The process
How it works
The service has one backbone: scans run on your own tooling, our proprietary risk analysis and a consultant sort what they find, and you receive a fix list ranked by actual exposure on a fixed day. Everything else, bands, cadences and add-ons, is that backbone at different intensities, priced before you enquire.
Six steps
From scoping call to closed findings
Steps one and two happen once. Steps three to six repeat every cycle for as long as you keep the service, which is the point.
Step 1
The scoping call
Free, 45 minutes, no obligation. We establish what you run: which scanners you have and how many, what they cover internally, whether you want external coverage in the same view, and which compliance regimes are pulling at you. You leave knowing the band that fits and the figure already printed on the pricing page.
Step 2
Onboarding and connection
We confirm the target list in writing, agree scan windows and exclusions, and connect to your world: on Managed we take the controls of your scanner on your licence; on Essential we set up the export feed from the scans your team runs. Either way the tool stays yours.
Step 3
Scans run to schedule
Monthly on Essential, on your schedule for Managed, continuous where Complex estates support it. Scans run on your tooling, by us or by you; nobody has to babysit them, and new assets you tell us about join the next cycle.
Step 4
A consultant triages everything
Raw results never reach you. Every export is ingested and run through our proprietary risk analysis, which weighs real-world exploitability and what each system is worth to the business, and a consultant verifies what remains, because a medium on your VPN gateway can matter more than a critical on a dead test box.
Step 5
The report lands as a fix list
On a fixed day you get a ranked fix list with remediation guidance written for the people doing the patching, plus a summary you can hand to a director or an auditor unedited. The Managed band adds a walkthrough call with the consultant who did the triage.
Step 6
Findings tracked to closure
Each finding carries through to the next cycle: fixed, outstanding or new. The month-on-month trail is your compliance evidence for PCI DSS, Cyber Essentials Plus readiness and ISO 27001 A.8.8, and it is also how you know the service is earning its fee.
One backbone, two shapes
The first cycle and the monthly rhythm
The managed service is a rhythm: the same scan, triage and report cycle repeating on your band's cadence, with findings tracked across cycles and the evidence trail growing every month. It suits any organisation that wants vulnerability management to simply keep happening without staffing it.
The first assessment cycle starts every engagement: scanners connected, the backlog ingested and risk-analysed, and the baseline report delivered. From there the rhythm takes over, and the PCI ASV cycle bolts on where card payments demand it.
The exchange
What the service needs from you, and what you get back
What it asks of you
- A named technical contact who receives the reports and owns the fix list inside your organisation.
- A confirmed target list: the IP ranges, hosts and domains in scope, agreed in writing before the first scan.
- Written authorisation to scan, signed at onboarding; we never scan estates we have not been authorised on.
- Access to your scanner (on the Managed band) or its exports (on Essential), agreed in writing; the tool and its licence remain yours throughout.
What it hands back
- A ranked, human-verified fix list every cycle, ordered by exploitability, with guidance your IT team or provider can act on directly.
- A dated evidence trail that answers PCI DSS, Cyber Essentials Plus, ISO 27001 A.8.8 and insurer questionnaires without assembly work at audit time.
- A month-on-month exposure trend, so you can show the number going down rather than assert that it is.
- A consultant who knows your estate and answers for the list, not a portal login and a wish of good luck.
Common questions
What teams ask before they book
Do we need to install anything?
For external scanning, nothing: we scan your internet-facing assets from outside, exactly as an attacker would encounter them. Internal scanning needs either lightweight agents on endpoints and servers or a small network appliance, chosen at onboarding; your team installs them with our guidance and they need no day-to-day attention afterwards.
What happens if something critical appears mid-cycle?
Critical findings do not wait for report day. Once triage confirms a finding is real and serious, your named contact hears about it directly with the recommended fix, and the formal report catches up later. The cadence governs the routine work, not the urgent exceptions.
Can you scan cloud environments?
Yes, wherever your scanner can see: externally exposed cloud services as standard, and cloud-hosted servers where your tooling covers them on the Managed and Complex bands. What your cloud provider secures for you, and what remains yours to patch, is exactly the kind of distinction the analysis explains rather than leaving you to guess.
How long does onboarding take?
External-only estates are usually scanning within days of the target list being confirmed: the work is scoping and authorisation, not installation. Bands with internal scanning depend on how quickly agents or the appliance can be deployed in your environment, which your team controls; we fit around your change process rather than pushing against it.
Step one costs nothing
Book the scoping call
Bring a rough count of what you expose and any compliance deadline on the horizon. We bring the band that fits, its published figure, and an unvarnished view of whether you need this service yet.