Technical Assurance & Offensive Security

Vulnerability Management as a Service

Continuous discovery, triage and remediation tracking — the boring work that prevents most breaches.

The situation

Scanning is easy; deciding what to fix first and proving it was fixed is where organisations fail.

We run the full cycle as a managed service: asset discovery, authenticated scanning, risk-based prioritisation informed by exploitability and exposure rather than raw CVSS, remediation tracking with owners and SLAs, and monthly reporting that shows the trend line rather than the noise.

What the client receives

Schedule of deliverables

  1. 01Asset discovery and coverage assurance
  2. 02Scheduled authenticated vulnerability scanning
  3. 03Risk-based prioritisation (exploit availability, exposure, business criticality)
  4. 04Remediation SLA tracking and escalation
  5. 05Patch and configuration management process design
  6. 06Monthly service report and quarterly trend review

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • ISO/IEC 27001 A.8.8
  • NIS2 Art. 21(2)(e)
  • CISA KEV
  • EPSS
  • CVSS v4.0

Discuss this engagement

Tell us about the estate to be covered and the remediation SLAs you need to hold and we will set out the scope, the method and the reporting format.

Contact us