Data and Risk Management

Vulnerability Management

In an ever-evolving IT stack it’s no wonder that keeping things up to date is one of the most critical security tasks.

Successful Information Security implementations and security breach mitigation technologies require a way to assess and report on the viability and effectiveness of their controls.

Performanta provides managed vulnerability management services to our clients, which allows for the discovery, assessment, prioritisation, and remediation action guidance for vulnerabilities that are found within your network, both from an internal and external perspective.

Our services ensure that all known vulnerabilities are identified for each of the assets in scope and remediation actions are guided and performed to reduce the vulnerability and risk on an ongoing basis, reported on monthly. The tooling that we utilize ensure that you as the client always have visibility of the progress and vulnerability landscape through the web-based dashboard to promote constant visibility and executive reporting.

The Performanta Managed Vulnerability Service aims to help your business better understand the risk exposure of the systems in scope and provide a clear roadmap and prioritisation of the mitigating actions that are required to address the vulnerabilities.

The service comprises of 2 Phases, the first of which is the preparation and initial assessment phase, followed by the managed security service that run on an ongoing monthly basis.

Identify
Evaluate
Prioritize
Report

Identify

  • Scan network-accessible systems
  • Identify open ports and services running on scanned systems
  • Gather detailed system information (Authenticated scan)
  • Correlate system information with known vulnerabilities

Evaluate

  • Evaluate Vulnerabilities to ensure risk is accurate
  • Ensure no false positives
  • Evaluate exploitability of vulnerabilities

Prioritize

  • Prioritising how to treat the vulnerabilities
  • Remediate – Fully fix or patch through the partnership with the client
  • Mitigate –reduce likelihood or impact
  • Accept – Take no action if risk is low

Report

  • Monitor vulnerabilities and track resolution activities
  • Ensure compliance and regulatory requirements are met

Consultancy Services

Our experts live and breathe Microsoft 365 Security and are experts in all areas of it, including the ever-growing Defender suite, DLP, Entra, etc.

Learn More

Security Assurance Service

Our Security Assurance Services are focused on validating that all of your Microsoft 365 controls (including the Defender suite) are effectively and appropriately deployed, and that nothing has been missed.

Learn More

Managed Controls Service

Our Managed Controls Service for Microsoft 365 provides a complete hands-off management service.

Learn More

MDR Service

Our Managed Detection and Response (MDR) Service for Defender for Endpoint provides you with a 24x7x365 service.

Learn More