Proposal
Vulnerability management
Periodic scanning of the environment, analysis of what comes out and, above all, someone following the remediation queue until it closes. The difference between this and a one-off assessment is the verb: an assessment finds, management chases. Most companies suffer less from a shortage of reports than from last quarter's report still carrying the same open items.
No price appears on this page. Scope does: what we do, how we run it, who runs it and what is not included. The people who read your request are the ones who will look after you, and they come back with the proposal and with time to talk it through.
Vulnerability management
Recurring scans, with someone chasing the fixes.
How we run it
What this work consists of
This is the service that turns scanning into a routine and puts someone chasing the remediation queue until every item is closed. The difference from a one-off assessment is in the verb: the assessment finds, the management pursues. Most companies do not suffer from a lack of reports. They suffer because last quarter's report still has the same items open.
The frequency follows the pace of your environment. Every three months meets standards requirements and works for environments that change little. Monthly, on top of the scans, you get remediation follow-up and progress indicators: how many items opened, how many closed, how long they stayed open. In continuous mode, anything critical reaches you as soon as it appears, without waiting for the next cycle.
From you, we need the asset scope, access to scan them, and a point of contact on the IT team to receive the remediation queue. You receive the scans at the agreed frequency, with analysis in every round. From the monthly cadence up, tracking of each item until it closes and progress indicators are included.
How we conduct it, stage by stage
Planning and authorisation
We agree the scope in writing and set the windows, the emergency contacts and the formal authorisations. No test starts without that.
Execution
We run the test cycle within the authorized window and scope, starting with what usually breaks first. Every finding is recorded with the evidence and the step-by-step needed to reproduce it later.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
Remediation follow-through
We chase the queue until each item closes, with a date and an owner. Finding things is the easy part.
What is not included
- Applying fixes and updates to systems, which stays with your IT team
- Exploiting the flaws found, which is the pentest
- Tool licenses when the client prefers to use their own
- Real-time attack monitoring, which is security operations
- Remediation queue tracking on the quarterly cadence, which only begins with the monthly plan
- Guaranteed closure deadlines for each item, which depend on the team doing the fixing, not on who tracks it
- Scanning assets that enter the environment without being added to the agreed scope: we scan what was agreed, and the list is updated with you
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.