Vulnerabilities tracked to closure, not just listed
A continuous programme, not an annual report. Scanning, validation, prioritisation by business impact, and remediation tracking.
The challenge
An annual scan is a snapshot that is stale the day it lands. New CVEs ship every week; what matters is a loop that finds, ranks and closes — continuously.
Scope — included and not included
Included
- Recurring authenticated scanning
- Validation and false-positive removal
- Prioritisation by exploitability and business impact
- Remediation tracking to closure
- Monthly posture report
- KEV and exploit-activity watch
Not included
- Applying the patches ourselves
- Exploitation of findings — that is a pentest
- Application logic testing
- Emergency response — that is the incident response retainer
How it works
01
Baseline
First full scan, validated and ranked, so you know where you start.
02
Recur
Scheduled scans keep the picture current as your estate and the CVE feed change.
03
Prioritise
Each cycle ranks by what is exploitable and what it would cost you.
04
Track to closure
Findings stay open until fixed and verified — nothing disappears into a PDF.
What you receive
- →Validated, prioritised findings list, continuously current
- →Remediation tracker with owners and status
- →Monthly posture report with trend
- →Alerting on actively exploited vulnerabilities in your stack
What we need from you
- ·Target inventory
- ·Scan credentials
- ·A remediation owner on your side
- ·Maintenance windows where required
Timeline and engagement
Baseline in the first two weeks, then recurring monthly. 30-day notice.
Standards, methods and tooling
OpenVASNessusDefectDojoCVSS 4.0CISA KEVPortal hosted in Canada
Frequently asked questions