Skip to content

Vulnerability management

Vulnerabilities found, fixed and closed with evidence.

Most organisations can produce a list of vulnerabilities. Far fewer can show that the important ones were fixed. We scan continuously, prioritise by what is exposed and exploitable, fix the findings as engineers, and prove closure every month.

Start with a cyber risk assessment
Locked steel server cabinet door, with blue light through the perforated mesh.

What is included

  • Continuous scanning of workstations, servers, cloud resources and internet-facing services, using Microsoft Defender Vulnerability Management or the scanner you already own
  • Prioritisation by exposure, known exploitation and the importance of the system, rather than by raw severity score
  • Remediation by North Ark engineers: patches, configuration changes and compensating controls, through your change process
  • Evidence of closure for each finding, re-scanned and recorded
  • Exceptions tracked with an owner, a reason and a review date
  • A monthly report showing what was found, what was fixed and what is waiting
A checklist of six security findings, four ticked as closed and two still open, connected to three areas of work: identity, endpoint and detection.

Why findings stay open elsewhere

Scanning is easy. Fixing is where findings stall: nobody owns the server, the patch needs a change window, the application owner is worried. Because the same engineers who scan also fix, findings keep moving until they are closed or formally accepted.

How it runs

  1. Baseline: scanning set up across the estate and the current backlog prioritised.
  2. Burn down: the most exposed and exploited findings fixed first.
  3. Keep up: new findings triaged each week and fixed within the timeframes agreed with you.
  4. Report: monthly evidence for your leadership, auditors and insurers.

Where it fits

Vulnerability management is an add-on to Managed Microsoft 365 and security, Managed infrastructure or full Managed Engineering, or it can run on its own. It supports the patching strategies of the Essential Eight, and the monthly evidence feeds straight into an assessment.

Questions buyers ask

Do you use our existing scanner?

Yes, if it covers the estate. Otherwise we use Microsoft Defender Vulnerability Management where you are licensed for it, or recommend a scanner.

Do you fix the findings or just report them?

We fix them. Remediation by our engineers is the core of the service, with evidence of closure for each finding.

What about findings we can't patch?

They get a compensating control where possible, and an exception with an owner, a reason and a review date.

Is this the same as penetration testing?

No. Scanning finds known weaknesses continuously. Penetration testing is a point-in-time attempt to exploit them. The two work well together, and we run both.

How is it priced?

A fixed monthly fee based on the size of the estate in scope, agreed for a 12-month term.

Start a conversation

Get the findings you already know about closed.

Tell us what happens to your vulnerability findings today.

Talk to an Engineer