PurpleScan

Vulnerability Management Driven by our SOC.

Cut your exposure window from over 30 days to under 8. PurpleScan combines automated scanning, expert SOC-led prioritization, and continuous follow-through – turning remediation into a controlled process instead of a race against the clock.

Certification ISO 27001

ISO 27001-certified SOC · ISAE 3000 assurance report · Operated from Switzerland · FINMA / FADP / NIS2 compliant.

Certification ISAE 3000

Why Vulnerability Management Fails in Most Organizations ?

Vulnerability management is the starting point of any cybersecurity strategy – required by standards (ISO 27001, PCI-DSS, FINMA) and expected by regulators and insurers alike. Yet the process remains extremely time-consuming and relies on scarce technical skills: discovering weaknesses, analyzing them, prioritizing, and finally patching.

For an organization handling this alone, an average of over 30 days goes by between discovering a vulnerability and applying a fix – an exposure window wide enough for an attacker to fully compromise your infrastructure. Some major vulnerabilities have even been exploited the day after disclosure.

PurpleScan was built to close exactly this gap.

PurpleScan — A Purple Team Approach to Vulnerability Management

PurpleScan is a managed Vulnerability Management as a Service (VMaaS) offering, operated by the analysts of our AT-Defense SOC. It combines two complementary dimensions:

  • A “Red” dimension: continuous detection that mirrors an attacker’s mindset, spotting weaknesses before they can be exploited.
  • A “Blue” dimension: analysis, prioritization, and guidance from our certified SOC analysts.

This crossover – the source of the name Purple Scan – transforms vulnerability management from a purely technical task into a governed, measurable, audit-ready process.

Full Coverage, from Discovery to Verification

PurpleScan covers every stage of the vulnerability lifecycle:

  1. Discovery of exposed assets
  2. Prioritization based on business criticality
  3. Analysis and real-world risk assessment
  4. Reporting, clear and actionable for your teams
  5. Remediation – patch and mitigation recommendations
  6. Verification that the fix was effective.

 

What PurpleScan Changes for You

Without PurpleScan With PurpleScan
Average exploitation window: 30+ days Exploitation window reduced to under 8 days
Manual prioritization, often delayed SOC-led prioritization within 24 hours
Static report, delivered at the end of the cycle Alerts as soon as a new vulnerability appears
Significant internal workload Analysis and review handled by our experts
Multiple, unconsolidated tools A single, centralized view of your exposure

 

  • Significantly reduces internal costs of vulnerability handling
  • Unifies your different security solutions into one coherent view
  • Raises your actual security posture – not just paper compliance
  • Supports a continuous improvement approach
  • Stays fully controllable and measurable by your teams: reports, indicators, exclusions.

PurpleScan Service Scope

Continuous Detection

  • Comprehensive initial assessment of your environment, with expert-led prioritization
  • Regular automated scans, with a summary report
  • Ongoing detection of new vulnerabilities as soon as they appear
  • Immediate analysis of any new critical vulnerability, with a report delivered in under 2 hours.

SOC-Led Prioritization

Our analysts assess each vulnerability based on its real-world risk – external or internal exposure, severity, likelihood of exploitation – so you know exactly what needs fixing first and what can be scheduled.

Expert Validation and Advisory

  • Real-risk validation by our experts, beyond a simple technical score
  • Expert judgment that saves your teams from chasing non-priority risks
  • Practical mitigation advice, tailored to your context
  • Systematic quality control before any report reaches you.

A Dedicated Portal to Manage Your Exposure

  • Access to a secure portal (two-factor authentication)
  • Real-time visibility into classification and prioritization
  • Filtering and exclusion options tailored to your needs
  • Automatic status updates once vulnerabilities are patched
  • Comments, task assignment, bulk actions
  • A view directly linked to your assets
  • Full traceability of all operations
  • Key performance indicators (response time, risk trends)
  • Data export ready for your auditors (FINMA, ISO 27001, etc.)

Simple to deploy, continuous by design.

Getting Started

Every deployment begins with a scoping phase with our experts: defining what needs to be covered, setting up the technical environment, then running an initial comprehensive scan that gives you an immediate picture of your exposure.

Day-to-Day Operation

Once live, PurpleScan runs continuously: scheduled detection, analysis by our SOC, then remediation guidance – with immediate notification whenever a critical risk is identified.

 

Our Commitments

  • A report delivered in under 2 hours whenever a new critical vulnerability is detected
  • Regular scans, with frequency adapted to changes in your environment
  • Automatic alerts whenever a risk threshold is exceeded
  • Continuous handling of changes to your scope.

Key Takeaways :

  • Purple Team approach: attacker-style detection, defender-style analysis
  • Continuous service, with no monitoring gaps
  • Works with your existing environment, regardless of its complexity
  • Certified Offensive & Defensive security analysts (OSCP, OSCE, CRTO, CRTP, GCPL, GWAPT, GCIH, GCFA, GREM)
  • Optimal responsiveness through real-time alerts
  • Reduced internal technical burden through outsourced analysis
  • Dedicated, secure infrastructure, unless you already operate a SOC
  • Customizable reporting, with key indicators delivered regularly
  • A reliable partner for your audits – FINMA, ISO 27001, and other compliance requirements
  • Scalable to other advanced defense services (EDR and more).

A Service That Adapts to Your Needs (quote-based)

  • Custom scope: target specific vulnerabilities or assets
  • Tailored dashboards, adapted to your business needs

Pricing and Quotes

PurpleScan is offered as a monthly subscription, sized according to the scope of your environment and the level of service required. Since every context is different, a quote is prepared following a scoping discussion with our experts.

e-Xpert Solutions SA  – Geneva

Chemin du Pont-du-Centenaire 109
CH-1228 Plan-les-Ouates / Geneva

+41 22 727 05 55
Support: +41 22 727 05 56
Under Attack: +41 22 727 05 45

e-Xpert Solutions SA  – LAUSANNE

Avenue de Gratta-Paille 20
CH-1018 / Lausanne

+41 21 802 26 78
Support: +41 22 727 05 56
Under Attack: +41 22 727 05 45

en_GB