Asset discovery
Confirm scoped hosts, cloud assets, domains, and networks before recurring scans begin.
Managed Vulnerability Scanning
Managed vulnerability scanning provides scheduled discovery, authenticated scanning where appropriate, triage, reporting, and remediation tracking so vulnerability management stays current between point-in-time tests.
Service detail
Confirm scoped hosts, cloud assets, domains, and networks before recurring scans begin.
Use agreed credentials or agents where appropriate to improve coverage and reduce false confidence.
Review scanner output for exploitability, exposure, business context, known noise, and remediation urgency.
Provide regular reports, trend summaries, and urgent notifications for high-risk findings.
Track open findings, retest fixed issues, and highlight recurring root causes.
Escalate critical exposures with clear evidence, affected assets, and practical next steps.
Managed vulnerability scanning is an ongoing vulnerability management service rather than a one-off test. It uses scheduled scanning, authentication where appropriate, review of scanner output, and reporting that helps teams remediate consistently.
Useful for organisations with changing infrastructure, compliance reporting needs, limited internal vulnerability management capacity, or a requirement to monitor internet-facing and internal assets between penetration tests.
Prerequisites
The prerequisite pack covers asset lists, authenticated scanning options, safe scan windows, allow-listing, cloud scope, notification routes, and remediation ownership.
PDF checklist for assets, scan cadence, credentials, safe windows, and reporting contacts.
Download PDFFAQ
Managed scanning is recurring vulnerability monitoring and triage. A penetration test is a deeper point-in-time assessment that manually validates exploitability and impact.
Cadence is agreed during scoping. Common options include monthly, quarterly, or more frequent scanning for high-change external, internal, cloud, or authenticated assets.
Yes. Authenticated scanning can improve coverage across servers, endpoints, applications, and cloud environments where suitable access can be provided safely.
Critical or actively exploitable findings should follow an agreed escalation route so technical owners can review and respond without waiting for routine reporting.
Yes. Scope can include external assets, internal networks, cloud environments, and authenticated assets, subject to access, authorisation, and safe scanning constraints.