Skip to content

Scheduled assurance

Continuous Assurance

A point-in-time assessment is true on the day it is run. Continuous Assurance runs the authorised checks on a schedule and compares each run against the last, so new, resolved and unchanged findings are tracked over time. Runs are automated; findings are human-validated. There is no customer portal; you receive the reports and change summaries directly.

Scheduled, automated reassessment on an agreed cadence, with each run compared against the last. Passive reviews between runs use a locked profile that reads public data only and cannot invoke active modules. Findings are human-validated, and there is no customer portal; reports are delivered to you directly.

The problem

Exposure changes; a single assessment does not

PBX and VoIP estates move. A firewall rule is changed, remote administration is switched on for a supplier, a trunk is migrated, a new endpoint is deployed. Any of these can reopen exposure days after a clean assessment, and nobody is usually re-checking for it.

What we commonly find

  • Firewall and remote-access changes that reopen exposure
  • New services and endpoints deployed without review
  • Newly published vulnerabilities affecting your platform vendor
  • Configuration drift after migrations or supplier work

The approach

Scheduled reassessment with change tracking

The engine schedules the authorised checks on your cadence and diffs each run against the previous one, so you see what is new, what has been resolved and what is unchanged, with an exposure trend over time. Passive reviews between runs use a locked profile that cannot invoke any active module, so they are provably safe. Runs are automated; a person validates the findings before they reach you.

  • Automated scheduled reassessment on your cadence (monthly, quarterly or annual)
  • Historical change tracking: new, resolved and unchanged findings per run
  • A locked passive profile that cannot invoke active testing, safe by construction
  • Findings human-validated before they reach you; no customer portal

Methodology

How the engagement runs

  1. 1

    Baseline

    Establish the current exposure picture and a first set of findings for the agreed assets.

  2. 2

    Schedule

    Set the reassessment cadence; the engine runs the authorised checks automatically.

  3. 3

    Reassess

    Each scheduled run repeats the checks under your existing authorisation.

  4. 4

    Diff & report

    Compare against the last run and report new, resolved and unchanged findings with a trend.

  5. 5

    Escalate

    Recommend a focused assessment when a material change warrants it.

What you receive

  • Baseline exposure picture and finding set
  • Automated scheduled reassessment on your agreed cadence
  • A change summary each run: new, resolved and unchanged findings
  • An exposure trend over time
  • A clear escalation path to a focused assessment

Who it suits

  • Organisations that want assurance between assessments
  • Businesses with changing or supplier-managed estates
  • MSPs offering ongoing telephony assurance to their base

Risks it addresses

  • Silent re-exposure

    Exposure often reopens through routine change; without reassessment, the first sign is an incident.

  • New vendor vulnerabilities

    PBX and VoIP vendors publish vulnerabilities regularly; each run flags the ones that affect you.

FAQ

Continuous Assurance: questions

Is the reassessment automated?

Yes. Scheduling and run-to-run comparison are built into the engine, so reassessment happens on your cadence and each run is diffed against the last. Findings are still human-validated before they reach you.

Is there a live dashboard or customer portal?

No. We deliver the reports and change summaries to you directly. It is scheduled automated reassessment with change tracking, not a real-time monitoring portal, and we will not describe it as one.

Does it touch our systems?

The passive reviews between runs read only public data, using a locked profile that cannot invoke active modules. Scheduled active reassessment repeats the authorised checks under your existing authorisation.

Related services

Explore related assessments

Keep your assurance current

Run the authorised checks on a schedule, with automated run-to-run change tracking and human-validated findings.

Testing is only performed against systems you own or are explicitly authorised to test.