Smarter Week

How to automate it

How to automate “prioritize vulnerability scan findings and chase patch owners”

Here are 2 ways to spend less time on this, best first. Each comes with steps you can follow today.

60 min
typically, once a week
50%
of the time can be automated
Some setup
to set up

Fix 1 of 2

AutomationBest fix

Prioritize findings by real risk and auto-ticket the owner

Instead of working the full scanner list, filter to what is exploitable and exposed, and let the tool open tickets for the owning team with due dates.

Typically saves about 45% of the time4 h to set up
  1. 1Filter findings by known exploited (CISA KEV), exploit likelihood (EPSS) and internet exposure.
  2. 2Map assets to owning teams using tags or your CMDB.
  3. 3Turn on automatic ticket creation in Jira or ServiceNow from Wiz, Snyk, Tenable, Qualys or Rapid7, with SLAs by severity.
  4. 4Report on overdue tickets instead of chasing individuals.

Tools: Wiz · Snyk · Tenable · Qualys · Rapid7 · Jira or ServiceNow

Fix 2 of 2

Automation

Let Dependabot or Renovate open upgrade PRs, grouped and auto-merged when safe

Bots open small upgrade PRs with changelogs and auto-merge patch updates that pass tests. A coding agent can handle the breaking ones.

Typically saves about 50% of the time1 h to set up
  1. 1Turn on Dependabot (GitHub) or install Renovate.
  2. 2Group minor and patch updates into one weekly PR per ecosystem to cut noise.
  3. 3Enable auto-merge for patch updates that pass CI.
  4. 4For major upgrades, assign the PR to a coding agent to fix breaking changes, then review.

Tools: Dependabot · Renovate · Snyk · Claude Code, OpenAI Codex, Cursor, GitHub Copilot agent mode or Devin Desktop (ex-Windsurf)

Quick wins

Have you tried…

Do Dependabot or Renovate open your dependency upgrade PRs automatically?
These bots watch your packages and open small PRs for each update, with release notes. Safe updates can merge themselves when tests pass.

Who does this task

Roles in our library that list this as one of their common tasks. Each guide covers the rest of that role’s week.

HourLeak · the 8-minute work audit

How many hours does this cost you?

The free 8-minute check works out where your week goes and gives you your top fixes. The team scan does the same for everyone and adds it up, so you know which leaks to fix first.

Answers are anonymous. Leaders only see team totals.

Other common tasks for IT / Systems administrators