Continuous scanning, with someone reading it.
A scanner on a schedule produces a report nobody triages. SubRosa runs the scans across your network and applications, validates what comes back, ranks it by what an attacker could actually use, and hands your team a short list instead of a long one.
Daily · weekly · monthly · your schedule
What is managed vulnerability scanning?
Managed vulnerability scanning is a scanning programme someone else runs and reads for you. The tooling, the schedule, and the coverage are handled, and every result is validated by an engineer before it reaches you, so false positives are removed and real findings arrive ranked by exploitability. It fills the gap between penetration tests: a pen test is a deep look on one date, while managed scanning watches continuously and tells you when something new appears.
Scanning, validated and prioritized.
Automated coverage across your estate, with an engineer between the scanner and your inbox.
Expert validation
Every finding is reviewed and prioritized by an engineer, so what reaches your team is confirmed and ranked rather than raw scanner output.
Flexible scheduling
Scanning runs daily, weekly, or monthly, set to your change rate and risk tolerance rather than a vendor default.
Network & web app coverage
Network infrastructure assessment alongside automated web application testing with OWASP Top 10 coverage.
Compliance reporting
Reporting models built to meet industry and regulatory requirements, with optional customization for your auditors.
Scanning is the easy part. Reading it is the service.
Anyone can point a scanner at an estate. What you are buying is the judgement applied to what comes back, and the fact that someone chases the fixes.
- 01
Onboarding and asset discovery
We establish what you actually own — which is routinely more than the inventory says. Forgotten subdomains, a staging environment left public and a decommissioned host still answering are common first-scan findings.
- 02
Scan scheduling
Scans run on a cadence matched to your risk and change rate, with windows agreed so nothing runs against a fragile system at month-end close.
- 03
Validation and false-positive removal
Every finding is reviewed by a person before it reaches you. Raw scanner output is full of issues that do not apply to your configuration, and a queue that cries wolf is a queue your team stops opening.
- 04
Prioritisation by real risk
Severity is CVSS-informed but ranked by what is genuinely reachable in your environment. A critical on an isolated internal host outranks nothing on your perimeter.
- 05
Delivery into your workflow
Findings land in Sable with owners and due dates, or in your ticketing system if you would rather work there. The point is that they arrive where work actually happens rather than in a monthly PDF.
- 06
Trend reporting and review
You get trend reporting that shows whether exposure is falling, and a periodic review with an engineer to look at what keeps recurring — because a vulnerability that returns every quarter is a process problem, not a patching one.
Between penetration tests, someone is still watching.
Continuous identification
New vulnerabilities are disclosed daily. Continuous scanning finds what appeared since your last assessment, instead of waiting for the next one.
Attack surface reduction
Findings are tracked to closed and retested, so your exposed surface shrinks over time rather than being re-measured every quarter.
Expert consulting
Consulting support to help validate and remediate, with recommendations your team can act on rather than a CVE number and a link.
It runs in the platform.
Managed scanning is a Sable module, not a separate tool with its own login. Continuous scans across hosts and apps are deduplicated and ranked by real-world risk in the same workspace as your policies, risk register and controls, so a finding becomes a tracked item the moment it appears.
- 1,284Raw scanner outputacross 312 hosts
- 417After deduplicationsame issue, many hosts
- 63After validationfalse positives removed
- 9Actually exploitableranked, assigned, tracked
Common questions
- What is managed vulnerability scanning?
- Managed vulnerability scanning is a scanning programme run and read for you. The tooling, schedule, and coverage are handled by the provider, and every result is validated by an engineer before it reaches you, so false positives are removed and real findings arrive ranked by exploitability rather than as raw scanner output.
- How is managed scanning different from a penetration test?
- A penetration test is a deep, manual examination on a specific date, where testers chain weaknesses together to prove real impact. Managed scanning is continuous and automated, watching for anything new that appears between those tests. They answer different questions, and most organizations run both: scanning for coverage and currency, pen testing for depth.
- How often are scans run?
- Daily, weekly, or monthly, set to how fast your environment changes and how much risk you carry, rather than a fixed vendor schedule. Environments that deploy frequently or hold regulated data usually scan more often.
- Where do the scan results go?
- Into Sable, SubRosa's platform, where managed scanning is a module rather than a separate tool with its own login. Findings are deduplicated across hosts, ranked by real-world risk, and tracked from open to remediated alongside your policies, risk register, and controls.
- How is managed scanning different from running a scanner ourselves?
- The scanner is the cheap part. What you are buying is a person reviewing every finding before it reaches you, so false positives and issues that do not apply to your configuration are removed rather than landing in your team's queue. A queue that cries wolf is one your team stops opening, and that is the failure mode of self-run scanning far more often than the tooling.
- How often should scans run?
- It depends on your rate of change more than on a calendar. An estate that deploys weekly needs continuous scanning; a stable environment may be well served monthly with immediate scans after any significant change. Some frameworks specify a minimum — PCI DSS quarterly, for instance — and we set the cadence against both.
- Will scanning disrupt anything?
- Scans are non-intrusive by default and scheduled in agreed windows. Where you have fragile legacy systems, flag them during onboarding and we will scan them more gently or exclude them and handle them another way, rather than discovering the problem live.
- Where do the findings end up?
- In Sable with owners and due dates, or in your existing ticketing system if your team works there. The point is that findings arrive where work actually happens rather than in a monthly report nobody opens.
Ready to strengthen your vulnerability management?
Don't wait for a vulnerability to become a breach. Start continuous monitoring with expert analysis and remediation guidance your team can act on.