This document discusses cyber security for critical infrastructure and the importance of identifying unknown or zero-day vulnerabilities. It describes how fuzz testing, a technique that involves feeding unexpected input to a system to trigger crashes or failures, can be used to find these unknown vulnerabilities before attackers discover and exploit them. The document outlines a process for conducting unknown vulnerability management that involves identifying targets, testing devices using various fuzzing methods, and generating detailed reports of any issues found to facilitate rapid remediation. Fuzz testing maturity models are also discussed as frameworks for conducting comprehensive fuzz testing programs to systematically uncover previously unknown vulnerabilities in networks and devices.