Skip to content
§
§ · build vs buy

Vulnerability Remediation Management Software: Custom Build or Off the Shelf

Buy. One scanner, a few hundred assets and one infrastructure team is not an aggregation problem, and Tenable or InsightVM with a maintained asset register beats any build.

Internal tools product interface illustration for Vulnerability Remediation Management Software Build vs Buy Guide.
The short answer

Buy. One scanner, a few hundred assets and one infrastructure team is not an aggregation problem, and Tenable or InsightVM with a maintained asset register beats any build. Look at building past roughly fourteen thousand assets, or sooner when your ownership rules cannot be expressed as tags and you are already maintaining a spreadsheet beside a product you bought.

What Nucleus, Vulcan and Brinqa already solve

Two honest statements before anything else. Keep your scanners. And if you have the multi-scanner problem but a fairly clean asset register and conventional ownership, evaluate the aggregation products properly before commissioning anything, because a subscription beats a project when the shoe fits.

Tenable and Qualys have decades of detection coverage and their finding quality is not your problem. Rapid7 InsightVM is a competent single-tool answer for a mid-sized estate and, with a maintained register and a monthly review meeting, will serve a small team better than a platform. Wiz and the cloud posture tools cover ground the traditional scanners never will.

The remediation aggregation vendors exist precisely because scanners cannot arbitrate between themselves, and they solve a real part of it. Nucleus Security is strong on connector breadth and finding normalisation. Vulcan Cyber puts effort into remediation workflow rather than reporting. Brinqa leans on the risk model and does the configurable scoring well. Seemplicity focuses on getting work into the queues that fixing teams actually use. Cisco Vulnerability Management brings exploit intelligence into the ranking. All four will deduplicate across your scanners, produce a defensible backlog number, and push tickets into Jira or ServiceNow.

Buy if that description matches you. Most security teams reading this should be running a product, not a project, and a firm that tells you otherwise before asking about your configuration management database is selling.

Where they stop: ownership rules that are not tags

Here is the specific workflow that breaks. A vulnerability management lead is asked for one slide before an audit committee. The slide should say whether the organisation is getting safer. What she has is ninety-four thousand open findings across three tools, a number that went up last quarter because the estate grew, and no way to say which of them represent real exposure. She knows perhaps a hundred genuinely matter. She cannot prove which hundred, and she cannot show anyone is fixing them, because remediation happens in six team backlogs across two ticketing systems and one spreadsheet the database group maintains.

Every product in this category ships an ownership model based on tags, and every real estate has ownership rules messier than tags. This subnet belongs to that team except for the four hosts an acquisition brought in. Container images inherit ownership from the repository that built them. Cloud accounts follow a naming convention that changed in 2023 and was never backfilled. Encoding your actual rules, with an inspectable resolution order and a named fallback human whose queue is visibly embarrassing, is the work, and it is the part a configurable product cannot reach.

Deduplication has the same shape one layer down. A finding is a triple of weakness, asset and location, and each is reported differently by each tool. Qualys reports by address, another scanner by hostname, a container scanner reports the same underlying library in an image. That is one weakness and three tickets. Resolving asset identity across hostname, address at a point in time, cloud instance identifier and agent identifier, with a confidence score and a manual merge path, is the foundation every other number depends on. The findings that will not deduplicate on their own are the ones with no Common Vulnerabilities and Exposures identifier at all: misconfigurations, weak ciphers, end-of-life software, policy failures.

The arithmetic: per asset pricing versus the cost to build

Aggregation platforms usually price per asset, sometimes per finding source as well. Work it from your own count rather than a projection.

Take your true asset count, meaning what the scanners actually report rather than what the register claims, because those two numbers differ and the invoice follows the first. If your platform charges $6 per asset per year, twenty thousand assets is $120,000 annually and forty thousand is $240,000. Add the internal cost of whoever maintains the spreadsheet beside it, because that spreadsheet is the tell that the product does not fit.

Against that, a first release covering scanner connectors, asset identity resolution, deduplication, the ownership engine and two-way ticketing integration runs $80,000 to $160,000. Take the middle at $120,000, add migration, add year two support, and the two-year figure is about $165,000.

The crossover therefore sits near fourteen thousand assets at that rate. Below it, licence a product. Above it, ownership starts winning and keeps winning, because per-asset pricing scales with an estate that only ever grows while a build does not.

Asset count is the weaker trigger though, and we would rather you used the other one. If you have already bought an aggregation product and are still maintaining a spreadsheet next to it, the crossover has already happened regardless of your asset count. That spreadsheet is your requirements document.

What a custom build actually costs

  • First release: $80,000 to $160,000 in 12 to 18 weeks. Connectors for the two scanners producing most of your findings, asset identity resolution with manual merge, deduplication including findings with no common identifier, the ownership rules engine with a visible fallback, and two-way Jira or ServiceNow integration.
  • Full platform: $200,000 to $450,000 phased across 6 to 12 months. Adds your own risk model, exception workflow with named acceptors and expiry, service level clocks by risk tier, executive reporting, and container or cloud posture sources.

Migration runs 10 to 25 percent of the build, and here it is mostly reconciliation rather than data movement: mapping historical exceptions and risk acceptances out of email and spreadsheets into records with owners and expiry dates. Year two runs 15 to 20 percent of the build annually, and in this category it is genuine work, because scanner interfaces change and new finding sources appear.

What drives cost up: the number of scanning tools, since several have unpleasant pagination and rate limiting. The state of your configuration management database, which is the single biggest schedule variable, because ownership rules built on a stale register produce confident wrong answers. Multiple business units with different service levels and risk appetites. And any operational technology or medical device estate, where scanning itself is constrained and the data arrives differently.

What keeps it down: start with the two scanners producing most of your findings and the three teams owning most of your estate. The long tail can wait a quarter.

The four situations where building wins

  • Regulatory fit. Evidence requirements shape the workflow rather than the report. PCI DSS expects critical patches applied within a defined window, federal agencies work to the remediation deadlines attached to the CISA Known Exploited Vulnerabilities catalogue under Binding Operational Directive 22-01, and cyber insurers now ask remediation timeframe questions at renewal. Evidence that is generated rather than assembled is worth money in that conversation.
  • Scale economics. Past roughly fourteen thousand assets, where per-asset pricing on a growing estate outruns what owning the system costs.
  • A workflow that is your competitive advantage. Your risk model. Scanners score against a general model such as the Common Vulnerability Scoring System, improved by the Exploit Prediction Scoring System and known exploitation data, and all of those describe the vulnerability rather than your exposure to it. A model that knows a host has no inbound path, or that a compensating control blocks the route, is yours and nobody sells it.
  • Integration sprawl across three or more systems. Two or three scanners, a cloud inventory, a configuration management database, and two ticketing platforms. When work has to live where the fixing teams already work, the join is the product.

How to decide in a week

One number decides this, and you can have it by Wednesday.

Take your current open findings and compute the unowned rate: the share with no named individual attached, not a team queue, an individual. Then pick twenty findings at random from the critical tier and ask, for each, who accepted it and on what date. Give it two days. If the unowned rate is low and someone can answer for most of the twenty, you have a working process and you should keep paying your subscription.

If most of the twenty come back with a team name and no person, you have found the real problem, and it is worth saying plainly that it is not a software problem yet. Findings sit open for eighteen months because no named human accepted them, not because they are hard to fix. Report the unowned rate weekly for a month before spending anything. It goes down fast once people can see it, and if that alone fixes your backlog you have saved a project.

Then, if the rules genuinely cannot be expressed in your product, move to a paid discovery phase. Ours runs two to three weeks and ends with a signed product requirements document covering asset identity resolution, the deduplication approach for findings with no common identifier, the ownership resolution order with its fallback, the ticketing contract in both directions, and acceptance criteria measured against your real backlog. That document keeps a fixed price fixed and you own it either way.

Digital Heroes is wrong for you if you want a managed security service, or a supplier holding your exposure data in their tenancy. We build systems you own. Our India LLP, US LLC and UK LTD entities mean the intellectual property assigns under your own law. More than fifty specialists, in-house products including Section Vault and ShopScore, a named team you meet before signing, and a record checkable on Clutch, Trustpilot, Fiverr Vetted Pro and D-U-N-S.

Book a 30-minute call with Digital Heroes and get a written plan and a fixed quote within 48 hours.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. The average developer spends more than 17 hours a week dealing with maintenance issues such as debugging and refactoring, and about four of those hours on 'bad code' - waste that equates to nearly $85 billion annually worldwide in opportunity cost. Source: Stripe (2018) →
  2. McKinsey found that tech debt can amount to 20-40% of the value of a company's entire technology estate before depreciation, and CIOs report that 10-20% of the budget for new products is diverted to resolving tech-debt issues. Source: McKinsey & Company (2020) →
  3. Workers can expect 39% of their existing skill sets to be transformed or become outdated over 2025-2030; 77% of employers plan to upskill their workforce, and 63% identify skill gaps as the biggest barrier to business transformation. Source: World Economic Forum (2025) →
  4. The right combination of digital transformation actions can unlock as much as US$1.25 trillion in additional market capitalization across Fortune 500 companies, while the wrong combinations put more than US$1.5 trillion at risk; companies with all three core factors (strategy, aligned technology, and change capability) saw a 5% market-value lift relative to peers. Source: Deloitte (2023) →
FAQ

Frequently asked questions

How much does a custom vulnerability remediation platform cost?

A first release covering scanner connectors, asset identity resolution, deduplication, the ownership rules engine and two-way ticketing integration runs $80,000 to $160,000 over 12 to 18 weeks. Adding your own risk model, exception workflow, service level clocks, executive reporting and cloud posture sources takes it to $200,000 to $450,000 across 6 to 12 months, plus migration and annual support.

Should we replace our scanners as part of this?

No. Keep at least one and probably the two producing most of your findings. Detection coverage built over decades is not something a build replicates, and it is not where your problem lives. The broken step is everything after the finding: deduplication, ownership, getting work into the right queue, and knowing when something is closed for real rather than closed because a host was rebuilt.

What happens if a scan fails or comes back partial?

A missing scan must never look like remediation, and this is the quiet failure mode of every platform in the category. Findings that vanish because a scanner could not reach a subnet should raise an exception rather than silently closing. Ask any vendor and any developer this question directly, because the answer separates people who have run these systems from people who have demonstrated them.

Who owns the code and the exposure data?

You do, from the first commit, and it belongs in the contract before kickoff along with the cloud accounts and every scanner credential held in your name. A system holding your complete exposure picture is a poor thing to rent from a supplier you cannot replace. Digital Heroes assigns through its India, United States and United Kingdom entities so the transfer happens under your own law.

How do you deduplicate findings that have no CVE identifier?

With an explicit mapping table that somebody maintains, and by accepting that it needs maintenance rather than pretending otherwise. Misconfigurations, weak ciphers, end-of-life software and policy failures are reported differently by every tool and are the least likely to collapse on their own. Any approach relying on string matching across scanner descriptions produces numbers nobody in the room will trust.

Can we build only the ownership engine and keep our aggregation product?

Often yes, and it is the cheapest way to test the thesis. An ownership layer reads findings from what you already licence, resolves an owner through an inspectable order of explicit assignment, cloud tags, network zone and register, and falls back to a named person with a visible queue. It fixes the reason findings sit open without touching deduplication or scoring.

How long before the backlog number becomes trustworthy?

Twelve to eighteen weeks to a first release, but trust arrives with asset identity rather than with delivery. Until hostname, address, cloud instance identifier and agent identifier resolve to one object, deduplication either merges two hosts and hides a real finding or fails to merge and inflates the count. Budget the first four weeks for that and resist demonstrating dashboards before it is done.

What is the difference between a scanner and a remediation management platform?

A scanner finds weaknesses on assets it can reach and reports them in its own identifiers. A remediation platform arbitrates between scanners, resolves asset identity, decides who owns each finding, pushes work into the systems fixing teams already use, tracks exceptions with named acceptors and expiry, and produces evidence. Buying more scanners will never solve a problem that lives entirely after detection.

How should exceptions and risk acceptances be handled?

As first-class records rather than email. Each needs a documented compensating control, a named acceptor with the authority to accept it, an expiry date, and automatic reappearance in the queue when it lapses. Without that, the same finding is rediscovered and re-escalated every quarter by whoever is new, and your backlog grows forever because nothing is ever legitimately closed.

Is it worth building if our asset register is out of date?

Not yet, and this is the most common reason a build disappoints. Ownership rules built on a stale register produce confident wrong answers, and the platform gets blamed for the register. Spend a quarter reconciling the register against what the scanners actually see, then reassess. That work has to happen either way and doing it first makes every subsequent estimate more honest.

How long does it take to build an internal tool from scratch?

A working first version typically ships in 4 to 8 weeks, and larger multi-module tools run 10 to 16 weeks. Across Digital Heroes internal tool projects the schedule splits into roughly one week of process mapping, 3 to 6 weeks of build, and 1 to 2 weeks of testing with your actual staff. The most common delay is not development but waiting on the client for sample data and workflow decisions, so name one internal owner before kickoff.

What are the biggest mistakes first-time software buyers make?

Choosing the lowest bid, paying more than 30-40% upfront instead of on milestones, skipping a written specification, and having no maintenance plan for after launch. The most expensive of the four in Digital Heroes rescue projects is the missing spec: without written acceptance criteria, done becomes an argument instead of a checklist, and every disagreement resolves in the vendor's favor. Fix those four and you have avoided most of the ways these projects fail.

Who owns the code when an agency builds our internal tool?

You should, outright, with full IP transfer in the contract and the code delivered to a repository you control, such as your own GitHub organization. Digital Heroes transfers complete ownership on final payment as standard practice, and any agency that keeps the code or licenses it back to you is building a dependency you will pay for later. Confirm you also own the hosting, domain, and database accounts, since many of the vendor disputes Digital Heroes gets called into involve infrastructure registered under the agency's name.

Who owns the code when an agency builds my software?

You should, completely, through a written intellectual property assignment that transfers everything on final payment; without that clause, copyright stays with whoever wrote the code by default. Insist that the repository lives in your own GitHub organization from day one and that hosting, domains, and third-party accounts are registered to you. Also check for licenses to the agency's proprietary frameworks buried in the contract, because those can make switching vendors practically impossible even when you own your own code.

At what point does Retool cost more than building a custom tool?

The crossover usually lands between 25 and 50 daily users. At Retool's published Business rates of $50 per standard user and $15 per end user monthly, a 40-person deployment with a typical seat mix runs roughly $9,000 to $15,000 per year, every year, while a comparable custom tool built once for $20,000 to $30,000 carries no per-seat fees and costs about 15 to 20 percent of the build price annually to maintain. On a three-year horizon, custom comes out ahead for most growing teams in Digital Heroes engagements.

Should I hire a freelancer or an agency for my software project?

A skilled freelancer is the right call for a single-discipline scope under roughly $15,000, like a website, a plugin, or one integration. Above that, projects need design, backend, testing, and project management at once, and a solo builder becomes the single point of failure: if they get sick or take a bigger client, your project simply stops. Agencies bill 20-40% more per hour but carry continuity, code review, and someone to escalate to, which is what you are actually buying.

Can custom software connect to the tools we already use, like QuickBooks, Stripe, and Google Workspace?

Yes, and connecting your existing tools is one of the main reasons to build custom: mainstream platforms like QuickBooks, Stripe, Shopify, and Google Workspace all publish documented APIs. Budget 1 to 3 weeks of work per integration depending on API quality and how much data flows in both directions. Ask any vendor whether they have integrated with your specific tools before, because quirks like QuickBooks' OAuth token handling and API rate limits get learned on someone's project, and it should not be yours.

Is custom software more secure than off-the-shelf SaaS?

Neither is secure by default; security tracks the practices of whoever builds and operates the system, not the model. SaaS gives you the vendor's certifications and patching but puts your data in a shared multi-tenant platform on their terms, while custom gives you full control over data residency, access rules, and compliance requirements like HIPAA, with the responsibility sitting with you and your agency. Before hiring anyone for a system holding sensitive data, ask for their security checklist: encryption at rest and in transit, an OWASP Top 10 review, role-based access, and a penetration test before launch.

Is a custom internal tool secure enough for HR records and financial data?

A properly built custom tool is generally safer for sensitive data than the shared spreadsheet it replaces, because you get role-based access, audit logs, encrypted storage, and the ability to cut one person's access instantly. Ask the agency specifically for encryption in transit and at rest, permissions down to the field level, and an audit trail showing who viewed or changed each record. If HIPAA, GDPR, or SOC 2 expectations from enterprise clients apply to you, raise it before the quote, because compliance features add real scope.

How many SaaS seats do we need before building custom becomes cheaper?

The crossover usually shows up between 20 and 50 seats on premium tiers. Salesforce Enterprise lists at $165 per user per month, so 40 users cost about $79,000 a year in subscriptions, which is real money against a custom system you would own outright. Run the comparison over three years: if subscription spend beats the build cost plus 15-20% annual maintenance, custom wins on price before you even count workflow fit.

Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading

Published · Last updated .

Online now

Hi there. How can we help you today?

Reply