Resources & Insights

Vulnerability management,
explained

Practical guides on RBVM, NIS2, DORA, ISO 27001, and the science of prioritising what to fix first.

UAE13 min read

UAE Vulnerability Management & Penetration Testing Regulations: A Practical Guide

NESA / SIA Information Assurance Standards, CBUAE Cyber Risk Regulations, DESC, ADHICS, TDRA — what UAE entities need to have in place for vulnerability management and penetration testing.

April 28, 2026Read more
RBVM8 min read

Risk-Based vs. Traditional Vulnerability Management: What's the Real Difference?

Why treating every CVE equally is costing your team time, money, and resilience — and how RBVM changes the equation.

March 15, 2025Read more
NIS212 min read

NIS2 Article 21: A Practical Vulnerability Management Implementation Guide

Step-by-step guidance on meeting NIS2 Article 21 vulnerability handling requirements before enforcement hits your sector.

February 28, 2025Read more
DORA10 min read

DORA ICT Risk Management: What Financial Entities Need to Know About Vulnerability Scanning

DORA entered into application in January 2025. Here's what financial entities must have in place for vulnerability management.

February 10, 2025Read more
RBVM9 min read

CVSS Scores Aren't Enough: Why Contextual RBVM Beats CVSS, EPSS & CISA KEV

CVSS, EPSS, and CISA KEV describe vulnerabilities at internet scale — not in your environment. See why CVSS for prioritisation falls short, how CVSS vs EPSS vs contextual scoring actually compares, and what real risk-based vulnerability management looks like.

January 22, 2025Read more
MSSP9 min read

How MSSPs Should Structure Vulnerability Management for Multi-Client Environments

The architectural and operational considerations for MSSPs building scalable vulnerability management practices.

January 8, 2025Read more
ISO 2700111 min read

ISO 27001 Control A.8.8: How to Demonstrate Vulnerability Management to Auditors

Practical guidance on implementing and evidencing ISO 27001:2022 Annex A control A.8.8 for your next certification audit.

December 18, 2024Read more
Blog — RBVM, NIS2, DORA, ISO 27001 & Vulnerability Management | Centraleyezer