The 90-Day Model: From 109,905 Vulnerabilities to a Remediated Estate
Hardening a large organisation feels overwhelming from day one. That’s why we use a focused 90-day model.
The 90-Day Timeline
- Weeks 1–2: Full discovery across 2,530 endpoints. Baseline established.
- Weeks 3–5: Rapid sprint. From 109,905 to 30,301 — a 72% reduction. 75,653 remediated.
- Weeks 6–10: Targeted patching of 512 production servers across 16 server groups. Legacy systems isolated with compensating controls. All CAB-approved.
- Weeks 11–12: Validation, handover, and operationalising the four pillars.
“Result: Zero security incidents across four months. The 90-day model works because each week the environment is measurably safer.”
You don’t need a 12-month roadmap. You need 90 days and discipline. This model has now worked for multiple public-sector engagements — the structure is repeatable, the results are measurable.
Part of the Secure & Patched series. View the full campaign.