Cyber Security
Vulnerability Management Service with Dark Web and Credential Monitoring
Monthly scanning, risk-ranked triage and a tracked fix list, plus alerts when your staff passwords or company data show up where criminals trade them.
When you need a vulnerability management service
A vulnerability management service finds the weaknesses attackers use before they do, ranks them by real risk, and tracks each fix until it is verified. Honeybadger Solutions runs it as part of our managed cyber security services, paired with monitoring for leaked passwords and exposed company data on criminal markets and paste sites.
Most small and mid-sized organizations already patch something. The gaps are elsewhere: a firewall or VPN appliance nobody updates, a forgotten server still facing the internet, a staff password reused on a breached website, or a scan report with hundreds of findings and no owner. Scanning without triage and tracking produces noise, not lower risk.
You likely need help if:
- Your cyber insurer or a client questionnaire asks how often you scan and how fast you patch.
- You have never seen a full list of what your organization exposes to the internet.
- A scan report exists but nobody knows which findings matter first.
- Staff credentials appeared in a breach notice or on a dark web report.
- You are preparing for a framework review such as CMMC, HIPAA or PCI DSS.
What changed in federal patch guidance in 2026?
CISA’s Known Exploited Vulnerabilities (KEV) catalog lists flaws that have been exploited in the wild. As of October 2, 2026 it held 1,733 entries. CISA calls it the authoritative source of exploited vulnerabilities and says every organization, including private industry, should use it as an input to vulnerability prioritization.
In November 2021, Binding Operational Directive 22-01 gave federal agencies flat deadlines to fix KEV entries. In June 2026, CISA replaced it with BOD 26-04, Prioritizing Security Updates Based on Risk. The new directive ranks each flaw on each asset by four factors: whether the asset is reachable from the internet, whether the flaw is on the KEV list, whether exploitation can be automated, and whether it gives an attacker partial or total control. For federal agencies, the worst combination must be fixed within three calendar days, and the highest-risk cases call for checking whether the system was already compromised.
BOD 26-04 binds federal civilian agencies, not your business. We use the same four factors because they answer the question owners actually ask: what do we fix this week?
| Risk combination | Example | What we recommend |
|---|---|---|
| Internet-facing, on the KEV list, easy to automate, full control | An exploited VPN or firewall flaw on a public appliance | Patch or isolate now, and look for signs of prior compromise before calling it closed |
| On the KEV list but internal, or exposed but not yet exploited | An exploited Windows flaw on office laptops | Fix in the next short cycle; confirm with a rescan |
| Internal, not exploited, limited impact | An outdated library on an internal server | Schedule into routine patching |
| Minimal risk | A low-impact issue on an isolated test system | Fix at the next planned upgrade |
Is a vulnerability scan the same as a penetration test?
No. Scanning is automated, broad and repeated every month; a penetration test is a human trying to chain weaknesses together at a point in time. Most organizations need scanning continuously and a test periodically. Our guide to penetration testing vs vulnerability scanning explains the difference in detail.
What we deliver
Four services can run alone or together. Most clients start with a baseline assessment or go straight to monthly vulnerability management.
Vulnerability management
Priced per asset, per month. A monthly authenticated scan, triage that removes false positives and ranks findings by exposure, KEV status and impact, a remediation tracker with an owner and due date for each item, and a capped number of analyst hours each month for follow-up and rescans.
External exposure and credential monitoring
A monthly service for one domain and a set number of staff identities. We watch breach data, criminal markets and paste sites for your domain and accounts, review findings with you each month, and tell you which passwords to reset. Takedown requests are a separate engagement.
Security baseline assessment
A fixed project with a capped number of consultant hours for one tenant or site and a set number of endpoints. We review configuration, patch levels, exposure and identity settings, then deliver prioritized findings and a debrief. It is the usual starting point.
Identity threat monitoring
Priced per identity, per month. A monitoring license and alerts on risky sign-ins and suspicious account changes in your Microsoft 365 or Google environment, so a stolen password is caught when it is used, not weeks later.
How a vulnerability management engagement runs
- Request online. Tell us roughly how many devices, servers, cloud tenants and public domains you have.
- Written authorization. You sign a scope that lists the IP ranges, domains and systems we may scan, the scan windows, and anything fragile to exclude.
- Asset inventory. We reconcile what you think you own with what we find, because you cannot fix a server nobody knows about.
- Scan. External scans of internet-facing assets and authenticated internal scans run monthly. CIS Controls v8 safeguards 7.5 and 7.6 call for internal scans at least quarterly and external scans at least monthly.
- Triage. We remove false positives and rank what remains using exposure, KEV status, automation and impact.
- Track. Each finding goes into a tracker with an owner and a date. Your IT team or our managed IT team does the fixes under its own scope.
- Verify and report. We rescan to confirm fixes and send a short monthly report showing what is open, what closed and what is overdue.
Credential monitoring runs alongside. When an account appears in breach data, we tell you which user, which source and what to do: reset the password, check multifactor settings and review recent sign-ins. NIST SP 800-63B-4, finalized in July 2025, requires checking new passwords against lists of known compromised passwords, and our findings help you do that.
Authority, consent and legal limits
We scan only systems you own or are authorized to test, under a signed scope. Scanning or accessing a system without authority can be a crime; Arizona’s computer tampering statute, A.R.S. 13-2316, covers a person who acts without authority or exceeds authorization. If your website, email or servers are hosted by a vendor, we confirm the vendor’s testing rules first. We do not scan your suppliers, customers or competitors.
Dark web monitoring is observation only. We do not buy stolen data, log in with leaked credentials, contact criminals or try to hack back. Leaked records stay out of our reports except for what you need to act, such as the affected account name. If monitoring shows signs of an active breach, we move you to cyber incident response. This is general information, not legal advice.
How it is priced
Our vulnerability management service is priced in words here and in numbers on your written quote. Vulnerability management is billed per asset per month, with a monthly minimum per customer, and includes the monthly scan, triage, the tracker and a capped block of analyst hours. External exposure and credential monitoring is a flat monthly fee for one domain and a set number of identities. The baseline assessment is a fixed project with stated hours, one tenant or site and a set endpoint count. Identity threat monitoring is billed per identity per month with a customer minimum, and includes the license and alerts.
The main cost drivers are the number of assets, the number of domains and identities, and how much follow-up your team needs from our analysts.
| Included | Quoted separately |
|---|---|
| Monthly scans, triage and remediation tracker | Hands-on patching and configuration fixes |
| A capped block of analyst hours each month | Analyst time beyond the monthly cap |
| Monthly credential findings review for one domain | Extra domains, extra identities and takedown requests |
| Baseline findings and debrief for one tenant or site | Penetration testing and incident response |
Mistakes to avoid before you contact us
- Ranking by severity score alone. A critical score on an isolated test box can matter less than a medium flaw on your VPN that is on the KEV list.
- Scanning without credentials. Unauthenticated scans miss most missing patches on workstations and servers.
- Closing tickets without a rescan. A patch that failed to install looks the same as one that worked until you check.
- Patching an exploited edge device and moving on. If it was exposed and exploited, look for signs someone got in first.
- Treating dark web monitoring as protection. It tells you a password leaked. Multifactor authentication and resets are what protect you.
- Leaving the asset list to memory. Old servers, test sites and former employees’ cloud accounts are where attackers look first.
Who this is for
- Small and mid-sized businesses
- Medical, dental and veterinary practices
- Law and accounting firms
- Defense contractors working toward CMMC
- Nonprofits and schools
- Companies answering cyber insurance questionnaires
Why the online request is faster
Choose vulnerability management on the online request form and it goes straight to the cyber and forensics lead who scopes this work. You give us your asset counts and domains once, we can review your public exposure before we talk, and there is no phone tag.
Frequently asked questions
How often should we scan for vulnerabilities?
CIS Controls v8 calls for external scans at least monthly and internal scans at least quarterly. Our vulnerability management service scans both monthly, and we add targeted rescans when a new KEV entry affects something you run.
What is the CISA KEV catalog?
It is CISA’s list of vulnerabilities known to be exploited in the wild, with 1,733 entries as of October 2, 2026. CISA recommends that every organization use it to decide what to fix first, and we flag KEV matches in every report.
Does dark web monitoring remove our data?
No. Once data is posted or sold, removal is rarely possible. Monitoring tells you what leaked so you can reset passwords, tighten sign-in rules and warn affected people. Takedown requests, where they make sense, are a separate engagement.
Will scanning disrupt our systems?
Rarely. We scan in agreed windows, exclude fragile systems such as some medical or industrial devices, and start gently. Your signed scope lists what is in and out.
Do you fix the vulnerabilities you find?
Our vulnerability management service finds, ranks, tracks and verifies. Fixes are done by your IT team or by our managed IT team under a separate scope, and the tracker shows who owns each item.
What should we do if our passwords show up in a breach?
Reset the affected passwords, confirm multifactor authentication is on, and review recent sign-ins for those accounts. If you see sign-ins you cannot explain, treat it as an incident and use our urgent intake form.
Related guides
- Penetration testing vs vulnerability scanning
- Dark web monitoring for businesses: buyer’s guide
- What dark web monitoring finds for businesses
- Actively exploited Windows vulnerabilities and the KEV catalog
- Credential stuffing investigation for small businesses
- Penetration testing service
- Identity and access security service
- Threat mitigation and SOC monitoring
We scan and monitor only systems, domains and identities you own or are authorized to cover, under a signed scope. Dark web monitoring is observation only.
Sources: CISA KEV catalog, CISA BOD 26-04, NIST SP 800-40 Rev. 4, CIS Control 7, NIST CSF 2.0.
Know what to fix first
Request this service online with your rough asset counts and domains, and our cyber lead will scope it. Picking the service on the form routes it straight to the right specialist, so there is no phone tag. If you see signs of an active intrusion, use our urgent intake form instead.