Report week
Your managed clients each get a monthly vulnerability scan and a report. The scanning itself is automated in your scanning platform, such as Tenable Nessus, Qualys or Rapid7. The report is not. At the start of each month, an analyst exports each client's results, removes known false positives and accepted risks from a list kept in a spreadsheet, compares the totals with last month, writes a short summary, and pastes charts into a Word template with the client's name on it.
It takes a couple of hours per client, longer when something odd happens: a new range appeared, a scan failed halfway, or the client patched a lot and the numbers dropped sharply. With a few dozen clients, report week becomes report fortnight, and analysts stop doing anything else.
Clients mostly read the first page. The rest is there because it always has been.
And some reports go out with last month's accepted risks still counted, because the spreadsheet of exceptions was updated in one place and not the other.
Why the reports take so long
- Scanner exports list raw findings, not the story a client needs: what is new, what was fixed, what is overdue.
- Accepted risks and known false positives live outside the scanner, in spreadsheets or emails.
- Comparing with last month means finding last month's export and matching findings by hand.
- Each client wants their own format, logo and level of detail.
- Failed or partial scans need spotting before the report goes out, and nobody checks systematically.
What the manual report costs
| Problem | Cost |
|---|---|
| Hours per report | Analyst time off monitoring and investigation |
| Exceptions list out of date | Accepted risks reported as new |
| Partial scan not noticed | Report shows a false improvement |
| No month-on-month trend | Client cannot see progress |
| Late reports | Service reviews run without data |
The report is often the only thing some clients see of your service each month. When it is late or wrong, that is what they judge you on.
It also sets the tone for the service review. If the monthly report is a pile of scanner output, the review becomes a walk through a spreadsheet. If it shows a trend and the few changes that matter, the review becomes a conversation about priorities, which is where your analysts add value.
The scan reporting we build
- Scan results are pulled from your scanning platform by API for each client, as soon as scheduled scans complete.
- Each run is checked for completeness: expected targets scanned, scan finished, no unusual drop in hosts found. Incomplete scans are flagged to an analyst before any report is drafted.
- Accepted risks and false positives are held in one exceptions register, per client, with who approved each, when, and a review date. They are applied automatically.
- Results are compared with previous scans: new findings, resolved findings, findings still open and how long they have been open against the client's agreed targets.
- A branded draft report is produced per client, in the format you choose, with the trend and the headline changes on the first page.
- An analyst reviews the draft, adds commentary where it matters, and releases it. Released reports go to the client's portal or by email, and are stored for the service review.
We do not change how you scan. The work is in turning results into a report your team can stand behind with a short review rather than a rebuild.
What report week becomes
Drafts are ready soon after the scans finish. Analysts spend their time on the judgement: which change is worth explaining, what to recommend the client discusses internally. The exceptions register is one list, reviewed on schedule, rather than a spreadsheet nobody trusts. Clients get a consistent report that shows their trend, which gives your service review something real to talk about.
Signs your scan reporting needs automating
- Monthly reports take analysts days to produce.
- Accepted risks are kept in a spreadsheet separate from the scanner.
- Month-on-month comparison is done by hand, or not at all.
- A partial scan has made it into a client report.
- Reports go out late when the team is busy.