on the finding source and the change implemented.

    Can the service support customer and audit evidence?

    Yes. The register, ownership history, exception decisions and closure evidence can support relevant customer, management-system and audit reviews. Certification or customer acceptance is not guaranteed.

    How much does Vulnerability Management cost?

    Asteron Vulnerability Management starts from €1,900 per month. Final pricing depends on the assets and products covered, finding sources, expected volume, reporting needs and remediation-coordination workload.

    Official references

    • - OWASP Vulnerability Management Guide
    • - NIST SP 800-40 Rev. 4
    • - CISA Known Exploited Vulnerabilities Catalogue
    • - Directive (EU) 2022/2555, Article 21

    Last reviewed: July 2026

    Turn vulnerability findings into controlled remediation

    Tell us which products, tools and finding sources you already have. We will define the operating scope, responsibilities and reporting cadence required to bring the process under control.

    View Security Operations pricing