Vulnerability Management
Most vulnerability management programmes
do not fail on the technology.
They fail because nobody ever settled who fixes what by when. The tool reports findings and very little happens next. We build the process behind it, your engineers run it, and we make sure it does not quietly revert.
The starting point
Nobody usually knows what their real coverage is.
Ask about coverage and you almost always get a number the tool produced. That number is almost always too high. Unauthenticated scans count in the statistics as though they were authenticated. Deduplication merges hosts that are not the same host. And whole network segments were never in scope at all, because nobody mentioned them when the thing was set up.
This is not a criticism of the product. The commercial platforms are good. They report on what they saw rather than on what is there, and the difference between those two numbers is precisely the part of your environment nobody knows anything about.
We start with that difference, because it is usually the finding that changes the conversation.
Two paths
We find organisations in one of two states.
The two look similar from outside but need a different starting point, so the first thing we establish is which one you are in.
The platform is in place and produces nothing
Somebody bought it two years ago. Scans run intermittently or not at all, findings reach no ticket queue, and the licence renews every year regardless. It is an uncomfortable position with one advantage: you can point at the invoice and know exactly what the problem costs. We establish why the rollout stopped, which of the original decisions have to be reversed, and get the programme running.
There is no programme at all
You know something is missing, but not what good looks like, how long a build takes, or what you will actually need at the end. That uncertainty is the real reason these projects sit still. We design the process, help choose tooling that fits your environment, define the measures, and work alongside your engineers until you are running it yourselves.
Working together
Three ways to work with us.
All three run at a fixed scope and a fixed price set at sign-off. Your engineers do the work; we design, measure and review. The easiest way in is at the top.
Advisory retainer
One day a month, and you set the agenda. We work through the numbers and ask why they moved. We clear exceptions that have aged past their deadline and bring new business units into the process. And we are reachable when one of your engineers wants a second opinion before committing to an approach. The effort is capped in the contract, so the retainer does not turn into an on-call arrangement.
Current-state assessment
A week to establish where you actually stand. What the existing tooling really sees, how a finding travels today from detection to closure, and at which point the chain breaks. You get a written report with a prioritised roadmap that belongs to you and that you can circulate internally. If you commission a programme within three months, half the fee is credited against it.
Programme restart
Diagnosis of a rollout that stopped, and recovery to a working programme. We establish first which of the original decisions are blocking the programme, and reverse only the ones that genuinely have to go. What follows is the same process as a build, running on the platform you are already paying for.
Why BrightPath
We earn nothing from which platform you choose.
When you buy a platform, the vendor offers you the rollout with it. Those teams are good and they know their product better than any outside advisor. They are measured on their own software working in the end, rather than on whether it was the right choice for you.
One question you can test us with
Ask what we earn if you choose a different platform. The answer is nothing. We hold no resale margins, no rebates and no vendor certifications that would create a preference. That answer is the same for every product on the market, and you can check it.
Requirements first, product second
We establish with you what the solution has to do before discussing any product. The alternatives we considered go into the recommendation with the reasoning. The decision stays yours and is still traceable in two years.
Swiss contract, Swiss law
BrightPath GmbH, Windisch, Aargau. Swiss law, Swiss jurisdiction, Swiss personnel, professional indemnity in place. No sub-processors, no licence chain and no third party in the data path, which means there is no supplier behind the supplier.
Your people execute
We design and review; we operate nothing. That keeps engagements finite and means your team genuinely holds the capability at handover rather than depending on us. If you would rather hand the running of it to someone, a managed service provider suits you better, and we are happy to name one.
Clarity
What we do not offer.
We do one thing and refer the rest on. This appears in every engagement scope, together with the referral.
- No SOC, no round-the-clock monitoring and no managed detection
- No operation of your tooling, because we design and review while you execute
- No penetration testing and no red-team work
- No incident response, though we do take on the work afterwards
- No certification and no attestation, but the evidence your auditor uses
- No software or hardware resale, in any form
Common questions
What you are probably about to ask
Next step
Let's talk before you decide anything.
One to two hours with your technical people. We work through where you stand, what has already been tried, and what a realistic next step would be. If it turns out you can do this yourselves, that is a result too.
Arrange a conversation