Exposure-based prioritisation
Findings ranked by reachability, exploit availability and asset criticality, so the list your team works from is short enough to finish this month.
Security & Compliance
A patching cadence you can keep, aimed at the vulnerabilities that are actually being exploited.
The work
Raw CVE counts tell you very little. A host with two hundred medium findings and no exposed service is usually a lower priority than one internet-facing appliance with a single flaw that has a working exploit. We start by building an exposure picture from your asset inventory, network reach and threat intelligence, then patch against that.
The mechanics differ by estate. Virtual machines get rolling patch windows with drain and health checks; container hosts get replaced rather than patched in place; language dependencies get version bumps through the same pipeline as the code. We automate what is safe to automate and keep a human approval on the changes that can take a service down.
Scope
Every engagement on this page covers the following, sized to your setup rather than delivered as a fixed package. If something here is not relevant to you, it comes off the scope and off the price.
Findings ranked by reachability, exploit availability and asset criticality, so the list your team works from is short enough to finish this month.
Scheduled jobs that apply OS and package updates through Ansible or your existing automation, with pre-checks, health gates and an automatic stop on failure.
Hosts drained, patched and returned to the load balancer one at a time, with capacity checks so the remaining nodes can carry the traffic.
Where hosts should not be patched in place, we rebuild from a fresh base with the same configuration and replace the node instead.
Which assets are current, which are overdue and which are deliberately excluded, refreshed after every run and readable by people outside the platform team.
Databases and stateful clusters get planned maintenance windows with replica failover first, since those are the patches that cannot be automated away.
What changes
Handover
Everything produced during the engagement is yours: the repositories, the accounts, the documentation. There is no proprietary layer and nothing to unlicense if you take the work in-house.
Tooling
A starting point, not a requirement. We work in whatever you already run wherever it does the job.
How it runs
The same four steps on every engagement. You see each one before it starts and can stop at any of them.
We combine your asset list, network exposure and known exploited vulnerability feeds to rank what genuinely needs attention first, rather than sorting by score alone.
Severity bands get a target window each, agreed with the teams who own the services, so everyone knows what happens and when without asking.
Playbooks and pipeline jobs handle the predictable work, with health checks that halt a rollout when an instance fails to come back cleanly.
Monthly reporting shows what slipped and why, and the cadence is adjusted when a target is consistently missed rather than quietly ignored.
Questions
There is no universal answer, and anyone quoting one number is guessing. For internet-facing systems we typically work to days, for internal services weeks. What matters is that the target is written down, measured and achievable with the staff you have.
No. Databases, appliances and anything without redundancy need a human decision and often a window. We automate the rest, and the parts that cannot be automated get recorded as exceptions with an owner rather than quietly left out.
Those are the hardest, and a scanner will keep flagging them. We handle them with compensating controls such as network restrictions, feature disablement or extra monitoring, and set a review date so the decision is revisited when a fix ships.
No, it usually consumes it. Keep the scanner you have for discovery and asset coverage, and let this work deal with prioritisation, scheduling and the evidence trail. Where a scanner misses whole platforms, we will say so and suggest something better.
Security & Compliance
Block images with known critical CVEs before they ever reach a registry your production cluster can pull from.
Servers and appliances configured from code, so rebuilding a box is boring and identical every time.
Continuous evidence collection instead of a quarterly fire drill — audit trails generated by your pipeline.
Bring the specific problem. We will tell you honestly whether this is the service that fixes it, and what it would take.