Platform capability

Operational

Continuous vulnerability identification and prioritisation

Continuous assessment of operating system packages and application dependencies, prioritised by exploitability and exposure rather than raw severity score.

Overview

A quarterly vulnerability scan tells you what was true on the morning it ran. Vanguard assesses continuously, because the interval between a vulnerability becoming public and being exploited at scale is now routinely measured in days.

Findings are prioritised by whether the affected service is actually reachable, whether a working exploit exists, and what the host does - not by severity score alone. A critical-rated vulnerability in a package that is installed but not running is a lower priority than a high-rated one on your internet-facing gateway, and treating them as equivalent wastes the limited remediation capacity most teams have.

Every remediation recommendation is verifiable. We report what is vulnerable, on which host, why it matters in your specific environment, and how to confirm the fix worked.

What this identifies

  • Unpatched operating system and application vulnerabilities
  • End-of-life software still in production
  • Vulnerable dependencies inside container images
  • Configuration weaknesses measured against CIS benchmarks
  • Hosts drifting out of the patching cycle

Delivery status: Operational - deployed and in production service.

Capabilities

What vulnerability management does

  • Operating system package assessment

    Continuous matching of installed package inventory against vulnerability data, per host.

  • Application dependency scanning

    Vulnerability identification in application dependencies and container images.

  • Exposure-based prioritisation

    Ranking that accounts for reachability, exploit availability and the role of the affected host.

  • Patch verification

    Remediation is confirmed against the running system, not inferred from a package manager summary.

  • Trend reporting

    Monthly view of vulnerability posture over time, showing whether exposure is actually reducing.

Under the hood

The engineering underneath

How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.

  • Installed package inventory is matched continuously against vulnerability data, host by host.
  • Container images and application dependencies are scanned for exposure at the application layer.
  • Patch verification asserts against the running system and aborts on any mismatch with the expected change set.
  • Scan jobs are known to the monitoring layer, so the platform never raises an alert on its own scheduled activity.

The full platform architecture is documented on the architecture page.

Services

Services delivered on this capability

The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.

  • Operational

    Security Monitoring

    An entry-level monitored service for smaller Namibian organisations: continuous detection, alerting and monthly reporting, without a full SOC engagement.

    Explore
  • Operational

    Vulnerability Management

    Continuous identification of vulnerabilities across your Namibian estate, prioritised by real exposure and tracked through to verified remediation.

    Explore
  • Operational

    Security Assessment

    An independent review of your current security posture, producing a prioritised and costed improvement plan rather than a list of findings.

    Explore

Related

  • Operational

    Endpoint Detection & Response

    Agent-based visibility into process execution, persistence, configuration drift and vulnerability state on every monitored host.

    Explore
  • Operational

    Security Reporting

    Monthly reporting generated from case records, written for both the technical team and the people who approve the budget.

    Explore
  • Operational

    File Integrity & Configuration

    Detects unauthorised change to critical files, configuration and binaries - one of the highest-signal, lowest-noise detections available.

    Explore

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.