Skip to content

Home Expertise / Endpoints & vulnerabilities

END / END-05

Continuous vulnerability and patch management

Establish a recurring cycle to find vulnerabilities, prioritise them by exposure and impact, schedule remediation and verify closure. Scanning produces observations; management adds ownership and follow-through.

WHEN IT HELPS

A focused response
to a defined need.

Scan reports with no follow-up, unknown assets, uncontrolled patch delays or a need to prove critical issues are tracked to resolution.

AT A GLANCE

Family
Endpoints & vulnerabilities

Engagement
Implementation or recurring

Reference
END-05

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Inventory
  • authenticated collection where possible
  • false-positive validation
  • contextual prioritisation
  • patch campaigns
  • exceptions
  • rescans
  • team-level metrics

Deliverables

  • Management policy
  • scope and coverage
  • vulnerability register
  • assigned tickets
  • remediation schedule
  • verification evidence
  • ageing and residual-risk dashboard

Acceptance evidence

Assets and owners are identified; priorities are approved; fixes are verified; exceptions are approved with expiry; metrics distinguish open, fixed and unverifiable issues.

DELIVERY

How the work is structured.

Approach

Inventory versions and applications; define policies; test on a representative group; deploy; verify coverage and exceptions; organise maintenance.

Prerequisites & responsibilities

Customer: inventory, deployment tools, support, application owners and windows. Provider: policies and integration; alert handling only if included.

Scope factors

Devices, OSs, compatibility, existing tools, policies and deployment effort. Subscriptions, daily management and SOC coverage are priced separately.

Questions to clarify

Who owns each asset? Who decides patch windows? Are vulnerabilities linked to actual exposure and critical applications?

IMPORTANT BOUNDARIES

Technical severity alone is insufficient. Scans may miss assets or disrupt some systems; scope, permissions and precautions must be approved.

Unsupported systems, exclusions and operational gaps are made explicit. Regression tests, fallback and response ownership are part of delivery.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A mid-sized company receives thousands of monthly findings. Project: group root causes, identify exposed assets and assign work packages. Target outcome: actionable backlog and closure evidence without equating closed-ticket counts with complete risk reduction.

Scenario 02

A provider hosts servers with limited maintenance windows. Project: risk-based scheduling, predeployment tests and interim measures. Target outcome: documented trade-offs; deferred patches remain visible and assigned to an owner.

Technology and reference context

Examples: vulnerability scanners, inventories and patching tools connected to change tracking; products selected after qualification.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.