Skip to content

Assessment

Vulnerability
Management Services

Recurring program from $1,500 per validated scan, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need a vulnerability management program

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • A scanner already runs and the output is hundreds of findings nobody has time to validate, rank, or chase to closure.
  • PCI DSS, SOC 2, ISO 27001, or NYDFS 500.5 expects an ongoing vulnerability management process, not one annual test, and the auditor wants the history to prove it.
  • A cyber-insurance application asks how often you scan, who validates the results, and how fast critical findings are fixed, with evidence to show for it.
  • You have no security team of your own and need someone to run the scans, sort the real risk from the noise, and keep the estate covered between penetration tests.
  • You want new critical disclosures checked against your own stack quickly, following CIS Control 7, continuous vulnerability management, as the backbone of a repeatable process.

Definition

What are vulnerability management services?

Vulnerability management services turn one-off scanning into an ongoing program. Instead of a single scan and a raw export, senior analysts run scheduled scans, validate the results, rank what is real by risk, and track every finding to closure with a rescan that proves the fix. Buyers also call this vulnerability management as a service, managed vulnerability scanning, or vulnerability scanning as a service; they describe the same recurring, analyst-led program.

The program is built from our published scan prices, $1,500 per validated scan for up to 250 devices and $2,500 for up to 1,000, billed per cycle. A monthly or quarterly program is agreed as a fixed annual figure in writing before the first cycle runs, and estates over 1,000 devices are quoted from the scope. See the vulnerability scanning and assessment cost page for what moves the number.

Scope of the service

A testing program, not a SOC or MDR

Invadel is a penetration testing company. This is a testing and validation program: we find, validate, prioritize, and track vulnerabilities on a cadence, and we prove the fixes with rescans. It is deliberately not 24/7 monitoring, managed detection and response, or a security operations center, and it does not watch your network for live intrusions. Those are different services, and we do not sell them.

When the question is not "what is exposed?" but "would we detect an attacker who is already inside?", that is a job for a purple team assessment or a red team, not a vulnerability management program. When you need proof of exploitation rather than a ranked list, that is a VAPT engagement or a full penetration test.

What we look for

What a vulnerability management program tracks

A scan is a snapshot; a program is the film. Each cycle turns raw scanner output into validated, ranked risk, and every finding is followed until a rescan proves it closed.

Asset discovery and inventory

You cannot manage what you do not know you own. Each cycle starts by finding the hosts, services, and cloud resources that appeared since the last one.

We test for

  • Recurring discovery across IP ranges, domains, and cloud accounts
  • New-asset detection compared against the agreed scope
  • Certificates and DNS records that reveal new services
  • Staging and preview environments exposed to the internet
  • Shadow assets other teams stood up without telling anyone

Known CVEs and missing patches

The vulnerabilities attackers exploit first, and the ones scanners are best at surfacing, checked against your inventory before an attacker checks first.

We test for

  • Known-CVE detection across hosts, services, and applications
  • Outdated software, frameworks, and operating systems
  • End-of-life components still in service
  • Analyst review of critical disclosures against your stack
  • Patch verification once the fix ships

Misconfiguration and weak access

The insecure settings and default access that widen exposure without any missing patch, across hosts, services, and cloud.

We test for

  • Insecure service and protocol configuration
  • Weak TLS and SSL settings
  • Default, sample, and exposed management interfaces
  • Public storage, over-permissive identities, and open network rules in the cloud
  • Default and weak credentials on reachable services

Analyst validation

The work that separates a program from a scanner subscription: a person confirms what is real before it reaches your backlog.

We test for

  • False positives removed before anything reaches your backlog
  • Exploitability confirmation, not just version matching
  • Deduplication across hosts and scans
  • The false positives listed, so you can see what the scanner claimed and why it was wrong
  • Escalation of anything critical the day it is confirmed

Risk-based prioritization

Ranking that reflects what an attacker would actually reach, so remediation time goes to the findings that matter most.

We test for

  • CVSS severity combined with business context and asset exposure
  • Exploit-in-the-wild signals, including CISA Known Exploited Vulnerabilities and EPSS probability
  • Internet-facing exposure weighted above internal-only findings
  • Chains where two medium findings combine into a real path
  • A remediation order your team can actually work through

Remediation tracking and rescans

Findings followed to closure, not handed over and forgotten, with the evidence trail an auditor wants.

We test for

  • Every finding tracked open to fixed to verified in the platform
  • Rescans that confirm the fix landed
  • Re-rating of old findings as exposure changes
  • Escalation paths for findings past their fix window
  • Trend reporting cycle over cycle for auditors and leadership

Comparison

Scan, assessment, or management program

The three terms are used interchangeably, but they buy different things. The difference is less about the scanner and more about what happens after the scan.

Vulnerability scan

What it is
One validated scan of one scope
Cadence
Ordered one scan at a time
Remediation
A prioritized list
Best for
A baseline or a pre-ASV check
Price
From $1,500 per scan

Vulnerability assessment

What it is
One analyst-led review with exploitability notes
Cadence
One-time or periodic
Remediation
A prioritized list plus guidance
Best for
A validated baseline before a first test
Price
From $1,500 per assessment

Vulnerability management program

What it is
A recurring program: discover, scan, validate, prioritize, track, rescan
Cadence
Monthly or quarterly, on a fixed calendar
Remediation
Tracked to closure with rescans and trend reporting
Best for
Ongoing coverage and compliance evidence all year
Price
From $1,500 per scan each cycle, agreed as a fixed annual figure

The vulnerability scanning service is the single scan, the vulnerability assessment is the analyst-led review, and this page is the ongoing program that runs them on a cadence and follows the fixes.

How we prioritize

Why one CVSS score is not a priority

A severity score tells you how bad a vulnerability could be in the abstract, not whether it matters in your environment. A critical on an internal test box behind three firewalls is a lower priority than a high on an internet-facing login page that attackers are exploiting this week. So the ranking combines the CVSS severity with three things the score alone leaves out: whether the affected asset is actually reachable, whether the vulnerability is being exploited in the wild, and what a compromise of that asset would reach next.

For exploitation signals we use the CISA Known Exploited Vulnerabilities catalog, which CISA says organizations should use as an input to their vulnerability management prioritization framework, and the Exploit Prediction Scoring System (EPSS) from FIRST, which estimates the probability that a published CVE will be exploited in the wild in the next 30 days. The result is a remediation order your team can work through top to bottom, described in full in our guide to vulnerability remediation.

Methodology

How the vulnerability management program runs

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your vulnerability management runs through.

  1. 01

    Scope and cadence

    The recurring scope and the cadence, monthly or quarterly, agreed with a fixed program price in writing before anything runs.

  2. 02

    Discover and scan

    Each cycle rediscovers the estate and runs authenticated and unauthenticated scans, tuned to the environment.

  3. 03

    Validate by hand

    An analyst confirms every finding that matters, removes false positives, and deduplicates across hosts.

  4. 04

    Rank and route

    Findings are ranked by real risk and routed to your ticketing system as they are confirmed, critical ones the same day.

  5. 05

    Track, rescan, trend

    Remediation is tracked to closure, rescans prove the fix, and each cycle is trended against the last.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping vulnerability management services.

Still have questions? 
01What are vulnerability management services?

They are an ongoing program that finds, validates, prioritizes, and tracks vulnerabilities across a defined scope on a set cadence, usually monthly or quarterly. Senior analysts run the scans, remove the false positives, rank what is real by exploitability and business impact, route findings to your ticketing system, and rescan to confirm each fix. It produces the ongoing vulnerability management evidence that PCI DSS, SOC 2, ISO 27001, and NYDFS all expect alongside periodic penetration testing.

02Is this managed detection and response or a SOC service?

No. Invadel is a penetration testing company. This program identifies and tracks vulnerabilities so you can fix them; it does not monitor your network in real time, respond to live intrusions, or run a security operations center. Managed detection and response and SOC services are things we do not offer. If your concern is whether an attacker already inside would be detected, that is a purple team assessment or a red team, not a vulnerability management program.

03How is it different from a single vulnerability scan?

A single scan is one validated snapshot of one scope. A management program runs scans on a cadence, tracks every finding from open to fixed to verified, rescans to prove the fixes, and trends the results cycle over cycle, so your coverage and your evidence never go stale. Both use the same analyst validation; the program adds the calendar, the remediation tracking, and the history.

04How much do vulnerability management services cost?

The program is built from our published scan prices: $1,500 per validated scan for up to 250 devices and $2,500 for 251 to 1,000, billed per cycle, with larger estates quoted from the scope. A quarterly or monthly program is agreed as a fixed annual figure in writing before the first cycle, so the cost is known for the year. Starting prices for every service are on our pricing page, and the vulnerability scanning cost page explains what moves the number.

05How do you decide what to fix first?

Severity is only the starting point. A finding moves up the list when the asset is reachable from the internet, when the CVE is in the CISA Known Exploited Vulnerabilities catalog or carries a high EPSS probability, and when compromising that asset would open a path to something more valuable. A finding moves down when it sits on an isolated host with no realistic route to it. The output is a remediation order your team can work top to bottom, not a wall of criticals.

06Does this satisfy PCI DSS, SOC 2, or NYDFS?

It covers the ongoing vulnerability management half of each: the PCI DSS Requirement 11.3.1 internal scans every three months, the SOC 2 CC7.1 detection of new vulnerabilities and configuration changes, and the NYDFS 500.5(a)(2) automated scans and manual review. It does not replace the penetration test that PCI DSS and NYDFS require and SOC 2 auditors usually expect. For PCI DSS we also deliver the quarterly external ASV scan Requirement 11.3.2 calls for, so the internal program and the ASV scan come from one team.

07Do you track remediation and rescan the fixes?

Yes, that is the point of a program over a one-off scan. Every finding is tracked in the Invadel platform from open to fixed to verified, findings flow to your ticketing system as they are confirmed, and a rescan proves each fix landed before the finding is closed. The trend report each cycle shows what closed, what is new, and what has been open too long, which is exactly the evidence an auditor or an underwriter asks for.

08What do we need to provide?

The recurring scope: IP ranges or hostnames, read-only credentials for authenticated host and cloud scanning, and a test account for any application in scope. Authenticated scanning finds several times more than an unauthenticated pass, so credentials are the single best thing you can provide. We confirm the scope and the fixed program price in writing before the first cycle runs, no sales call required.

Ready to test your defenses?

Talk to our team about scoping vulnerability management services.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.