EmberKat

Vulnerability management consulting

Vulnerability Management Consulting

As a vulnerability management consultant, EmberKat helps teams turn vulnerabilities into decisions: which asset is affected, what is exploitable in context, who owns the change, when it ships and how closure is verified.

Discuss the scope
Typical durationUsually 2–4 weeks
Starting priceFrom €12,500 excl. VAT
Commercial basisWritten scope and proposal

Service definition

Make vulnerability work move

The engagement replaces a severity-sorted scanner queue with an evidenced vulnerability process that connects exposure, exploitability, service ownership, release capacity and accepted residual risk.

Scope

Work included in the scope

  1. 01

    Vulnerability inventory and asset-context review

  2. 02

    Severity, exploitability and exposure prioritisation

  3. 03

    Dependency and product vulnerability triage

  4. 04

    Ownership, SLA and exception-rule assessment

  5. 05

    Customer, regulator and disclosure response workflow

  6. 06

    Remediation verification and closure evidence

Client problems

Use this service when

  1. 01

    The scanner reports more work than engineering can safely absorb.

  2. 02

    Severity labels are treated as the risk model without asset context.

  3. 03

    The same vulnerability returns after it was marked closed.

  4. 04

    No one can explain which products, releases or customers are affected.

Deliverables

Documents and decisions provided

  1. 01

    Vulnerability-management operating model

  2. 02

    Risk-based prioritisation and triage rules

  3. 03

    Asset, service and remediation ownership map

  4. 04

    Exception, disclosure and customer-response route

  5. 05

    Verification and closure-evidence plan

Common questions

Questions to settle before the work starts

Short answers to the questions that usually determine whether this is the right engagement.

Does vulnerability management consulting replace a scanner?
No. It makes scanner output useful by adding asset, exposure, exploitability, ownership and verification context. Existing tools may stay; the decisions around them become explicit.
How do you prioritise vulnerabilities?
Priority is based on the affected asset, exposure, exploitability, business consequence, available mitigation and the time needed to change and verify the system—not on a severity label alone.
Can this support a product vulnerability disclosure?
Yes. The scope can include triage, affected-version analysis, remediation planning, reporting obligations, customer communication and evidence that the response was completed.

From the glossary

remediation
Actually fixing what an assessment found — as opposed to recording it.
The full glossary

Related engagement

Audit Findings Translation & Remediation Sprint

Translate findings and vulnerability reports into owned engineering work with acceptance criteria.

View engagement