Technical Assurance & Offensive Security
Vulnerability Management as a Service
Continuous discovery, triage and remediation tracking — the boring work that prevents most breaches.
The situation
What the client receives
Schedule of deliverables
- Asset discovery and coverage assurance
- Scheduled authenticated vulnerability scanning
- Risk-based prioritisation (exploit availability, exposure, business criticality)
- Remediation SLA tracking and escalation
- Patch and configuration management process design
- Monthly service report and quarterly trend review
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- ISO/IEC 27001 A.8.8
- NIS2 Art. 21(2)(e)
- CISA KEV
- EPSS
- CVSS v4.0
Related services
Discuss this engagement
Tell us about the estate to be covered and the remediation SLAs you need to hold and we will set out the scope, the method and the reporting format.