Scheduled assurance
Continuous Assurance
A point-in-time assessment is true on the day it is run. Continuous Assurance runs the authorised checks on a schedule and compares each run against the last, so new, resolved and unchanged findings are tracked over time. Runs are automated; findings are human-validated. There is no customer portal; you receive the reports and change summaries directly.
Scheduled, automated reassessment on an agreed cadence, with each run compared against the last. Passive reviews between runs use a locked profile that reads public data only and cannot invoke active modules. Findings are human-validated, and there is no customer portal; reports are delivered to you directly.
The problem
Exposure changes; a single assessment does not
PBX and VoIP estates move. A firewall rule is changed, remote administration is switched on for a supplier, a trunk is migrated, a new endpoint is deployed. Any of these can reopen exposure days after a clean assessment, and nobody is usually re-checking for it.
What we commonly find
- Firewall and remote-access changes that reopen exposure
- New services and endpoints deployed without review
- Newly published vulnerabilities affecting your platform vendor
- Configuration drift after migrations or supplier work
The approach
Scheduled reassessment with change tracking
The engine schedules the authorised checks on your cadence and diffs each run against the previous one, so you see what is new, what has been resolved and what is unchanged, with an exposure trend over time. Passive reviews between runs use a locked profile that cannot invoke any active module, so they are provably safe. Runs are automated; a person validates the findings before they reach you.
- Automated scheduled reassessment on your cadence (monthly, quarterly or annual)
- Historical change tracking: new, resolved and unchanged findings per run
- A locked passive profile that cannot invoke active testing, safe by construction
- Findings human-validated before they reach you; no customer portal
Methodology
How the engagement runs
- 1
Baseline
Establish the current exposure picture and a first set of findings for the agreed assets.
- 2
Schedule
Set the reassessment cadence; the engine runs the authorised checks automatically.
- 3
Reassess
Each scheduled run repeats the checks under your existing authorisation.
- 4
Diff & report
Compare against the last run and report new, resolved and unchanged findings with a trend.
- 5
Escalate
Recommend a focused assessment when a material change warrants it.
What you receive
- Baseline exposure picture and finding set
- Automated scheduled reassessment on your agreed cadence
- A change summary each run: new, resolved and unchanged findings
- An exposure trend over time
- A clear escalation path to a focused assessment
Who it suits
- Organisations that want assurance between assessments
- Businesses with changing or supplier-managed estates
- MSPs offering ongoing telephony assurance to their base
Risks it addresses
Silent re-exposure
Exposure often reopens through routine change; without reassessment, the first sign is an incident.
New vendor vulnerabilities
PBX and VoIP vendors publish vulnerabilities regularly; each run flags the ones that affect you.
FAQ
Continuous Assurance: questions
Is the reassessment automated?
Yes. Scheduling and run-to-run comparison are built into the engine, so reassessment happens on your cadence and each run is diffed against the last. Findings are still human-validated before they reach you.
Is there a live dashboard or customer portal?
No. We deliver the reports and change summaries to you directly. It is scheduled automated reassessment with change tracking, not a real-time monitoring portal, and we will not describe it as one.
Does it touch our systems?
The passive reviews between runs read only public data, using a locked profile that cannot invoke active modules. Scheduled active reassessment repeats the authorised checks under your existing authorisation.
Related services
Explore related assessments
PBX Security Assessment
An authorised, end-to-end assessment of the PBX systems your business runs on.
Read moreVoIP Security Assessment
An attack-surface review of your VoIP platform, endpoints and remote users.
Read moreToll-Fraud Risk Assessment
Find the exposure that lets attackers turn your phone system into call spend.
Read more
Keep your assurance current
Run the authorised checks on a schedule, with automated run-to-run change tracking and human-validated findings.
Testing is only performed against systems you own or are explicitly authorised to test.