شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Assess & test

Vulnerability managementVulnerabilities found, prioritised and closed, not lists that pile up

We turn vulnerability scanning from an annual report into a running process: scan, rank by real risk, and follow up with system owners until closure.

At a glance

Frameworks

  • NCA ECC
  • SAMA CSF
  • CIS Controls
  • ISO 27001
  • NIST CSF

Deliverables

  • Asset inventory with criticality classification
  • Approved scan plan
  • Monthly vulnerability and trend report
  • Exception register with compensating controls
  • Remediation tracking dashboard

The challenge

The NCA Essential Cybersecurity Controls (ECC) require periodic vulnerability scanning and remediation within timeframes proportionate to severity, and the SAMA Cyber Security Framework (CSF) expects the vulnerability lifecycle to be documented from discovery to closure.

The problem is not scanning but what follows it: thousands of unranked findings, operations teams that do not know where to start, and critical flaws left open for months because nobody chased them.

We run the whole process: the scanning tools, prioritisation by real-world exploitation and asset criticality, remediation tickets, and reports that show management the trend month by month.

How we work

  1. 1

    Inventory and asset classification

    We build an inventory of internal and external assets, classify them by business criticality, and identify system owners and permitted scan windows.

  2. 2

    Scan and prioritise

    Recurring authenticated scans of networks, servers and applications, then ranking by combining CVSS with real-world exploitation data (KEV, EPSS) and asset criticality.

  3. 3

    Track to closure

    Remediation tickets to system owners, follow-up against agreed timeframes, verification rescans, and a monthly report of trends and approved exceptions.

What is included

  • Infrastructure and network scanning

    Authenticated scanning of servers, network devices and endpoints using platforms such as Tenable, Qualys or your existing tooling.

  • Web application scanning

    Recurring dynamic scanning of applications and exposed APIs, complementing manual penetration testing.

  • External attack surface

    Continuous discovery of internet-exposed assets, including subdomains and forgotten services.

  • Risk-based prioritisation

    Combining CVSS with actively exploited lists, exploitation likelihood and asset criticality, so teams start with what matters.

  • Patch management integration

    Linking findings to patching tools (WSUS, SCCM/Intune, third-party patching) and your ticketing system.

  • Configuration compliance

    Configuration checks against CIS Benchmarks for operating systems, databases and network devices.

  • Exception management

    A documented register of temporarily accepted vulnerabilities with justification, compensating controls and review date.

  • Reporting and metrics

    Dashboards showing mean time to remediate, ageing vulnerabilities and compliance with agreed timeframes, by unit and system.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • SAMA CSF
  • CIS Controls
  • ISO 27001
  • NIST CSF

Frequently asked questions

Do you apply the patches yourselves?

The core service covers scanning, prioritisation and tracking, with remediation staying with system owners. Patch execution can be added under managed IT services.

How often do you scan?

Frequency is set by asset classification and the frameworks that apply to you, and documented in the approved scan plan.

Can you use the scanning tools we already own?

Yes. We run your existing tools where they cover the scope, and provide a platform only where none exists.

Does this integrate with the SOC?

Yes. Vulnerability data feeds the SOC to prioritise alerts, and indicators seen by the SOC adjust vulnerability ranking.

What affects the cost of managed vulnerability management?

The number of assets in scope (servers, endpoints, network devices, web applications and external IP ranges), how often each class is scanned, and whether scans are authenticated. Whether you already own a scanning platform, integration with your patching and ticketing tools, and the depth of reporting also play a part. We set this out in a written proposal after the asset inventory.

What do we need to provide to start?

Asset lists and IP ranges, service accounts with the permissions needed for authenticated scanning, and the scan windows your operations team approves. We also need system owners for each area, access to your ticketing system, and a list of fragile systems to exclude or scan with care.

Do we still need penetration testing if we have vulnerability management?

Yes. Recurring scanning finds known weaknesses across many assets, while in a penetration test a human tester proves what can actually be exploited, including business-logic flaws and chains of small issues that scanners miss. The NCA Essential Cybersecurity Controls (ECC) give each its own subdomain, and we deliver testing through our Penetration Testing service.

  • Assess & test

    Penetration testing

    Application, network and infrastructure testing with recognised methodologies and an actionable report.

  • Detect & respond

    Managed SOC

    24/7 monitoring, analysis and response under an NCA licence.

  • Operate & outsource

    Managed IT services

    IT operations and support with clear service levels and regular reporting.

  • Solutions & infrastructure

    Infrastructure

    Data centres, servers, storage and networks built to security standards from day one.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.