
14.07.2026
An IT system is only secure when companies know their own vulnerabilities. This is exactly where vulnerability management comes in.
Every organisation runs systems with security vulnerabilities, whether through outdated software, missing patches or misconfigurations. The critical question: how quickly does an organisation find, assess and close these gaps?
In an interview, Stefan Kappey, Service Owner Vulnerability Management at accompio, explains how the process works in practice, which mistakes companies should avoid, and what role artificial intelligence plays in prioritisation.
How does vulnerability management work in practice? What tools are used? And why does patching remain the most important single measure despite all the automation? Stefan Kappey answers all these questions in the full video interview.
Vulnerability management refers to the continuous process of identifying, assessing, prioritising, and remediating security vulnerabilities in IT systems. The aim is to reduce an organisation's attack surface before attackers can exploit a vulnerability.
The process fundamentally distinguishes between two categories of vulnerabilities:
The latter require manual intervention as no patch can automatically fix them.
Many companies rely on their administrators' gut feeling to assess risks. This approach rarely provides a complete picture of the actual attack surface.
„Without knowing my attack surface, I cannot protect it.“
— Stefan Kappey, Service Owner at accompio
Stefan Kappey hits the nail on the head in the interview. Only a systematic scan of the entire IT environment creates the basis for sound decisions about prioritisation and remediation.
Vulnerability management follows four consecutive phases, which repeat after each remediation.
A purely manual inspection quickly reaches its limits in IT environments with hundreds of systems. Automated vulnerability scanners test entire networks daily and provide an up-to-date overview of the security status.
The manual approach also shows a practical weakness: administrators who initiate an update and see a successful installation assume a secure system. However, updates do not always function reliably in the background. A vulnerability management tool uncovers such silent errors that often go unnoticed in a purely manual process.
A practical example from the interview illustrates this point: In one case, the tool used identified a WannaCry vulnerability on a system, even though it had long been corrected across the entire company. The cause was an old, restored system image. Without continuous scanning, this vulnerability would have remained undetected.
The most common mistake in vulnerability management remains Unpatched. A reliable patching process significantly reduces effort, as it closes most vulnerabilities in advance.
A second challenge concerns inter-departmental communication. Particularly at the Interface between classic IT and Operational Technology (OT) different priorities apply. While IT prioritises security, OT primarily focuses on the availability of systems. A lack of communication between the two areas regularly leads to security vulnerabilities that nobody fixes, as responsibility remains unclear.
Not least, prioritisation itself requires experience: a critically classified vulnerability on a non-critical system sometimes consumes more resources than its actual risk justifies.
Artificial intelligence is increasingly supporting vulnerability management in evaluating large amounts of data and recognising relevant patterns.
However, the actual prioritisation will continue to remain the task of experienced specialists.
„Despite AI in vulnerability management, I still need my own experience, expertise, and gut feeling to derive the right steps from the data for prioritisation.“
— Stefan Kappey, Service Owner at accompio
Complex prioritisation decisions require contextual knowledge about the respective company, which AI or a tool alone cannot provide.

accompio identifies vulnerabilities in your IT infrastructure and derives prioritised measures for remediation.
Vulnerability management is only effective at protecting companies when detection, prioritisation according to business context, and a reliable patching process are integrated. A well-thought-out Vulnerability Management sustainably reduces the attack surface and creates the foundation for further measures in the area of Cyber Security.

Stefan Kappey is Service Owner Vulnerability Management at accompio and supports companies in establishing structured vulnerability management processes.
Vulnerability management is the continuous process of identifying, assessing, prioritising, and remediating security flaws in IT systems. The aim is to reduce a company's attack surface.
A Vulnerability scan provides a snapshot at a specific point in time. Vulnerability management maps out the entire continuous process of detection, assessment, prioritisation and remediation.
Continuous, automated scanning is considered standard. Critical systems benefit from more frequent scans, as new vulnerabilities become known daily.
Patching closes a large portion of vulnerabilities but does not address configuration vulnerabilities such as weak passwords or open access. These require additional manual measures.
Classical IT systems, cloud environments, web applications, and increasingly also operational technology systems (OT) in production require structured vulnerability management.
No. AI analyses large data sets and supports pattern recognition. The ultimate prioritisation within the respective company context remains the task of experienced specialists.

Arrange an initial consultation