All services

Vulnerability Assessment & Management for Saudi Organisations

Continuous scanning, risk-based prioritisation, and remediation tracking across your entire asset inventory, so the list of known weaknesses actually gets shorter.

A scan is a list. Management is what closes it

NCA ECC-2:2024 Domain 2 (Cybersecurity Defence) names vulnerability management as an explicit control area, separate from penetration testing. Most organisations already own a scanner. The gap that shows up in an assessment is rarely the scan itself, it is what happens to the findings afterward: no risk-based prioritisation, no owner assigned, no SLA, and a backlog that grows faster than it clears.

We run continuous, credentialed scanning across your servers, endpoints, cloud workloads, and internet-facing assets, then do the part a scanner cannot: rank findings by exploitability and business impact rather than raw CVSS score, assign owners, track remediation against defined SLAs, and re-verify that a fix actually closed the finding.

What the service covers

Continuous Scanning

Credentialed, authenticated scans across internal and internet-facing assets on a defined cadence, not a once-a-year snapshot.

Risk-Based Prioritisation

Findings ranked by exploitability, asset criticality, and exposure, not CVSS score alone. A critical CVE on an isolated test box is not your first fix.

Remediation Tracking

Every finding gets an owner and an SLA, tracked to closure and re-verified rather than marked resolved because a ticket was closed.

Asset Inventory Coverage

You cannot manage vulnerabilities on assets you do not know you have. Discovery and inventory reconciliation are part of the service, not a prerequisite you supply.

How this differs from penetration testing

Coverage vs. Depth

Vulnerability management is broad and continuous, scanning your entire estate on a schedule. Penetration testing is narrow and deep, a human exploiting a defined scope once or twice a year.

Known vs. Novel

Scanning finds known, catalogued weaknesses (CVEs, misconfigurations). Testing finds what a scanner cannot: chained exploitation paths and business-logic flaws unique to your environment.

They Feed Each Other

A mature vulnerability management programme gives a pentest team a clean starting point instead of spending the engagement re-discovering what a scanner already knew.

How the programme runs

1

Discovery & Inventory

1-2 weeks

Reconcile your asset inventory against what is actually reachable on the network and in cloud accounts. Shadow assets are common and better found now.

2

Baseline Scan

1 week

First full credentialed scan across the confirmed inventory, establishing the starting finding count and severity distribution.

3

Prioritisation & SLA Assignment

Ongoing

Findings triaged by exploitability and business context, assigned an owner and a remediation SLA by severity tier.

4

Continuous Scanning & Reporting

Ongoing

Recurring scans on a defined cadence with a monthly report: open findings, SLA compliance, and trend against the previous period.

5

Remediation Verification

Ongoing

Closed findings are re-scanned to confirm the fix actually removed the weakness before the finding is marked resolved.

What is included

Asset discovery and inventory reconciliation
Credentialed, authenticated scanning across your estate
Risk-based prioritisation beyond raw CVSS score
Owner assignment and remediation SLAs by severity
Monthly reporting with trend and SLA compliance metrics
Remediation re-verification before findings are closed
NCA ECC vulnerability management evidence mapping

Find out where your programme actually stands

The Vulnerability Management Maturity Assessment scores your scanning coverage, prioritisation process, and remediation SLAs in about 15 minutes.

Related services

Penetration Testing

Manual testing that exploits what scanning finds.

Explore

Managed SOC & MDR

24x7 detection across cloud and endpoints.

Explore

Compliance Management

Ongoing compliance across ISO 27001, NCA ECC, and SAMA CSF.

Explore

Vulnerability Assessment & Management FAQ

Find answers to common questions about our services