Systematically identify, assess and remediate vulnerabilities across your entire IT environment
New vulnerabilities arise every day. Without structured vulnerability management, critical gaps often remain undetected until they are exploited. As your external Vulnerability Manager, Swiss Infosec AG takes charge of the ongoing monitoring of your IT environment through regular vulnerability scans, assesses the results by risk, and supports you in systematically resolving them.
What we do for you
Swiss Infosec AG sets up a continuous vulnerability management process within your environment. Using established solutions, we carry out regular, coordinated scans of your network infrastructure, servers, clients and, depending on the scope, your web applications. The scan results are filtered by our experts according to criticality, assessed and prioritised in the context of your environment. In doing so, we adhere to recognised assessment standards such as CVSS, as well as the actual exploitability and business criticality of the affected systems.
Service components
- Scan operations: Setup and operation of regular vulnerability scans (internal/external) based on leading scanning platforms
- Result evaluation: Technical triage and prioritisation of vulnerabilities based on CVSS, exploitability and system criticality
- Remediation management: Assignment of vulnerabilities to responsible parties, setting deadlines and tracking the status of remediation
- Exception management: Documented handling of vulnerabilities that cannot be remedied immediately (risk acceptance, mitigation measures)
- Trend analysis: Evaluation of vulnerability trends over time to assess the progress of the security programme
- Reporting: Regular technical and management reports with prioritised recommendations for action and a KPI dashboard
Your added value
With us as your external vulnerability manager, you gain complete transparency over the vulnerabilities in your IT environment: assessed continuously, in a structured manner and with technical expertise. You benefit from clear prioritisation that focuses your resource allocation on the truly critical gaps, and from a traceable, audit-proof process that meets regulatory requirements.