Cybersecurity
The full domain, and the other capabilities within it.
Turn a scanner's output into a process that actually closes things.
Vulnerability management is asset discovery, authenticated scanning, prioritisation, remediation and verification, run as a cycle. The scanning is the easy part. The capability is the operating process around it: who owns a finding, what the deadline is per severity, and what happens when the deadline passes.
Most organisations that say they have a problem here do have a scanner. What they have is a report with thousands of findings, no owner per system, and no agreed definition of critical — so nothing is prioritised and nothing is closed.
If more than one of these is true, this is usually the right place to start.
| Deliverable | What it contains |
|---|---|
| Asset inventory | Discovered assets reconciled against your records, with ownership assigned and the unclaimed ones escalated. |
| Scanning design | Scope, credentials, schedule and the coverage figure — with what is deliberately excluded and why. |
| Prioritisation model | How severity, exploitability and exposure combine into a remediation deadline, agreed with the teams who will meet it. |
| Operating process | Ownership, SLA per severity, exception workflow, and the monthly report that shows trend and ageing rather than a raw count. |
A reference, not a template. Your estate decides which parts apply and in what order they arrive.
Targets are agreed with you before the work starts, and reported against for its duration.
Scanning produces findings; management closes them. The difference is coverage you can prove, an owner per system, deadlines tied to severity, and an exception route that is recorded rather than informal. Without those, a scanner is a report generator.
An unauthenticated scan sees what an unauthenticated attacker sees from the network. It cannot see installed software versions or missing patches on a hardened host, so it under-reports substantially — and the gap is invisible unless you compare the two.
By exploitability and exposure rather than by score. An internet-facing service with a known exploited vulnerability outranks a higher-scored issue on an internal host with no known exploit. That reordering is usually what makes the backlog tractable.
No. Vulnerability management is continuous, broad and automated. A penetration test is periodic, narrow and human, and it finds classes of problem — chained logic flaws, business logic abuse — that no scanner finds. They answer different questions.
They exist in every estate: unsupported operating systems, medical or industrial equipment, applications certified against one version. They go through the exception process with compensating controls and a named approver, so the risk is accepted deliberately rather than by silence.
Yes — it is one of the capabilities most often delivered as a managed service, because the value is in running the cycle consistently rather than in any single scan. The process and the ownership model stay yours either way.
The full domain, and the other capabilities within it.
Segmentation, next-generation firewalling and network detection designed as one control set — so a compromised host stays a compromised host.
EDR deployment, detection engineering and automated containment across endpoints, servers and identities — tuned to your estate, not to a vendor demo.
The fastest way to a useful answer is a short, scoped look at what you already have.