New CVEs are published daily. The CISA Known Exploited Vulnerabilities catalog is updated multiple times per week. A vulnerability that was not present in your last quarterly scan can be identified and actively exploited by the time your next scan runs. Continuous scanning changes the model - new vulnerabilities are identified within 24 hours and fast-tracked for remediation.
We switched from quarterly to continuous vulnerability scanning. In the first month, BetterWorld Technology identified 12 critical vulnerabilities that would not have appeared until our next quarterly scan - two of which were on the CISA KEV list.
CISO, Healthcare Technology Company