The last scan found thousands of findings. Fix the ones that matter first.
A free 28-question self-assessment for the people who run scanning, triage, and patching. It covers the eight working parts of a programme — from asset inventory to board reporting — and returns a maturity band with plain-English next steps, in about ten minutes. With it comes a working toolkit: registers, runbooks, deadline frameworks, and reporting packs. The assessment runs in your browser. Your answers never leave your device.
Two free ways to see if the toolkit fits.
1. Take the free assessment
28 questions across the eight working parts of a programme — asset inventory, scanning, prioritisation, remediation, patching, cloud workloads, exceptions, and reporting. About ten minutes. You get a weighted score and a maturity band, from Foundational to Advanced. Runs in your browser. No email required; nothing is sent anywhere.
Take the free assessment →2. Read the free guide
"Your First Vulnerability Management Wins" walks through the first steps that pay off fastest — what to scan first, which findings to fix first, and why. Plain English, and yours to keep.
Read the free guide →This is for running a vulnerability-management programme.
It measures how you find, prioritise, and fix vulnerabilities (from asset inventory to board reporting), not your general security baseline. If you want that baseline, see the SMB Security Assessment; if a specific vulnerability report needs handling now, that's PSIRT Response.
Three tiers: one for a single owner, one for the first security hire, one for programmes at scale.
- Asset Register Starter Kit — register, SaaS inventory, and a criticality guide
- First Scan Cycle Runbook — from tool choice to reading the report
- First Scanner Setup and Authenticated Scanning Guide — from first install to credentialed scans
- End-of-Life Software Register and Migration Planner — track what's out of support and plan the exit (PDF and editable Excel)
- Plain-English Triage Guide — the decision path that starts with the Known Exploited Vulnerabilities (KEV) catalogue
- Remediation Verification and Rescan Checklist — prove each fix actually landed (PDF and editable Excel)
- Starter deadline framework (a simple Service-Level Agreement) and a four-field exception log
Enough if you’re scanning and patching a small estate on your own.
Buy Solo — $49- Remediation deadline framework, with patch ticket and verification templates
- Environmental Risk Scoring Worksheet — rank findings by your exposure and asset criticality (PDF and editable Excel)
- Exception Management Pack — request form, register, quarterly review, risk acceptance
- False-Positive and Scan-Noise Triage Workflow — separate real findings from scanner noise
- Patch Testing and Rollback Playbook — test before you deploy, and back out cleanly when a patch misbehaves
- Vendor Advisory and Third-Party Pack — subscriptions, intake triage, vendor questionnaire
- Remediation Campaign Runbook — for clearing a whole class of findings estate-wide
- Everything in Solo
Choose this when you need a real programme: triage, SLAs, and clear ownership.
Buy Team — $99- Metrics pack — dashboard, plain-English metric definitions, and a reporting cadence map
- Board-Level Risk Summary template — plain-language quarterly reporting
- Cloud and Container Runbook
- Supply Chain Runbook, including the Software Bill of Materials (SBOM)
- Vulnerability Management Policy Template — the formal programme policy auditors ask for first
- Programme Maturity Self-Assessment — structured self-scoring between assessment runs
- Everything in Solo and Team
Step up here for scale: metrics, board reporting, cloud and supply-chain coverage.
Buy Enterprise — $299Every tier is a one-time purchase with a 30-day money-back guarantee, no questions asked, and free updates while the toolkit is in our catalogue.
How access works: the documents in every tier are downloads you keep, and the assessment app unlocks in your browser with the licence key from your purchase receipt — no account, no sign-in. The key activates on up to 3 devices on the solo tier, 7 on the middle tier, and 13 on the top tier.
The companion books: the field guide and the workbook behind this toolkit.
The books teach the discipline; the toolkit does the work with you. The Vulnerability Management Field Guide covers the judgement; the Operator's Workbook carries the templates.
If this is your situation, one of these usually is too
PSIRT Response
Vulnerability management handles the flaws in the estate you run. PSIRT Response covers the other direction — vulnerability reports arriving about the product you ship.
SMB Security Assessment
Patching is one of four controls cyber insurers ask about. The SMB Security Assessment covers the full everyday baseline — access, data, backups, and patching.
The situation this toolkit is built for, written up.
Your first scan just found 4,000 findings — ~7 min read.