The hypervisor, the switch, the firewall, the NAS and the box a contractor built in 2021 do not run an endpoint agent. They are still on your network, and they are still how people get in.
Continuous discovery and scanning across the whole estate, prioritised by what attackers are genuinely using, with the patching and re-checking that turns a finding into a closed one.
Most vulnerability programmes fail at one of two points. Either they only cover the assets that were easy to cover, which means the report is reassuring and wrong, or they produce a list of nine thousand findings that no team on earth could work through, so nobody starts.
This addresses both. Discovery runs across the network rather than only where agents are installed, so unmanaged and forgotten assets appear. Prioritisation uses exploit data rather than raw severity scores, which typically reduces a nine-thousand-item list to a few dozen things that genuinely matter this month. Then the patching is ours, so the finding closes instead of moving to your backlog.
Internal, external and web application scanning from one service.
Discovers assets no endpoint agent covers: hypervisors, network kit, appliances.
Prioritised by real-world exploitation, not CVSS severity alone.
Operating system and third-party application patching in agreed windows.
Re-scanned after remediation, so closure is proved rather than assumed.
Reporting that a non-specialist can take to a board.
How it is packaged
Three tiers, and you can start at any of them.
The first two are priced per agent — per PC and per server the agent is installed on. The third adds the estate-wide modules, which are priced per site because they find things that have no agent to count.
Tier 1
Managed Vulnerability Scanning
Continuous scanning and prioritisation. You get a clear, ranked picture of what is wrong and your team does the fixing.
Agent on every PC and server
Internal and external vulnerability scanning
Exploit-based prioritisation
Monthly report and review call
Charged per agent.
Tier 2
Vulnerability & Patch Management
Everything in tier one, and we do the remediation. Operating system and third-party application patching in windows you agree, with the re-scan that proves it closed.
Operating system and application patching
Agreed maintenance windows and approval rules
Documented exceptions with review dates
Verified closure, not assumed closure
Tickets raised directly into your service desk
Charged per agent, at a higher rate than tier one.
Tier 3
Managed Exposure
Everything in tier two, plus the things that have no agent: your external attack surface, your web applications, your identity estate and your cloud tenancies.
External attack surface and web application scanning
Active Directory and Entra ID hygiene review
Microsoft 365 and Google Workspace configuration
Sensitive data discovery across file shares
Network device and firewall configuration review
Technical evidence mapped to your control framework
Tier two per agent, plus the estate-wide modules per site.
Most organisations start at tier two, because a finding you cannot action is not worth paying for. Tier three is usually added after the first assessment, once the external and identity findings have made the case on their own.
Why coverage is the hard part
The asset register is always wrong.
Endpoint tooling is very good at telling you about endpoints it manages. The question it cannot answer is what is on the network that it does not manage.
Microsoft Defender gives genuinely excellent vulnerability data for enrolled, licensed endpoints, and where we run it for customers we use exactly that. But an endpoint agent is a floor, not a ceiling. It cannot install on an ESXi host, a storage array, a managed switch, an edge firewall, a building-controls panel or a printer with a web interface on it, and it is not present on the Linux box somebody stood up for a project that ended.
Those assets are not edge cases. They are routinely the initial access in real incidents, precisely because they sit outside the tooling everybody checks. The first discovery run on a new customer almost always finds assets nobody had on a list — and finding them is not a clever trick, it is just the difference between scanning a network and polling an agent estate.
Hypervisors, switches, firewalls, storage, printers, building systems. Discovered and assessed over the network rather than skipped because no agent will install.
The external estate
Forgotten subdomains, a staging site left public, an admin interface exposed after a firewall change. Scanned from outside, the way an attacker sees it.
Identity and cloud posture
Excessive privilege in Active Directory and Entra ID, weak password policy, misconfigured tenancies. Weaknesses that no endpoint scan reports because they are not on an endpoint.
Priority that reflects reality
Ranked by whether a vulnerability is actually being exploited. Thousands of findings become the few dozen that matter this month, which is the difference between a programme that runs and one that stalls.
If you already run Defender, this sits alongside it and fills what it does not reach. We are not going to sell you a replacement for something that works.
How it runs
Agreed in advance, because patching breaks things.
The scanning half is straightforward. The patching half is change management, and it is run like change management rather than like automation.
01
Discover
Agents deployed to PCs and servers, and the network swept for everything that cannot take one. The first run is usually longer than the asset register suggests.
02
Baseline and prioritise
A first full assessment ranked by real-world exploitation. This is the reference point, and it is the document that tends to change how people think about their estate.
03
Agree the rules
Patch windows, approval thresholds, what we apply without asking, what always comes to you, and which systems are off-limits until a change board says otherwise.
04
Patch and except
Applied in the agreed windows. Anything that cannot be patched gets a documented exception with a compensating control and a review date, rather than staying silently open.
05
Verify and report
Re-scanned to prove closure, then reported as movement — what closed, what is new, what regressed and what still needs a decision from you.
Questions
Vulnerability management, answered.
What is managed vulnerability scanning?
A service that continuously finds and ranks weaknesses across your estate, rather than a scanner you buy and run yourself. The managed part is the coverage, the prioritisation and somebody reading the output every month — which is where unmanaged scanning usually fails.
How is this different from Defender vulnerability management?
Defender reports on endpoints that are enrolled and licensed, and it does that very well. This covers the rest — hypervisors, network devices, appliances, your external estate and your identity posture — and adds the patching. They work together rather than competing.
Is this the same as a penetration test?
No. This is automated, continuous and broad: it finds known weaknesses everywhere, all the time. A penetration test is a person chasing an objective and finding what automation cannot. Most organisations need both, and this one first.
Do you actually apply the patches?
On tier two and above, yes — operating system and third-party applications, in windows you agree, under approval rules you set. Anything that cannot be patched gets a documented exception with a review date rather than being quietly ignored.
What if patching breaks something?
It is run as change management, not automation. You set the windows, the approval thresholds and the systems that are off-limits, and there is a rollback position before anything is applied. Risk of breakage is the reason patching does not happen, so it is planned for.
How is it priced?
Per agent — per PC and per server the agent is installed on. Tier three adds estate-wide modules priced per site, because external, identity and cloud findings have no agent to count. Exact figures follow scoping.
How long before we see anything useful?
The first discovery run usually produces something worth acting on within days, and it is frequently an asset nobody knew was there. A full prioritised baseline follows within the first few weeks.
Does this help with ISO 27001 or SOC 2?
It produces the technical evidence those frameworks ask for — coverage, prioritisation, remediation timelines. It is not a compliance programme on its own, and we would not pretend otherwise; our risk and compliance practice does that part.
Where to start
The first scan finds something you did not know you had.
It is the most reliable thing about this service. Discovery runs across the network rather than polling an agent estate, and the gap between the two is where the interesting findings live.