APaaS Assure · Module

Security

Known-exploited vulnerabilities, external exposure and endpoint protection on your live estate - with the SLA clock mapped to the Cyber Essentials 14-day window and the next fix proposed for you.

See it in action

A working Security screen with representative sample data.

assure.apaas.org / security
Open the full demo ↗

The modules

KEV-Aware Risk Register

NIST NVD plus CISA Known Exploited Vulnerabilities overlaid on your live estate. The SLA clock starts the moment a KEV match is found, mapped to the CE+ 14-day window, and a high-confidence filter keeps the register to actionable rows, not noise.

External Vulnerabilities

An outside-in view of the client's internet-facing footprint - an A-F security grade and scorecard from external scanning, so the exposures an attacker would see sit on the same page as the internal estate.

Endpoint Protection Health

Microsoft Defender and anti-malware health from the device agents - protection state, real-time scanning, signature age, tamper protection and risky exclusions, scored per device with no cloud connection required. Connect Defender for Endpoint to add alerts, incidents and exposure.

Network Security

Passive discovery of what's actually on the client network - devices, roles and OUI vendor fingerprints from the agent - building a live picture of the network surface without active scanning.

Advisory Remediation Agent

An agent that reviews the estate and proposes the next fixes - patch this, remove that - as reviewable recommendations with the evidence behind them. Autonomy tiers and a kill switch keep you in control: it suggests, you approve.

What it finds, and what it does

Security pulls every vulnerability source and every endpoint signal into one live view of a client's risk, then puts a clock and a next-action on each item so nothing drifts past a deadline.

  • Actively-exploited vulnerabilities (CISA KEV) present on real devices, with the count of affected installs.
  • Critical and high CVEs from NIST NVD, correlated to the true installed version - coarse, major-only matches filtered out.
  • Patch SLAs mapped to the CE+ 14-day window, with anything overdue surfaced first.
  • Internet-facing exposure graded A-F, so external risk sits beside internal risk.
  • Endpoints running without real-time protection, with stale signatures, tamper protection off, or drive-wide exclusions.

And then it acts on it: the SLA clock starts automatically on a KEV match, the register ranks by exploitation and severity, and the advisory agent proposes the specific fix to apply next - which, through Application Packaging, can be packaged and shipped to Intune or ConfigMgr in minutes.

Further reading

Practical guides from the APaaS Assure team.

See your estate's exposure.

UK-based onboarding · No procurement friction

Book a demo