END / END-05
Continuous vulnerability and patch management
Establish a recurring cycle to find vulnerabilities, prioritise them by exposure and impact, schedule remediation and verify closure. Scanning produces observations; management adds ownership and follow-through.

WHEN IT HELPS
A focused response
to a defined need.
Scan reports with no follow-up, unknown assets, uncontrolled patch delays or a need to prove critical issues are tracked to resolution.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Inventory
- authenticated collection where possible
- false-positive validation
- contextual prioritisation
- patch campaigns
- exceptions
- rescans
- team-level metrics
Deliverables
- Management policy
- scope and coverage
- vulnerability register
- assigned tickets
- remediation schedule
- verification evidence
- ageing and residual-risk dashboard
Acceptance evidence
Assets and owners are identified; priorities are approved; fixes are verified; exceptions are approved with expiry; metrics distinguish open, fixed and unverifiable issues.
DELIVERY
How the work is structured.
Approach
Inventory versions and applications; define policies; test on a representative group; deploy; verify coverage and exceptions; organise maintenance.
Prerequisites & responsibilities
Customer: inventory, deployment tools, support, application owners and windows. Provider: policies and integration; alert handling only if included.
Scope factors
Devices, OSs, compatibility, existing tools, policies and deployment effort. Subscriptions, daily management and SOC coverage are priced separately.
Questions to clarify
Who owns each asset? Who decides patch windows? Are vulnerabilities linked to actual exposure and critical applications?
IMPORTANT BOUNDARIES
Technical severity alone is insufficient. Scans may miss assets or disrupt some systems; scope, permissions and precautions must be approved.
Unsupported systems, exclusions and operational gaps are made explicit. Regression tests, fallback and response ownership are part of delivery.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A mid-sized company receives thousands of monthly findings. Project: group root causes, identify exposed assets and assign work packages. Target outcome: actionable backlog and closure evidence without equating closed-ticket counts with complete risk reduction.
Scenario 02
A provider hosts servers with limited maintenance windows. Project: risk-based scheduling, predeployment tests and interim measures. Target outcome: documented trade-offs; deferred patches remain visible and assigned to an owner.
Technology and reference context
Examples: vulnerability scanners, inventories and patching tools connected to change tracking; products selected after qualification.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
