Vulnerability & Patch Management (B/S/G)

Security & Continuity MS Managed
Code: SC-MS-VPMGT

Summary. Find and reduce risk with continuous vulnerability scanning and a clear, achievable patch cadence.

Who it's for. SMEs that want fewer urgent incidents and clear progress that can be evidenced to stakeholders.

Business Outcomes

What’s Included

ScopeDescription
Core Inclusions
  • Asset & vuln discovery; prioritised findings
  • Patch cadence and maintenance windows
  • Exception handling and management reporting
  • Credentialed vuln scans with evidence and remediation guidance
  • Patch rings/maintenance windows with rollback notes
Optional Add‑Ons
  • EDR/XDR uplift (per Annex)
  • Remediation sprints (T&M)
  • Executive risk briefings

Onboarding & Steady‑State

Note: timelines depend on size and current tooling.

PhaseActivitiesDeliverablesIndicative Duration
01 — Baseline
  • Scan/import assets
  • Define cadence
  • Baseline risk view & first remediation plan
  • Patch calendar & rings
1 week
02 — Stabilise
  • Remediation focus
  • Exception process
  • Documented down-trend in risk
  • Exception register (owner + expiry)
2–4 weeks
03 — Operate
  • Monthly scans & reports
  • Quarterly roadmap
  • Monthly scorecard (risk, patch compliance, MTTR)
  • Quarterly roadmap
Ongoing

Service Levels (Summary)

PlanCoverageResponse / RestoreGovernance
BronzeBusiness hours (Mon–Fri 08:00–17:00 NZT, except Public Holidays)Findings triage monthlyMonthly summary
SilverExtended hours (Mon–Fri 07:00–19:00 NZT, except Public Holidays)Findings triage fortnightlyMonthly review
GoldBusiness + after‑hours (24×7 P1 only)Findings triage weeklyMonthly review + exec summary
For pricing, terms and conditions see the Pricing Annex.

Success Criteria (from our perspective)

Prerequisites

Assumptions

Risks & Mitigations

Out of Scope

Get started

Prefer to stabilise first? Run a short pilot to establish a clean baseline; then roll into this managed service.

Related Resources