Platform capability
OperationalContinuous vulnerability identification and prioritisation
Continuous assessment of operating system packages and application dependencies, prioritised by exploitability and exposure rather than raw severity score.
Overview
A quarterly vulnerability scan tells you what was true on the morning it ran. Vanguard assesses continuously, because the interval between a vulnerability becoming public and being exploited at scale is now routinely measured in days.
Findings are prioritised by whether the affected service is actually reachable, whether a working exploit exists, and what the host does - not by severity score alone. A critical-rated vulnerability in a package that is installed but not running is a lower priority than a high-rated one on your internet-facing gateway, and treating them as equivalent wastes the limited remediation capacity most teams have.
Every remediation recommendation is verifiable. We report what is vulnerable, on which host, why it matters in your specific environment, and how to confirm the fix worked.
What this identifies
- Unpatched operating system and application vulnerabilities
- End-of-life software still in production
- Vulnerable dependencies inside container images
- Configuration weaknesses measured against CIS benchmarks
- Hosts drifting out of the patching cycle
Delivery status: Operational - deployed and in production service.
Capabilities
What vulnerability management does
Operating system package assessment
Continuous matching of installed package inventory against vulnerability data, per host.
Application dependency scanning
Vulnerability identification in application dependencies and container images.
Exposure-based prioritisation
Ranking that accounts for reachability, exploit availability and the role of the affected host.
Patch verification
Remediation is confirmed against the running system, not inferred from a package manager summary.
Trend reporting
Monthly view of vulnerability posture over time, showing whether exposure is actually reducing.
Under the hood
The engineering underneath
How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.
- Installed package inventory is matched continuously against vulnerability data, host by host.
- Container images and application dependencies are scanned for exposure at the application layer.
- Patch verification asserts against the running system and aborts on any mismatch with the expected change set.
- Scan jobs are known to the monitoring layer, so the platform never raises an alert on its own scheduled activity.
The full platform architecture is documented on the architecture page.
Services
Services delivered on this capability
The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.
- Operational
Security Monitoring
An entry-level monitored service for smaller Namibian organisations: continuous detection, alerting and monthly reporting, without a full SOC engagement.
Explore - Operational
Vulnerability Management
Continuous identification of vulnerabilities across your Namibian estate, prioritised by real exposure and tracked through to verified remediation.
Explore - Operational
Security Assessment
An independent review of your current security posture, producing a prioritised and costed improvement plan rather than a list of findings.
Explore
Related
Capabilities that work with this one
- Operational
Endpoint Detection & Response
Agent-based visibility into process execution, persistence, configuration drift and vulnerability state on every monitored host.
Explore - Operational
Security Reporting
Monthly reporting generated from case records, written for both the technical team and the people who approve the budget.
Explore - Operational
File Integrity & Configuration
Detects unauthorised change to critical files, configuration and binaries - one of the highest-signal, lowest-noise detections available.
Explore
Get started
Find out what is actually happening on your network
A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.