Skip to content
Qualys, Inc.

Platform expertise / Qualys

A scanner measures. It does not remediate.

Qualys will tell you, accurately and continuously, how much work there is. Whether any of it gets done depends on an owner, a change path and somewhere an exception can live with an expiry date — none of which arrive with the licence. Aevis builds the half that closes findings.

Qualys is third-party software selected and licensed by the client from Qualys, Inc. Aevis provides advisory, deployment, integration and operational services around the client’s subscription.

Vulnerability management layer

Discovered · assessed · owned · closed
SECURITYIT OPERATIONSCLOUD ENGINEERINGAUDIT
Platform
Qualys
Starting point
Coverage and closure review
Commercial model
Project, deployment, managed or co-managed

Platform fit

The backlog grows faster than anyone closes it.

The scanner is working correctly. That is the difficulty: it produces more findings each week than the organisation has capacity to action, with no agreed order, no owner per asset, and no route from a finding into work anybody is measured on.

Findings with no owner

A report reaches a distribution list. Everyone on it assumes somebody else has the server, and the finding is still open at the next scan and the one after that.

Prioritised by severity alone

Ten thousand criticals is not a priority order. Without exposure, exploitability and business context, the queue is worked from the top and never reaches the thing that actually mattered.

Coverage that quietly stopped

Agents stopped reporting, a cloud account was never onboarded, a subnet is unauthenticated. The report is clean because those assets are absent, not because they are healthy.

Our role is to make findings owned, ordered and closed in your environment — not to sell an Aevis software product.

Product landscape

Where Qualys measures the estate.

We shape the engagement around the applications and entitlements your organisation has subscribed to. Scope, capability and scan behaviour always depend on your licensing and deployment.

VMDR

VMDR

Discovery, assessment, prioritisation and the remediation workflow the whole programme rests on.

  • Asset discovery
  • Vulnerability assessment
  • Risk-based prioritisation
Cloud

Cloud security posture

Misconfiguration and entitlement assessment across cloud accounts, where a finding is a config change rather than a patch.

  • CSPM across accounts
  • Container and image scanning
  • Entitlement review
Policy

Policy compliance

Configuration assessment against benchmarks, with drift reported per asset rather than per policy document.

  • CIS and custom benchmarks
  • Configuration drift
  • Evidence collection
Web apps

Web application scanning

Assessment of web applications and APIs, including the authenticated paths that make the results meaningful.

  • Authenticated scanning
  • API assessment
  • Finding triage
Patch

Patch management

Deploying the fix from the same platform that found the problem — useful where it fits your existing endpoint tooling rather than duplicating it.

  • Patch deployment
  • Job scheduling
  • Closure verification
Inventory

Asset inventory and CMDB sync

The discovered estate, and the reconciliation with the register that decides whether coverage figures mean anything.

  • Global asset inventory
  • CMDB synchronisation
  • Tagging and ownership

Aevis capabilities

From findings to closure.

Engage us for a focused intervention or an end-to-end programme. We work within your licensing, change-control and data-protection constraints.

Coverage and closure review

What is genuinely being assessed, what is missing, and what proportion of findings ever reach a verified closure.

  • Scan and agent coverage against an independently assembled asset view
  • Authenticated versus unauthenticated coverage, stated honestly
  • Closure-rate and age analysis across the current backlog

Ownership and prioritisation model

Who owns which asset, what order findings are worked in, and what happens when the answer is "not this quarter".

  • Asset tagging and ownership mapped to real accountable teams
  • Prioritisation on exposure and exploitability, not severity alone
  • Exception policy with justification, compensating control and expiry

Deployment and onboarding

Agents, scanners, cloud connectors and authenticated scanning configured so the data is trustworthy enough to act on.

  • Agent and scanner appliance rollout across sites and networks
  • Cloud account and container onboarding
  • Authentication records configured so scans see what they should

Integration with the workflow spine

Findings that become change records with owners, and closures that reconcile back rather than being asserted.

  • Service-management integration for remediation and exception records
  • Endpoint-tooling integration so remediation is actioned where it belongs
  • CMDB and SIEM feeds so one asset view is shared across teams

Reporting and assurance

Reporting built around the decisions it informs, including the coverage caveats an assurance team will ask about.

  • Executive and operational reporting from the platform, not spreadsheets
  • Evidence packs for client and third-party assurance
  • Coverage gaps reported alongside compliance figures rather than beneath them

Managed and co-managed operations

Running the scan calendar, the triage queue and the exception register, or standing behind a team that does.

  • Scan scheduling and platform health operated to an agreed calendar
  • Finding triage, false-positive handling and closure verification
  • Exception register reviewed rather than accumulated

AI and analytics in vulnerability management

Ranking is a model’s job. Accepting risk is not.

Prioritisation is the part of this discipline where analytics genuinely helps, because the input is large and numeric. The line below is where a ranking stops being advice and becomes a decision somebody is accountable for.

  • Risk-based prioritisation

    Ranking findings by exploitability, exposure and asset context so the queue is worked in a defensible order rather than by severity count.

  • Threat and exploit correlation

    Correlating findings with known exploitation activity so what is actually being used against organisations rises in the queue.

  • Assisted triage and summarisation

    Grouping related findings and drafting the remediation summary, with the underlying evidence shown rather than hidden.

What stays human — without exception

No AI accepts a risk, grants an exception or closes a finding. Prioritisation output is advice to the accountable owner; the decision to remediate, defer or accept is a human judgement made under your risk governance and remains the accountable decision of the person who made it. A ranking that is treated as an acceptance has quietly moved a risk decision from a person to a vendor’s model.

How value is measured

  • Asset coverage against the independent estate view
  • Time from detection to verified closure, by severity band
  • Findings closed against findings merely reported closed
  • Open exceptions, and how many are past their expiry
  • Owner override of model-suggested priority

Entitlement and data

Which analytics and prioritisation capabilities are available depends on the client’s Qualys applications and subscription, and on what the vendor ships in that release. Assessment data is processed for the agreed operational purpose only, under the client’s data-protection terms.

Connected architecture

The scanner is one end of a loop that has to close.

A finding is only useful if something downstream turns it into work with an owner and a due date, and something further downstream verifies it actually went away. Designing that loop is the engagement; the scanning is the easy part.

Assets

Endpoints, servers, cloud workloads, containers, web applications and the network paths a scanner can and cannot reach.

Assessment

Agents, appliances, cloud connectors, authentication records and the scan calendar that decides freshness.

Prioritisation and ownership

Tagging, asset ownership, risk scoring, the exception register and the policy behind all four.

Remediation and evidence

Change records, endpoint tooling, cloud pipelines and the verification that closes the loop.

Architecture boundaryAvailable applications, scan capability, API allowances and integration options depend on the client’s Qualys subscription and entitlement. We validate entitlement and network reachability before committing to a design.

Delivery model

Coverage, then ownership, then closure.

In that order, and the second is the one organisations try to skip. Prioritising a backlog before assets have owners produces a better-sorted list that still nobody actions.

  1. Review

    Establish real asset coverage, authenticated scan reach, backlog age and how many findings ever reach verified closure.

    Coverage and closure baseline
  2. Agree

    Settle asset ownership, prioritisation policy, remediation service levels and the exception rules including expiry.

    Written policy and ownership model
  3. Build

    Deployment or remediation work: agents, connectors, authentication, tagging and the integration that routes findings into owned work.

    Trustworthy data and a working closure path
  4. Pilot

    Run the full loop on one owning team — finding to change record to verified closure — before extending it.

    A proven loop on a real team
  5. Operate

    Run the scan calendar, the triage queue, the exception register and the reporting as one governed cycle.

    Governed operating cycle
  6. Improve

    Close standing exceptions, extend coverage into what the review found missing, and shorten the closure interval.

    Wider coverage, shorter closure time

Use cases

What organisations bring us.

Each of these is a normal starting point rather than a programme. We map the adjacent dependencies so a local fix does not create a hidden failure elsewhere.

A backlog nobody is closing

Findings grow weekly with no owner and no order. Ownership and prioritisation policy do more here than any scan change.

Designed outcomeA queue with owners and an order

A clean report from an incomplete scan

Assets absent from the scan are absent from the report. Reconciling against an independent estate view is the first honest step.

Designed outcomeCoverage stated, with its gaps named

An audit or client questionnaire

Evidence assembled after the fact rather than produced by the work. The fix is in the closure path, not the reporting.

Designed outcomeEvidence produced as work happens

Cloud accounts nobody onboarded

Workloads created faster than the assessment estate grew, so the newest infrastructure is the least assessed.

Designed outcomeCloud in scope as it is created

Remediation that never reconciles

The endpoint team patches and the scanner still reports. Closure verification is what turns the two into one number.

Designed outcomeClosures verified, not asserted

Exceptions that never expire

A register that only grows, with justifications whose authors have left. Expiry and review make it a control again.

Designed outcomeOwned exceptions with review dates

Engagement shapes

Four ways to start.

Which one fits is usually a question about where accountability should sit rather than about budget.

Coverage and closure review

Best forA backlog that will not shrink

A bounded assessment of coverage, authentication reach, backlog age and closure rate, ending in a gap list with an owner and an effort estimate against each item.

Deployment or integration project

Best forOnboarding, or a loop that does not close

Defined scope with acceptance criteria — agent and connector rollout, authenticated scanning, tagging or workflow integration — handed over documented.

Managed operations

Best forNo standing vulnerability team

Aevis operates the scan calendar, triage, exception register and reporting to an agreed cadence, with the accountability boundary set out in the service agreement.

Co-managed and enablement

Best forA team that should own this

We operate alongside your team and hand over deliberately, with the operating model documented and train-the-trainer where the capability should stay with you.

Designed outcomes

Measure closure, not detection.

Baselines and targets are agreed per engagement. We do not import a vendor benchmark into your estate and call it a business case.

Assessment coverage

Assets assessed, and authenticated, as a share of an independent estate view.

Time to closure

Detection to verified closure, by severity band and by owning team.

Verified closure rate

Findings confirmed gone at the next assessment, against findings reported closed.

Exception health

Open exceptions, how many are past expiry, and the trend in both.

What we do not promise

No provider can guarantee immunity from a vulnerability or a compliance outcome. Aevis performs vulnerability management rather than formal penetration testing, and certifies nothing. What is contracted is the operation, the evidence and the improvement practice within an agreed scope; the organisation retains its risk decisions and its regulatory interpretation.

Governance

The four things that keep this a control.

A vulnerability programme decays into a reporting exercise unless these four hold. Each is a standing control rather than a project deliverable.

Coverage reconciliation

The assessed estate is reconciled against an independent source on a cadence, so a figure is always a share of something agreed.

Ownership per asset

Every asset resolves to an accountable team, because a finding without an owner is a report rather than a piece of work.

Exception discipline

Every exception carries a justification, a compensating control and an expiry, and expiry means a review rather than automatic renewal.

Closure verification

A finding is closed when the next assessment confirms it, not when somebody marks it done.

Why Aevis

Platform expertise with an operator’s perspective.

We approach Qualys as one end of a loop that operations has to close. The work is designed to survive handover, a change of owner and an audit.

We measure closure, not detection

Detection is the part the platform already does well. The engagement is judged on whether findings reach verified closure, which is the only measure that describes a control rather than an instrument.

Ownership before prioritisation

A better-sorted backlog with no owners is still not actioned. We do the unglamorous asset-ownership work first, even though prioritisation demonstrates better.

We also do the remediating

Aevis runs endpoint and infrastructure operations. The people designing your closure path know what a patch costs to deploy on a Tuesday, which is why the service levels we propose are ones somebody can meet.

No licence resale

Licences are contracted directly between you and Qualys. We hold no margin in your asset count, which is worth checking for in any competing proposal.

Relationship clarityAevis does not claim ownership of Qualys products and this page does not state or imply a certified partnership. Product names and trademarks belong to their respective owners.

Testimonials

In their words.

Each testimonial is tied to the service it refers to, so service pages can draw the relevant one automatically.

  • The change we noticed first was not technical. It was that there was finally one person to call, and that person already knew the history of the problem.
    Placeholder NameHead of IT OperationsNorthvale BankManaged Services
  • They rebuilt the service catalogue around how our teams actually work rather than how the platform was shipped. Adoption stopped being an argument.
    Placeholder NameDirector, Service ManagementHalden InsuranceIT Service Management
  • We had the security tooling before Aevis arrived. What we did not have was anybody turning what it produced into decisions.
    Placeholder NameChief Information Security OfficerCerulean HealthCybersecurity

Frequently asked questions

Questions teams ask early.

The useful answers depend on your estate and subscription. These are the principles we use before an assessment establishes the exact scope.

Are you a Qualys partner?

This page makes no partnership claim. Aevis provides advisory, deployment, integration and operational services around a subscription the client holds directly with Qualys. Where a formal partner relationship is relevant to a procurement, ask us and we will answer it precisely rather than by implication.

Is this the same as a penetration test?

No, and the distinction matters commercially as well as technically. Vulnerability management is continuous, automated assessment of known weaknesses across an estate. A penetration test is a scoped, human exercise against a defined target at a point in time. They answer different questions, most assurance regimes want both, and Aevis performs the first — we do not certify your organisation.

We have thousands of open findings. Where do we start?

Not by sorting them. Start with asset ownership, because a prioritised backlog with no owners produces a better-ordered list that still nobody actions. Once every asset resolves to an accountable team, prioritisation by exposure and exploitability turns an unusable count into a week of defensible work.

How does this sit with our endpoint tooling?

They are the two halves of the same loop and the split is worth deciding deliberately. Qualys is generally the better instrument; your endpoint platform is often the better actuator, particularly where it already owns patching. What matters is that closure reconciles between them, so the same finding is not open in one system and closed in the other.

Some findings cannot be remediated. What then?

They become a documented, owned exception with a justification, a compensating control and an expiry date, rather than an entry that ages silently. Expiry means a review, not automatic renewal — an exception register that only grows has stopped being a control.

Can our own team take this over?

That is the co-managed shape. The operating model, tagging scheme and closure path are documented as they are built, and train-the-trainer is available through the Corporate Training practice. A supplier whose model depends on you not holding this capability is the wrong supplier for it.

Qualys enquiry

Start with what happens after a finding.

Tell us what your scanner reports, and what happens to one of those findings the day after it appears. The second answer is usually the whole brief.

Response
One working day, Monday to Friday

Enquiry attributed toQualys

Your details are used to respond to this enquiry. Licensing is contracted directly with the vendor, and any scope, target or control responsibility is agreed only through the formal engagement process.