Christchurch · Dunedin · Nationwide
Vulnerability Management Services for NZ Businesses
Find, prioritise, fix and verify the weaknesses across your computers, servers, internet-facing systems and Microsoft 365. Exodesk agrees what is covered, how findings are ranked and who fixes each one, then checks and records the result.
Supporting New Zealand businesses since 1989
The short answer
What is vulnerability management?
Vulnerability management is the repeating cycle of finding security weaknesses across the systems a business runs, deciding which ones matter, fixing or reducing them, and confirming the fix worked.
It covers more than missing patches. Misconfigured settings, default or weak credentials, services exposed to the internet and outdated software inside the applications you bought all count. New weaknesses are published every week and systems change, so a scan describes the day it ran. The service keeps the cycle going and gives every finding an owner.
When to look closer
Signs your weaknesses are not being managed
A business can patch diligently and still leave known weaknesses open.
These are signs the cycle has a gap somewhere, not a diagnosis.
Nobody knows what is exposed
There is no current list of what can be reached from the internet, or which systems are running old software.
Reports nobody acts on
A scanning tool produces a long list each time it runs, and the same findings reappear with no owner.
Updates on, settings unchecked
Windows updates install, but firewall rules, remote access and admin accounts have not been reviewed in years.
Software outside the update cycle
Business applications, browsers, plug-ins and device firmware are left out of the routine that updates the operating system.
Cloud settings left at setup
Microsoft 365 was set up once and its security settings have not been compared with current guidance since.
Closed tickets, unchecked fixes
A fix is marked done without anyone confirming the weakness is gone from the system.
What we cover
What does our vulnerability management service cover?
Four areas, each checked in the way that suits it. Your vulnerability management scope lists the supported operating systems, applications, cloud services and checks, including anything excluded or dependent on another provider.
Computers
Laptops and desktops
Missing updates, outdated applications and weak settings on the Windows and Mac computers staff use every day.
A computer past vendor support cannot be fully patched. We flag it with the options for replacing or isolating it.
Servers
Physical and virtual servers
Operating system and application weaknesses on the servers your business runs, with fixes planned around the role each server plays.
Changes that could interrupt a business system are scheduled with you before they go on.
Internet-facing
Firewalls, remote access and public services
External scans of the addresses and services you authorise, looking for exposed admin pages, unpatched remote access and services that should not be reachable at all.
We only scan systems you own or have permission to test, and the list is agreed in writing.
Cloud
Microsoft 365 and cloud settings
Security settings in your Microsoft 365 tenant and supported cloud services compared with current guidance, so weak configuration is found alongside missing patches.
The cloud provider patches its own platform. The settings you control inside it are part of your scope, and wider cloud protection is scoped through our cloud security service.
The service
What our vulnerability management service includes
Six areas of work that take a finding from first detection to a checked and recorded outcome.
Asset inventory
A record of the computers, servers, internet-facing systems and cloud services in scope, kept current as things are added and retired.
Agent and external scanning
Agents on computers and servers report supported vulnerability and configuration findings as checks run and devices report in, and scheduled external scans check what can be reached from the internet.
Prioritisation
Each finding ranked on whether it is being exploited, whether it is exposed, what the system is worth to you and its severity score.
Patching and fixes
Updates applied and settings corrected on the systems we manage, with vendors followed up where the fix is theirs to supply.
Verification
Each result checked by follow-up scan, agent report or configuration review. Findings are recorded as fixed, mitigated, accepted or still open, and accepted risks have an owner and review date.
Reporting
A clear view of what was found, what was fixed, what is waiting on a decision and what has been accepted, in plain language.
Before vulnerability management work starts, we agree how often external scans and cloud reviews run, when findings are reviewed, and how urgent issues are escalated. Remediation timeframes reflect the risk, the systems affected and any approval or vendor dependency. Scheduled reporting does not replace the agreed escalation route for urgent findings.
Some related work has its own service. Protection software on each device is covered in endpoint security, round-the-clock investigation of alerts in managed detection and response, and a person actively trying to break in is penetration testing. This service focuses on finding, prioritising and resolving known weaknesses across the systems in scope.
Vulnerability management can be bought on its own or alongside our managed IT services, and it works with your current IT provider or internal team on a co-managed basis.
Getting started
How does vulnerability management work?
The first pass sets a baseline. After that, the cycle repeats to address outstanding findings and changes in your systems.
Agree scope and permission
List the systems in scope, confirm which internet-facing addresses we are authorised to scan, and agree which changes need your sign-off first.
Establish the baseline
Deploy agents, run the first external scan and review cloud settings. Expect the first list to be long. That is the normal starting point.
Rank what matters
Sort the findings into fix now, fix next and planned, and walk you through anything that needs a business decision.
Fix and reduce
Apply updates and configuration changes, or put a compensating control in front of a weakness that cannot be removed yet.
Verify and repeat
Check each result, record it as fixed, mitigated, accepted or open, and pick up new findings as devices report in and scheduled scans run.
Prioritisation
How do we decide what to fix first?
A severity score on its own is not a to-do list. We weigh four things together.
- Is it being exploited? A weakness attackers are using now can outrank a higher-scored one nobody has used. The Known Exploited Vulnerabilities catalogue from the United States Cybersecurity and Infrastructure Security Agency is one free input to that judgement.
- How could it be reached? We assess how an attacker could reach the weakness, including internet exposure, internal access and existing controls.
- What would the impact be? We consider the impact on operations, money and information, including the access the system has to other services.
- What is the severity score? The Common Vulnerability Scoring System rates weaknesses from None through Low, Medium and High to Critical. CVSS v4 includes Threat and Environmental metrics so a score can reflect exploitation and the environment in which the system runs, not just the base rating.
Ownership
Who fixes what we find?
A finding without an owner stays on the list. Your scope sets out who handles each type.
We fix
Systems we manage
We apply patches and correct settings on the computers, servers, network equipment and cloud tenants we look after.
We coordinate
Vendor and third-party software
Where the fix has to come from a software vendor or another provider, we raise the finding with them, track progress and discuss mitigation or replacement where a fix is unavailable.
You decide
No fix available yet
Where a weakness cannot be removed, we recommend a way to reduce the risk. If you accept the risk, we record your decision with an owner and review date, so accepted risks are deliberate and revisited.
Where we work alongside your own IT team or another provider, the agreement lists which systems each party fixes, and we still verify the result.
NZ guidance
How fast should critical patches go on?
The New Zealand Information Security Manual sets two days for critical patches, with a distinction worth knowing.
The NZISM applies to government agencies and to organisations with agreements to access classified information. Other businesses can use it as a published benchmark.
MUST, Confidential and above
Critical patches within two days
Control 12.4.4.C.01 requires critical security patches as soon as possible and within two days of release, at Confidential, Secret and Top Secret.
SHOULD, other classifications
Preferably within two days
Control 12.4.4.C.04 recommends the same two days at every other classification, as soon as possible and preferably within that window.
MUST, all classifications
A patch management strategy
Control 12.4.4.C.02 requires a patch management strategy, including an evaluation or testing process, at every classification.
The same manual makes it a MUST at all classifications to obtain assurance that cloud providers patch and maintain their own systems. In practice that means a documented process with timeframes you can check against, and asking your providers the same question.
The NCSC Patching Minimum Standard, written for government agencies, sets critical patches within two days of release on internet-facing systems and within two weeks on internal systems. These are published benchmarks, not Exodesk service commitments.
The evidence
Why known weaknesses still matter
Unpatched weaknesses remain a route into business systems. Reducing that exposure is one part of a wider security programme.
Sophos State of Ransomware 2026, a survey of 2,158 IT and cybersecurity professionals at organisations with 100 to 5,000 employees in 17 countries, found malicious email and phishing behind half of the ransomware attacks respondents reported, with exploited vulnerabilities behind 18 per cent. The National Cyber Security Centre Cyber Threat Report 2025 says failing to patch in time has been a contributing factor in a significant proportion of the high impact incidents it recorded over five years.
The same report describes how, in August 2025, NZ Police gave the NCSC information that devices at 19 New Zealand organisations had been compromised by a suspected ransomware group. When the NCSC investigated, every compromised device was exposed to the same known vulnerability. Vulnerability management exists to find that kind of weakness before someone else does. Our ransomware protection guide covers the other routes in.
Cost
What affects the cost of vulnerability management?
The service is priced on what it covers and how much of the fixing we do.
We scope the service before quoting. These are the things that move the figure:
- Computers and servers. The number of devices running agents.
- Internet-facing systems. How many public addresses and services are scanned.
- Cloud scope. Whether Microsoft 365 and other cloud settings are included.
- Remediation. How much patching and configuration work we carry out, compared with coordinating fixes by others.
- The starting point. A large first backlog can need a one-off clean-up before the regular cycle begins.
Your quote sets out what the recurring fee covers and what counts as separate project work.
Why Exodesk
Why work with Exodesk?
Supporting businesses since 1989
We support New Zealand organisations from our teams in Christchurch and Dunedin, with weaknesses fixed by people who understand your systems.
Found, resolved and recorded
We do not stop at a report. Findings are ranked, fixed or reduced, and checked, so the record matches the systems.
Part of your wider security
Vulnerability management sits alongside our cyber security services and network security, so weaknesses and defences are handled together.
Questions
Vulnerability management questions
What is vulnerability management?
Vulnerability management is the repeating cycle of finding security weaknesses across your systems, deciding which ones matter, fixing or reducing them, and confirming the fix worked. It covers misconfigured settings, weak credentials and exposed services as well as missing patches. The cycle repeats because new weaknesses are published every week and systems change.
How is vulnerability management different from patch management?
Patch management applies vendor updates, and it is one part of vulnerability management. The wider service also finds weak settings, exposed admin interfaces, default credentials and outdated components inside business software. A business can patch diligently and still be exposed, because no patch closes a service that should not have been reachable from the internet.
What does your vulnerability management service cover?
Laptops and desktops, physical and virtual servers, internet-facing systems such as firewalls and remote access, and Microsoft 365 and supported cloud settings. Each area is listed separately in your scope. External scans only cover the addresses you authorise in writing.
How do you find vulnerabilities?
Agents on your computers and servers report missing updates and weak settings as checks run and devices report in. Scheduled external scans check what can be reached from the internet, and cloud settings are reviewed against current guidance. We also check again after significant changes, such as a new system going live.
How often are systems checked?
How often external scans and cloud reviews run, and when findings are reviewed, is agreed in your vulnerability management scope before work starts. Urgent findings are raised through the agreed escalation route rather than waiting for the next scheduled report. Remediation timeframes reflect the risk, the systems affected and any approval or vendor dependency.
Who fixes the vulnerabilities you find?
We apply patches and correct settings on the systems we manage. Where the fix has to come from a software vendor or another provider, we raise the finding with them, track progress and discuss mitigation or replacement if no fix is available. If you choose to accept a risk, we record the decision with an owner and review date.
How do you decide which vulnerabilities to fix first?
We weigh four things together: whether the weakness is being exploited, how an attacker could reach it, the impact on your business and its severity score. The CISA Known Exploited Vulnerabilities catalogue is one free input on exploitation. A lower-scored weakness under active attack can outrank a higher-scored one nobody is using.
How do you check a fix worked?
We check the agreed action using a follow-up scan, agent report or configuration review. A fixed finding needs a successful check. If the weakness remains but a control reduces the risk, we record it as mitigated, and any accepted risk is recorded separately with an owner and review date. A closed ticket alone does not show that a weakness has been removed.
What is CVSS and how much should we rely on it?
The Common Vulnerability Scoring System rates weaknesses from None through Low, Medium and High to Critical on a scale of 0 to 10. CVSS v4 includes Threat and Environmental metrics so a score can reflect exploitation and the environment in which the system runs. A base score alone is a starting point, which is why we use it alongside exploitation, exposure and business importance.
How quickly should critical patches be applied in New Zealand?
The New Zealand Information Security Manual sets two days from release for critical patches. It is a MUST for Confidential, Secret and Top Secret systems and a SHOULD, preferably within two days, at other classifications. The manual applies to government agencies, so for other businesses it is a published benchmark, not a rule and not an Exodesk service commitment.
Is vulnerability management the same as penetration testing?
No. Vulnerability management is the ongoing cycle of finding and fixing known weaknesses across the whole environment. A penetration test is a point-in-time exercise in which a person actively tries to break in by chaining weaknesses together. The two work best as complements.
Can a New Zealand business get free vulnerability scanning from the government?
The National Cyber Security Centre runs a Vulnerability Insights Programme that reports on internet-facing weaknesses, and its sign-up page is written for government organisations. Check eligibility with the NCSC directly. Its incident response service is available to all New Zealanders, including small businesses.
Can we buy vulnerability management without managed IT?
Yes. Vulnerability management can be bought on its own, without moving the rest of your IT to Exodesk. We can work alongside your current IT provider or internal team, with the agreement setting out who fixes each type of finding.
How much does vulnerability management cost?
The cost depends on the number of computers and servers, the internet-facing systems scanned, whether cloud settings are included and how much of the fixing we carry out. A large first backlog can need a one-off clean-up. Your quote sets out what the recurring fee covers.
Next step
Find what is exposed before someone else does
Talk to Exodesk about vulnerability management for your computers, servers, internet-facing systems and Microsoft 365. We will discuss what you have, what is in scope and what a sensible first step looks like.
If you would rather see where you stand across your whole IT environment first, request an IT assessment.
Get in touch
Discuss vulnerability management
Tell us a little about your systems and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941