Retainer · Baseline coverage

Vulnerability Management (Retainer)

The recurring layer underneath your annual penetration test — regular scanning across your estate, every finding triaged by a human, and remediation tracked until it actually closes.

A test once a year tells you where you stood that week. This is the discipline that covers the other fifty-one.

We have written at length about why a vulnerability scan is not a penetration test, and we are not going to contradict ourselves here. A scanner finds known, published weaknesses in things it recognises. It cannot chain two low-severity findings into a domain compromise, and it cannot reason about your business logic. That is what a penetration test is for.

But most of what goes wrong between tests is ordinary: a host that missed a patch cycle, a forgotten server someone spun up, a library with a new CVE filed against it. Those do not need an operator to discover. They need someone to look regularly and take the results seriously. This retainer is that discipline, bought as a service — deliberately the cheapest thing we sell, because it should be the first thing you have rather than the last.

What's included

Authenticated and unauthenticated scanning — across the internal ranges, external addresses and web applications you define.

Manual triage of every finding — an operator removes what doesn't apply and corrects the severity inflation scanners are prone to.

A ranked, actionable report — short enough to read, with the reasoning attached and a clear delta since last cycle.

Remediation tracked to closure — we verify fixes rather than take them on trust, and flag anything ageing badly.

A scope review each cycle — so newly added assets don't quietly fall outside coverage, which is how most estates drift.

Why not just run a scanner yourself

Nothing stops you licensing one. Most organisations that do end up with thousands of open findings, an inflated severity distribution and no idea where to start — and after three months, nobody opens the console. The value here isn't the tool. It's that an operator reads the output, discards what doesn't apply, verifies what does, and hands you a page you can act on instead of an export you can't.

Each cycle

From raw output to a shortlist you can act on

01

Scan

Authenticated and unauthenticated sweeps across the agreed scope, scheduled so they don't disrupt production.

02

Triage

An operator reviews every finding, removes what doesn't apply to your environment, and corrects inflated severities.

03

Report

A short ranked list with reasoning attached, plus what changed since last cycle: new, fixed and still outstanding.

04

Track

Open items carry forward. Fixes are verified rather than assumed, and anything ageing badly gets escalated.

Where this ends

This is not managed detection and response

We are not watching your network overnight. We will not be the first to know if you are being actively attacked, and we do not provide incident response. If that is what you need, you need a provider built around it — and we would rather say so now than after something happens.

What this does is make sure the ordinary, known, fixable things get found and fixed on a schedule — so your next real test is spent on the interesting problems instead of the obvious ones.

Tell us what you're running

Fixed monthly fee, scope agreed in writing, and an honest answer about whether you'd be better served by a one-off test first.