Vulnerability Management
Enterprise vulnerability management without an enterprise team to run it.
Our analysts work through the findings, quantify the real risk and tell your IT team what to patch. Progress is reviewed with you every month.
Why the backlog never decreases
A scanner is very good at finding vulnerabilities and completely indifferent to whether you act on them.
Most organisations do not have a detection problem. They have a triage problem. The tool runs, the findings arrive, and somebody has to decide which of them are worth a change window, an outage risk and an argument with the business. That job often does not get done, which is why the same findings appear month after month.
Severity that ignores your estate
A score describes the vulnerability, not the machine it is running on. The same CVE on an internet-facing server and on a decommissioned test box carries the same number and completely different consequences.
Findings you have already dismissed
False positives return every cycle. Without someone maintaining the exceptions, your team re-investigates the same non-issues, and may skim the ones that matter.
No sense of what to do first
A list ordered by severity is not a plan. It says nothing about what can be patched, what needs a change window, or what your team could realistically close this month.
Nobody chasing it
Findings get raised and then become stagnant. Without regular reviews, the backlog becomes a number nobody looks at.
How the service runs
From scan output to a list your team can work through.
The platform finds the vulnerabilities. What follows needs people to decide what matters in your environment, raising it in a form your team can act on, and coming back to it every month.
-
01
Onboarding and asset scope
We agree what is in scope and scan across it, including the parts of the estate that are often missed, such as cloud workloads, remote endpoints, and anything a project left behind.
-
02
Continuous scanning
Scanning runs on a schedule against the agreed scope, so findings arrive continuously rather than in an annual batch.
-
03
Analyst review
Our team works through the output. False positives are removed, recurring exceptions are maintained, and findings are checked against what the asset does and who depends on it.
-
04
Risk quantification
Each finding is weighed in the context of your environment, taking into account exposure, asset criticality, compensating controls are already in place, and whether the vulnerability is being exploited in the wild.
-
05
Remediation raised with your team
The work is raised with your IT team in a form they can act on, ordered so that the top of the list is the right place to start.
-
06
Monthly service review
Progress is reviewed with you every month. What closed, what is still open, what is ageing, and what changed in the estate since last time.
Where the value is added
The platform scores the vulnerability. Our analysts provide the context.
Risk-based scoring is a real improvement on raw severity, and the platform does it well. It draws on threat intelligence to identify what is being exploited and adjusts its ranking accordingly.
What it cannot know is your business. Which server the finance system depends on. Which change window that application falls into. Which box is due to be decommissioned in six weeks and does not warrant the work.
That context is what turns a ranked list into a plan, and it is the part our analysts add.
Not everything is a vulnerability
The same review often surfaces configuration that has drifted from your own policies, controls that were switched on once and turned off during an incident, and permissions that were meant to be temporary. These are raised alongside the findings.
The boundary
We make sure you know what needs patching, and that it does not get forgotten.
Talanos
- Scanning coverage across the agreed scope
- Analyst review of every cycle's findings
- False positive removal and exception management
- Risk quantified against your environment
- Remediation raised with your team
- Monthly review of progress and ageing
Your team
- Applies the patches
- Owns the change process and the maintenance windows
- Decides what gets deferred, and tells us why
- Keeps control of your own infrastructure
Most infrastructure teams prefer it this way. Patching is where their change control, maintenance windows and knowledge of what will break all live. The triage that comes before it is our job.
Two services, two questions
Coverage is not the same as consequence.
Vulnerability management and penetration testing are often spoken about as though they are the same discipline. They answer different questions, and most organisations need both answers.
Vulnerability Management
What weaknesses exist across our estate?
- Continuous scanning, analyst review and tracking of known vulnerabilities
- Coverage and completeness: nothing missed
- Runs every month, alongside your remediation programme
Penetration Testing as a Service
What could an attacker do with them?
- Active, safe exploitation to prove which weaknesses chain into real compromise
- Impact and priority: what to fix first
- Runs when you change something, or to prove a fix worked
Most organisations need both. This service tells you the size of the problem and keeps it moving. Penetration testing tells you which part of it an attacker could reach.
How it is delivered
Runs on its own, or as part of the SOC.
Most clients take vulnerability management as part of our Managed SOC service. The same analysts who watch your environment for active threats are the ones reviewing your vulnerability findings, so the two are weighed against each other rather than arriving in separate reports from separate teams.
It also runs on its own, and works with the tooling you already have. Some clients hold their own Qualys licence and we operate it for them. Others use the vulnerability management built into Microsoft Defender or their SIEM. The platform varies; the analyst work and the monthly review do not.
Questions we are asked
What buyers want to know.
Do you apply the patches?
No. We tell you what needs patching, in what order and why, and we track it with you through the monthly service review. Your team applies the patches, because your team owns the change process and knows what depends on what.
Do we need our own Qualys licence?
Not necessarily. Some clients hold their own licence and we operate it on their behalf, which gives the fullest set of capability and visibility. Others use the vulnerability management already included in Microsoft Defender or in their SIEM subscription.
We will tell you honestly which route fits, including when your existing tooling is enough.
What is the difference between attack surface management and vulnerability management?
Attack surface management is concerned with what you have exposed: the assets, services and entry points visible from outside, including the ones nobody remembers deploying. Vulnerability management is concerned with the weaknesses in those assets once you know they exist.
In practice the first question feeds the second, which is why our onboarding starts with scope and asset discovery rather than with scanning.
What happens to findings nobody actions?
They are raised again, with their age attached, at the monthly review. Deferring something is a legitimate decision when there is a reason for it, and we will record the reason. What we will not do is let a finding disappear because it stopped being new.
How is this different from a penetration test?
A vulnerability scan identifies known weaknesses from a signature database. A penetration test exploits them to establish what an attacker could reach. Under PCI DSS these are separate obligations: Requirement 11.3 covers scanning, Requirement 11.4 covers penetration testing.
We deliver both, as separate services.
Which compliance obligations does this support?
Vulnerability scanning is a requirement in most regimes we see: PCI DSS Requirement 11.3, ISO/IEC 27001, SOC 2, NIS2 and DORA all expect regular scanning with evidence of remediation. The monthly review record is what most clients use as that evidence.
We support these obligations. We do not claim to deliver compliance on your behalf, and anyone who tells you a scanning platform does that is overselling it.
Ready to talk
Start with a conversation about what you are running right now.
Bring what you already have: the tool, the last set of findings, and how far through them your team got. We will tell you where the gaps are and whether this service would close them.