Managed cyber security

Vulnerability Management

Continuous visibility of missing updates, exposed services and priority risks.

What is Vulnerability Management?

Vulnerability management is the ongoing process of discovering weaknesses, deciding which ones matter, assigning remediation and confirming closure. 39Security combines scanning with business context, patch and configuration follow-up, exposure review and management reporting so the customer receives an owned risk process rather than a long unprioritised list.

Who is this service for?

Businesses with internet-facing services, multiple endpoints, servers, cloud systems or customer security obligations that need evidence that technical weaknesses are being identified and addressed.

What problem does it solve?

Automated scans can produce hundreds of findings, including duplicates and low-value issues. Without ownership, deadlines and validation, the same weaknesses remain open while urgent internet exposure or exploited vulnerabilities are lost in the noise.

What is included?

  • External attack-surface discovery
  • Authenticated or internal scanning where agreed
  • Risk-based validation and prioritisation
  • Patch and configuration remediation plan
  • Tracking of owners, target dates and exceptions
  • Retesting of remediated findings
  • Management reporting and trend review

What is not included?

  • Penetration testing unless separately commissioned
  • Guaranteed discovery of every weakness
  • Unauthorised testing of third-party systems
  • Application source-code review
  • Remediation projects outside the agreed managed scope

How implementation works

We define authorised targets, maintenance windows, credentials and exclusions. The initial scan establishes a baseline, findings are validated and grouped, then owners and target dates are assigned. High-risk exposure is escalated immediately rather than waiting for the routine report.

Supported platforms and products

The service can cover public IP addresses, domains, supported Windows and server environments, network devices and selected cloud assets. Scope depends on safe access, licences and ownership. Third-party hosted systems require permission.

How quickly are alerts investigated?

Critical internet exposure, known exploitation and material new weaknesses are prioritised for prompt review. Lower-risk findings are handled through the agreed remediation cycle. The service schedule defines scan frequency and escalation times.

Who responds?

39Security validates the finding, identifies affected assets, recommends the safest fix and works with the responsible IT team or supplier. Where patching is not immediately possible, compensating controls and a documented risk decision may be proposed.

What evidence and reporting will you receive?

Customers receive prioritised findings, affected assets, remediation status, retest results and accepted exceptions. Trend reporting shows whether exposure is reducing and where unsupported hardware or software is creating recurring risk.

Cyber Essentials, insurance and Microsoft 365

Vulnerability management supports Cyber Essentials security-update management, insurance reviews and ISO/IEC 27001 risk treatment. A scan report alone does not prove compliance; scope, remediation and evidence of sustained control matter.

What does it cost?

Pricing depends on number and type of assets, scan method, frequency and remediation support. Indicative managed rates are shown excluding VAT. Penetration testing and complex application assessment are separately scoped.

How is the service governed?

Before activation, the proposal should identify the covered users, devices, locations and platforms, together with the service window, escalation contacts and change responsibilities. During operation, material exceptions are recorded rather than hidden, and recommendations are separated into urgent actions, planned improvements and optional projects. This gives managers a practical view of risk, cost and ownership.

Service reviews should test whether coverage still matches the business. New starters, leavers, acquisitions, cloud applications, office moves and supplier changes can all create gaps. 39Security therefore treats onboarding, reporting and periodic review as part of the control, not as administration around the edge of the product.

What should good delivery look like?

A buyer should be able to identify what is protected, who is watching it, what happens when something goes wrong and which evidence will be available afterwards. The provider should explain limitations honestly, avoid vague promises and document any dependency on Microsoft licensing, internet connectivity, third-party suppliers or customer action. Clear boundaries make response faster and reduce disputes during an incident.

Questions to ask before selecting a provider

  • Which systems, users and locations are included in the quoted scope?
  • Who reviews alerts, during which hours, and what happens when the named contact is unavailable?
  • What evidence will we receive for clients, insurers, auditors or board reporting?
  • Which actions are included in the monthly fee and which require separate project approval?
  • How are service quality, response times, exclusions and exit arrangements documented?

Frequently asked questions

Is vulnerability scanning the same as penetration testing?

No. Scanning uses automated checks to identify known weaknesses at scale. Penetration testing applies controlled human testing to explore whether weaknesses can be combined or exploited. Many businesses need regular scanning and periodic independent testing.

Do all vulnerabilities need immediate patching?

No, but each finding needs a risk-based decision. Internet exposure, active exploitation, asset importance and available mitigations affect priority. Critical risks should not be buried behind a simple severity score.

Can you check unsupported hardware and software?

Yes. Lifecycle status is an important part of vulnerability management because an unsupported platform may no longer receive security fixes. The service can flag replacement or upgrade requirements and track the associated risk.

Will you fix the findings?

Remediation support is included to the extent stated in the service scope. Changes to managed Microsoft 365, endpoints or firewalls may be completed directly, while application or supplier changes may require a separate project.