Vulnerability Management

The last scan found thousands of findings. Fix the ones that matter first.

A free 28-question self-assessment for the people who run scanning, triage, and patching. It covers the eight working parts of a programme — from asset inventory to board reporting — and returns a maturity band with plain-English next steps, in about ten minutes. With it comes a working toolkit: registers, runbooks, deadline frameworks, and reporting packs. The assessment runs in your browser. Your answers never leave your device.

Free first

Two free ways to see if the toolkit fits.

1. Take the free assessment

28 questions across the eight working parts of a programme — asset inventory, scanning, prioritisation, remediation, patching, cloud workloads, exceptions, and reporting. About ten minutes. You get a weighted score and a maturity band, from Foundational to Advanced. Runs in your browser. No email required; nothing is sent anywhere.

Take the free assessment →

2. Read the free guide

"Your First Vulnerability Management Wins" walks through the first steps that pay off fastest — what to scan first, which findings to fix first, and why. Plain English, and yours to keep.

Read the free guide →
Who this is for

This is for running a vulnerability-management programme.

It measures how you find, prioritise, and fix vulnerabilities (from asset inventory to board reporting), not your general security baseline. If you want that baseline, see the SMB Security Assessment; if a specific vulnerability report needs handling now, that's PSIRT Response.

Pick a tier

Three tiers: one for a single owner, one for the first security hire, one for programmes at scale.

Solo
$49one-time
For the one person who looks after security: Information Technology (IT) generalists, founders, and solo practitioners with a small estate.
  • Asset Register Starter Kit — register, SaaS inventory, and a criticality guide
  • First Scan Cycle Runbook — from tool choice to reading the report
  • First Scanner Setup and Authenticated Scanning Guide — from first install to credentialed scans
  • End-of-Life Software Register and Migration Planner — track what's out of support and plan the exit (PDF and editable Excel)
  • Plain-English Triage Guide — the decision path that starts with the Known Exploited Vulnerabilities (KEV) catalogue
  • Remediation Verification and Rescan Checklist — prove each fix actually landed (PDF and editable Excel)
  • Starter deadline framework (a simple Service-Level Agreement) and a four-field exception log

Enough if you’re scanning and patching a small estate on your own.

Buy Solo — $49
Enterprise
$299one-time
For programme leads running at scale: metrics, board reporting, cloud and supply chain.
  • Metrics pack — dashboard, plain-English metric definitions, and a reporting cadence map
  • Board-Level Risk Summary template — plain-language quarterly reporting
  • Cloud and Container Runbook
  • Supply Chain Runbook, including the Software Bill of Materials (SBOM)
  • Vulnerability Management Policy Template — the formal programme policy auditors ask for first
  • Programme Maturity Self-Assessment — structured self-scoring between assessment runs
  • Everything in Solo and Team

Step up here for scale: metrics, board reporting, cloud and supply-chain coverage.

Buy Enterprise — $299

Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.

How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.

From Sylvan Press

The companion books: the field guide and the workbook behind this toolkit.

The books teach the discipline; the toolkit does the work with you. The Vulnerability Management Field Guide covers the judgement; the Operator's Workbook carries the templates.

Plain-English security tools that never see your data.

The free vulnerability management self-assessment scores you in the browser. We do not collect your answers, your score, or your gap list. We collect your email address only if you choose to enter it for the free guide. Nothing else.

Our website uses Cloudflare's server-side traffic counts for page totals — no scripts added to the page, no cookies, no data that identifies you.

From the blog

The situation this toolkit is built for, written up.

Your first scan just found 4,000 findings — ~7 min read.