Vulnerability Management Program Kit

Stand up a risk-based VM program in weeks.

A complete program built by a practitioner: policy, prioritization model, SLAs, workflows, metrics, and executive reporting. Findings are ranked by real exploitability rather than raw CVSS scores.

Get the Kit · free Free maturity assessment Ten editable files, open license, no sign-up
Same 6 findings, two ways to rank them
Finding CVSS EPSS KEV Asset · Exposure Priority
By CVSS, a 9.8 sits on top even when nobody is exploiting it. illustrative data

Sorting by CVSS means working the wrong list.

Most teams build VM from scratch. They stitch a policy together from blog posts, sort findings by severity, and chase "criticals" nobody is exploiting while the vulnerability on CISA's Known-Exploited list waits in the backlog.

The kit fixes the ranking first. A two-stage model puts exploitation status and business exposure ahead of raw score, so the work queue reflects real risk and you can defend every decision to an auditor or a board.

What's inside

A working program, not a folder of templates.

01

Policy & standards

VM policy, operating standard, scope and asset-coverage definition, roles & RACI.

02

Prioritization model

Paste a scanner export and map the columns once; the worksheet scores every finding (KEV · EPSS · criticality · exposure), assigns priority and SLA, and carries the methodology to defend it.

The engine
03

SLA matrix

Priority-to-SLA mapping, tunable to your risk appetite.

04

Workflows

Vulnerability lifecycle, triage runbook, exception & risk-acceptance process with register.

05

Scanner onboarding

A tool-agnostic onboarding playbook covering the fields the program needs, coverage validation, and tuning, with notes for Tenable, Qualys, Rapid7, Wiz, and Snyk.

06

Metrics & reporting

A live dashboard inside the model (MTTR, SLA attainment, backlog and aging, known-exploited exposure) plus the one-page executive report.

07

Maturity & roadmap

Five-level maturity model matched to the free self-assessment, plus a 90-day program roadmap.

08

Framework crosswalk

Mapped to NIST CSF, PCI DSS (req 6 & 11), ISO 27001, and SOC 2.

09

Enablement

Start-here implementation guide, the kickoff deck with speaker notes, and escalation paths.

See inside

Ten files. Here's what's actually in them.

No mystery box. This is the full manifest, plus two excerpts from the real documents: the SLA matrix out of the policy, and the lifecycle the runbook and overview deck walk through. Download all ten, free →

PPTXFlintScope-VM-Program-Overview.pptxThe whole program on 11 editable slides, with speaker notes. Rebrand it and present it to your leadership.
DOCXFlintScope-VM-Policy.docxPolicy & standard: scope, RACI, asset tiering, prioritization method, SLA matrix, exceptions, governance.
XLSXFlintScope-Prioritization-Model.xlsxThe engine. Paste a scanner export and map its columns once; it scores exploitability, criticality, and exposure, assigns priority and SLA, tracks open and closed dates, and runs the live dashboard: MTTR, SLA attainment, backlog, aging, and KEV exposure, with charts.
DOCXFlintScope-Triage-Remediation-Runbook.docxThe operating procedure, intake through close, with escalation paths and a worked example.
DOCXFlintScope-Executive-Reporting-Template.docxThe one-page leadership summary answering "are we exposed, and is it improving?"
XLSXFlintScope-Framework-Crosswalk.xlsxEvery program element mapped to NIST CSF 2.0, PCI DSS v4, ISO 27001:2022, and SOC 2, with the evidence each produces.
XLSXFlintScope-Exception-Register.xlsxThe governed risk-acceptance register: approver set by priority, expiry that flips to an SLA breach, live counts.
DOCXFlintScope-Scanner-Onboarding-Notes.docxBringing a scanner into the program: required fields, authenticated coverage, and tuning, with notes for Tenable, Qualys, Rapid7, Wiz, and Snyk.
DOCXFlintScope-VM-Maturity-Model.docxSix dimensions × five levels, scored like the free assessment, plus what to fix first at each level and the 90-day roadmap.
PDFFlintScope-VM-Program-Kit-START-HERE.pdfWhat each file is, the order to adopt them, and what to customize before you deploy.

Excerpt · VM Policy §8

Severity & SLA matrix

P1Critical / active threat
Exploited and internet-facing, or top composite
72 hours
24h if exploited & internet-facing
P2High
Severe + exposed or exploited
30 days
P3Medium
Moderate composite
90 days
P4Low
Limited exposure / criticality
180 days
or formally risk-accepted

Thresholds are tunable in the Prioritization Model and ratified against your own risk appetite.

Excerpt · Program Overview, slides 3 & 6

The lifecycle, and the two-stage model

IntakeTriagePrioritizeRouteRemediateVerifyClose

Stage 1, the threat gate. A finding that is exploited (on CISA KEV, known to be actively exploited, or EPSS ≥ 0.90) and internet-facing goes to P1, regardless of CVSS.

Stage 2, the composite. Everything else scores Severity × Exploit likelihood × Asset criticality × Exposure, mapping to P1 through P4. KEV or active exploitation sets exploit likelihood to its maximum, so an exploited finding on a segmented, low-value host still ranks by exposure and asset value like everything else.

A documented compensating control may lower priority by one tier at most. Every input is recorded, so the decision is auditable.

The differentiator

Why a high can outrank a critical.

A high that's on the Known-Exploited list, internet-facing, on a crown-jewel asset is a fire. A critical with near-zero exploit probability, sitting internal and segmented on a non-prod box, is a scheduled ticket.

The model encodes exactly that: a threat gate for findings that are exploited and internet-facing, then a composite score across severity, exploit likelihood, asset criticality, and exposure. Flip the demo above. That reshuffle is the daily reality CVSS-only programs get wrong.

Read the full method, with every threshold →

Free · no email required to start

Take the useful parts. Seriously.

The fastest way to trust a method is to use it. These are free and stand on their own: the full method, a tool that checks your CVE list against KEV and EPSS, a five-minute game about fix order, a short course for owners, and plain-English basics. Share them with your team. That's the point.

Tool · runs in your browser

KEV Check

Paste a list of CVE IDs, a scanner export or a ticket. Get each one's CISA KEV status, EPSS score and threat-gate result. Your list is never uploaded.

Check a list →
Data · refreshed daily

KEV Watch

What joined CISA's Known Exploited Vulnerabilities catalog, and what EPSS said about each flaw the day before it was listed. Computed from the two public feeds.

See the numbers →
Game · 5 min · Small business

What First

Thirty security problems, budget to fix five a quarter, and hidden dice deciding which of the rest get used against you. At the end you see what your order cost, and what six other orders would have cost with the same luck.

Play the game →
Course · 2 modules · Small business

Run security like a program

A free course for owners with no security staff. Module 1: what to fix first, how fast, and what to accept in writing. Module 2: a plain inventory of your accounts, apps, devices and vendors. Each lesson ends with part of a real file you keep.

Start the course →
Interactive · 3 min

VM Maturity Self-Assessment

Eight questions that place your program on a five-level scale and tell you the first things to fix. No sales call at the end.

Take the assessment →
Working tool · Excel

Prioritization Quick-Check

Drop in a finding, answer three yes/no questions, get FIX NOW / FIX SOON / STANDARD QUEUE. The thesis, demonstrable in thirty seconds.

Download the tool →
One-pager · PDF

The KEV Rule

The first piece of data to add to your queue and what to do with it once it's there, in four steps you can adopt this week. One lookup against a free feed.

Get the one-pager →
One-pager · PDF · Small business

The Free Six

Six free security steps, in plain English, that a business with no security team can finish this week. They stop the scams that actually hit small businesses.

Get the one-pager →

Running a real program? The VM Program Kit is free too. No security team? The Security Starter is the plain-English version.

Nick Strupp

Built by an operator

This is the program I ran in the field.

I'm Nick Strupp. At Accenture I built and scaled an application-security and vulnerability-management program from 12 people to 60, covering more than 5,000 applications, running the same risk-based prioritization this kit ships with. The kit is that program, written down, minus the years of trial and error.

Free and paid

What's free, and what's paid.

For firms

Commercial License

For consultants, vCISOs, MSPs and MSSPs who use the Kit in paid client work.

$399 / per firm
  • One firm, all of its people, unlimited clients
  • Deliver adapted documents under your own name
  • Later versions of the Kit included
  • One-time payment, 30-day money-back guarantee
See the commercial license
Entry

Security Starter

For a business with no security team: the owner, the office manager, whoever's "good with computers."

$49 / one-time
  • 18-step checklist in three phases, plain English
  • Printable one-page wallchart with tick boxes
  • Progress tracker + inventory spreadsheet
  • Questionnaire-prep tab with ready answers for insurers
Get the Security Starter
Paid for something that isn't a fit? Email support@flintscope.com within 30 days for a full refund.

Questions

Questions people ask.

Is this just templates?

No. The prioritization model and SLA logic are the operating decisions; the documents are the easy part. The model is the part you can't write from a blog post, and it is why the files work as one program.

Will it fit my tools?

Yes. It's tool-agnostic, with onboarding notes for the major scanners: Tenable, Qualys, Rapid7, Wiz, and Snyk.

Can I defend it to auditors?

Yes. The framework crosswalk maps every program element to NIST CSF 2.0, PCI DSS v4, ISO 27001:2022, and SOC 2, with the evidence each produces, and the policy's methodology section explains every scoring decision. It's a defensible starting point; your assessor has the final say.

What do I get?

Ten editable Word, Excel and PowerPoint files, free to download with no sign-up. You adapt every document to your own organization and tooling. New versions are posted on the Kit page.

Why is it free?

A method nobody can read can't be checked or adopted. The Kit is the program I ran, written down, and it does more good open than behind a checkout. The method is published in full for the same reason.

Do I need the commercial license?

Only if you use the Kit in paid work for clients, sell it, or build it into a product. Using and adapting it inside your own organization is free, at any size. The terms are on the license page.

Free

Not sure where your program stands?

Take the VM Maturity Self-Assessment, a quick scorecard across coverage, prioritization, remediation, and metrics. We'll send your results.