The scanner finds.
We make sure it gets fixed.
We sit between the scanner and the line: what comes first, whether it actually happened, what was knowingly accepted and until when, and whether anything is still being scanned. The scan comes from Rapid7, Holm, Nessus or whatever you already have; the patching is done by the line. A report with four thousand findings is not an instruction. The steering in between is.
Between the scanner and the line.
We are not a scanner and not a patching factory. The scan comes from Rapid7, Holm, Nessus or whatever you already have; the patching is done by the line. We deliver the steering in between, with a register, so every choice can be traced back.
- What comes first, prioritised on what it touches at your organisation, not on the CVSS score alone
- Bundled per fix, one patch that removes thirty findings is one ticket, not thirty
- Did it happen, a finding only closes once a retest shows it
- Knowingly accepted, with an owner and an expiry date, so it does not quietly stay put
- Is anything still being scanned, scan coverage is a measurement in its own right; a scanner that stops otherwise surfaces at the audit
Nobody knows what was left behind .
Scanning happens, patching happens, and there is no place recording which part of the findings has actually gone. At the next scan it starts over, and the list has grown.
That is not a scanning problem. That is an administration problem, and that one can be solved.
Three people, three questions.
The same data, but nobody is served by the same screen.
What do I advise the line.
Advice aimed at fixes, bundled per fix and passed on as a single ticket. Not an export of four thousand rows thrown over the fence.
Are we ahead or behind.
Remediation within the agreed window per severity, aging, scan coverage, accepted risks with an expiry date, and the trend across quarters.
What do I need to do this week.
A work list: what, where, why this first, and when it has to be gone. Without anyone having to decipher a report first.
What we do not do.
- We do not scan. Your scanner stays your scanner
- We do not patch. That is done by whoever runs the system
- We do not decide what counts as acceptable risk. You do; we record it with a date attached
What we do is make sure those three connect, and that you can show at any moment where things stand.
We are building this domain out now .
Vulnerability intelligence is the youngest domain in our portfolio. The service is being set up as we speak; the first customers are involved in shaping what it becomes.
If you want to think along or be among the first to join, let us know. That is more honest than pretending it has been here for years.
How much of your last scan round was actually resolved?.
If you cannot answer that question, that is exactly what this is about.