One number for the board.
Program risk you can defend, not a 32k-row CSV. Attainment, KEV exposure, and per-BU rollups in one view.
Security stops owning risk it can't fix. Every scanner finding lands on a named human — the one who can actually patch.
Program risk you can defend, not a 32k-row CSV. Attainment, KEV exposure, and per-BU rollups in one view.
The engine groups affected hosts by owner. Each owner sees their ~200, with SLAs you actually negotiated.
Every finding lands on a named human with a clock. The handoff happens — and shows up in the audit log.
Gartner's CTEM defines five stages — and every legacy scanner stops one stage short. Stage 5 is where vulnerabilities meet a named human with an SLA. Without it, findings pile up in a shared inbox and stay open.
Every finding from every scanner is fused with your asset truth, prioritized, and cascaded from a named owner up to the CISO view — with SLAs the org can defend.
A real CVE rarely hits one asset. It hits hundreds, across many owners. Watch one move from drop to closed — and see exactly what each tier of the org receives along the way.
Most tools report unowned servers and network gear and leave you to chase them. The unowned queue is the killer of every infrastructure vulnerability program. We close it.
ZeroInSec fuses six signals — CMDB, AD groups, IPAM subnets, DHCP scopes, patch-system owners, and on-call schedules — into a probabilistic owner score, then assigns.
Tuned for infrastructure — servers, network devices, hypervisors, storage.
| Host | Why unowned | Source | Suggested |
|---|---|---|---|
| bmz-edge-04.acme.com | CMDB owner field empty | IPAM + AD group | k.alvarez |
| erdc-bgios.acme.com | Owner left company 112d ago | AD lifecycle | a.bishop |
| sw-core-eu-09.acme.com | Network device, no CMDB row | IPAM + DHCP scope | m.tanaka |
| db-eu-prod-12.acme.com | CMDB stale > 180d | Patch system owner | j.silva |
subnet_24 · min_matches 3 · max conf 95%subnet_16 · min_matches 5 · max conf 85%adjacent_ip · min_matches 2 · max conf 90%hierarchy_match · min_matches 2 · max conf 88%scanner_tag · min_matches 3 · max conf 78%asset_type_match · min_matches 3 · max conf 80%criticality_match · min_matches 3 · max conf 75%weight, min_confidence, and min_matches in SuggestionConfig — kill-switch any source per tenant. Suggestions aggregate via suggestion_aggregator; multi-source matches rank higher. Auto-assign fires at ≥ 0.95 confidence after constraint validation.| Tool | Ownership model | Behavior on gaps | vs. ZeroInSec |
|---|---|---|---|
| Qualys | Tag-based · manual | Reports unowned, doesn't fix | Suggests + assigns |
| Tenable | Asset tags · imported | Inherits CMDB gaps as-is | Closes CMDB gaps |
| ServiceNow | CMDB record only | Stale if CMDB stale | Cross-source fusion |
| Brinqa | Rules engine · you write | Needs hand-tuned rules | Suggested out of box |
| ZeroInSec | Multi-source fusion + ML confidence score | Auto-closes via Suggestion Engine | — |
One canonical record per asset, deduplicated across Qualys, Tenable, Wiz, CrowdStrike, CMDB, and tickets.
Severity × asset criticality × exploit signal (KEV, EPSS). Not a CVSS leaderboard.
Asset Owner Suggestion Engine reads CMDB, AD, cloud tags, and commit history to name a human for every host. No asset left unowned.
SLA clocks, escalations, and approvals keep the queue moving — and cascade visibility from owner up to CISO.
Every finding lands with an asset, an owner, and a clock. When the clock breaks SLA, the right engineering team gets paged — not the security inbox.
| Vulnerability | Asset | Sev | SLA | Owner |
|---|---|---|---|---|
XZ Utils backdoor — sshd auth bypassCVE-2024-3094 | erdc-bgios.acme.com | critical | +147d | Unowned |
OpenSSH regreSSHion — pre-auth RCECVE-2024-6387 | erdc-bgios.acme.com | critical | +112d | SRE / Core |
FortiOS SSL VPN out-of-bounds writeCVE-2024-21762 | bmz-edge.acme.com | high | +96d | Platform / Edge |
Zimbra postjournal — unauthenticated RCECVE-2024-45519 | bmz-edge.acme.com | medium | +34d | Platform / Edge |
Apache Struts file upload path traversalCVE-2023-50164 | app-api.acme.com | low | -3d | App / API |
Connect a scanner and ZeroInSec routes every finding to a named owner, with SLAs the org can actually defend.