Vulnerability Management: Frequently Asked Questions

Description

Overview

What is Vulnerability Management?

Vulnerability Management (VM) focuses on what makes the most impact on risk to business-critical assets. We deliver actionable risk insights by identifying exposures from exploitable vulnerabilities across your endpoints and prioritizing what should be addressed first to keep the attack surface shrinking. This offering combines vulnerability management with native patch management and asset management, so identification, remediation, and visibility all happen within a single platform.

 

Who is PDQ?

PDQ Connect is a cloud-based endpoint vulnerability and patch management platform that we have partnered with to deliver VM services. PDQ makes it easy to identify vulnerabilities across your Windows and macOS endpoints with no unnecessary complexity. The PDQ platform is MSP enabled, empowering partners to provide their clients with a proactive solution to manage and mitigate risk.

 

What are the benefits of using PDQ through SonicSentry?

This offering through SonicSentry provides partners the combined intelligence of the PDQ platform and the SonicSentry organization. SonicSentry provides the product and reporting at a reduced, consumption-based, month-to-month price point, and works closely with partners to help them focus their attention on what to remediate or patch and how to do so effectively. SonicSentry also provides highly praised support and training, enabling partners to become as self-reliant as needed while ensuring they always have a direct contact when an issue arises. Crucially, this offering closes the loop on the vulnerability management lifecycle, allowing your team to identify and remediate vulnerabilities in the same place. 

 

Features

Vulnerability Scanning

The agent scans enrolled Windows and macOS endpoints for known vulnerabilities, drawing from multiple sources including the MITRE CVE database, NIST NVD, CISA's Known Exploited Vulnerabilities (KEV) catalog, vendor release notes, and ongoing security research. Once the agent is installed on a machine, it begins reporting on discovered vulnerabilities and outdated software automatically. It is then validated whether a machine meets all conditions required for a vulnerability to actually be applicable, keeping findings accurate and actionable.

Each identified vulnerability is assigned a risk score based on its CVSS rating, potential business impact, and likelihood of exploitation. Vulnerabilities are ranked by this score, so the most critical issues in your environment are always surfaced first. If your team decides to accept the risk of a particular vulnerability rather than remediate it, it can be marked as ignored, for a single device or across the environment.

Scans run automatically on a recurring basis as devices check in, so newly discovered vulnerabilities and outdated software are typically surfaced within hours rather than days. Your team can also trigger an on-demand scan for an individual device or in bulk at any time.

Patch Management

Native patch management is what sets this offering apart. Once a vulnerability or outdated application is identified, your team can deploy the patch directly to the affected endpoint from within the platform, no separate patching tool required. This creates a true end-to-end workflow where identifying and fixing a problem happen in the same place.

This applies to:

  • Outdated third-party applications and software
  • OS-level vulnerabilities on supported platforms
  • Any software packages reachable by the installed agent

Asset Management

Beyond vulnerability and patch management, the platform provides visibility into the hardware and software assets across your environment. Enrolled endpoints automatically report device configuration and hardware details, along with a full inventory of installed software and versions.

This gives your team a centralized, up-to-date view of what is running across the environment, without needing a separate asset tracking tool. Devices can also be organized into dynamic groups based on inventory data, making it easier to manage and act on specific subsets of your environment.

This applies to:

  • Hardware and device configuration details
  • Installed software inventory and version tracking
  • Software compliance visibility across endpoints
  • Dynamic grouping of devices based on inventory data


Typical Workflow

Asset visibility runs continuously in the background, while the core vulnerability-to-patch workflow follows this sequence:

  1. Scan – The agent automatically scans enrolled endpoints and reports vulnerabilities and outdated software.
  2. Prioritize – Each finding is assigned a risk score, so the most critical issues surface first.
  3. Decide – Your team reviews each finding and chooses to remediate or accept the risk and ignore it.
  4. Patch – Deploy the needed update directly from the platform, using an existing package, a custom-built package, or automated updates for supported applications.
  5. Confirm – Review updated reporting to verify the vulnerability has been resolved.


Frequently Asked Questions

Will this patch the vulnerabilities for me?

The offering gives your team the ability to patch vulnerabilities directly from the platform, eliminating the need to pivot to an RMM or separate software deployment tool to find, download, and push an update. In most cases, the update needed to mitigate a vulnerability is already available within the platform, ready to deploy.

For the rare case where a patch is not readily available, the platform allows for quick and efficient custom package creation, so you can still push the needed update across multiple machines in the environment. Custom packages can be created directly by your team, and SonicSentry can also assist with package creation and maintenance as part of ongoing advisory support. 

The platform also supports patch and update automation for many commonly used applications (for example, Chrome, Edge, and Notepad++), so your team can ensure the latest patch is installed automatically once it becomes available.

Will SonicSentry patch vulnerabilities on our behalf?

No. This offering is currently co-managed, meaning the platform identifies vulnerabilities, but the responsibility for reviewing and applying patches falls to the partner. A fully managed offering, in which SonicSentry performs patching on the partner's behalf, is on our roadmap.

Is a Proof of Concept (PoC) available?

Yes. We offer a 14-day Proof of Concept so you can test all supported features of the platform firsthand. A PoC is not required to take advantage of this offering, but it is available if you would like to evaluate the platform before committing.

 

Starting a PoC

To begin a 14-Day Proof of Concept, contact your SonicSentry account representative to request a quote. Once the quote is signed, SonicSentry will provision access and your kickoff call will be scheduled. This offering PoC allows for up to 100 endpoints on Windows and macOS devices. 


PoC Timeline

Day 1 – Kickoff Call

  • Confirm login credentials and access to the platform
  • Walk through the portal and console
  • Install the agent on at least one machine
  • Review any vulnerabilities discovered on enrolled endpoints

Day 7 – Midpoint Check-in

  • Review agent deployment progress across enrolled endpoints
  • Address any installation or connectivity issues
  • Review vulnerabilities identified since kickoff
  • Answer questions on patch deployment and prioritization

Day 14 – PoC Converts to Live Offering

  • Reports available within the portal

 

Converting to Production/Live Offering

At the end of the 14-day evaluation period, the PoC automatically converts to the live offering, and SonicSentry handles billing and licensing automatically, with no action required from the partner to formally convert. Reports and findings from the PoC period carry forward, so no data is lost in the transition.

Once live, partners can continue onboarding new customer tenants on an ad hoc basis without needing to contact SonicSentry first. Customers can also be removed on an ad hoc basis as needed. A SonicSentry representative will follow up periodically to schedule check-ins and implementation reviews.

Canceling the PoC

If a partner decides not to move forward after the PoC, they must contact SonicSentry before the PoC ends, through the respective PoC ticket. SonicSentry will send a reminder one business day before the PoC is scheduled to auto-convert.

Agent uninstall can be pushed directly from the portal, by either the partner or SonicSentry. SonicSentry will be responsible for shutting down the instance once the PoC is canceled.

Is there multi-tenancy?

Yes. In the platform, a parent organization is initially created for the partner, which they can use to install their own internal devices if desired. The partner can then create additional tenants for each of their customers, with these tenants nested as separate instances under the partner's existing parent organization.

  • Parent organization: Established at setup for the partner. Can be used to manage the partner's own internal devices, and serves as the top-level structure under which customer tenants are nested.
  • Customer tenants: Created by the partner as needed, one per customer, each logically separated from the others. Partners access tenants through a single login, with the ability to select or switch between the parent organization and individual customer tenants.

Vulnerability review and patching are performed at the tenant level. There is currently no parent-level view or bulk action across tenants, so each customer tenant must be reviewed and remediated individually.

Is there 2FA/MFA for the portal?

Yes. The portal supports a range of authentication and MFA options to keep your account secure. For primary login, you can use passwordless email authentication or link a Google or Microsoft account. For MFA, the portal currently supports an Authenticator App, with the option to add a Passkey or SMS as additional methods. When Account MFA is required, the portal ensures at least one method always remains active, so you can never be locked out by disabling your last available option.

Is this agent based?

Yes. This offering uses an agent-based deployment, currently supported on Windows and macOS endpoints. The agent is what enables both vulnerability scanning and patch management, so keeping agents deployed and healthy across your endpoints is essential to getting the full value of the platform.

An additional, optional agent is also available for remote desktop functionality, allowing partners to remotely access and manage endpoints directly through the platform if desired.

Isn't this just an RMM tool?

No. This offering is not intended to replace your existing RMM tool; it is purpose-built around vulnerability management, patch management, and asset management, as outlined above. That said, the platform does include RMM-style features and functionality, and some partners have chosen to fully migrate from their existing RMM to this offering as a complete solution.

Does this offering integrate with the MXDR?

No. This offering is scoped to vulnerability identification and remediation, not threat detection. Findings are not currently ingested, analyzed, or alerted on by the SonicSentry Security Operations Center (SOC). Vulnerability data remains within the platform and is reviewed directly by your team. 

What are the responsibilities of the partner?

  • Managing the implementation process, including agent installation and device enrollment
  • Reviewing, approving, and acting on patch and software policies, including triage and accept/ignore decisions
  • Remediating vulnerabilities in accordance with reporting provided
  • Providing Tier 1 support and escalating Tier 2/3 issues to SonicSentry
  • Monitoring environment health, including auditing device connection times and identifying duplicate or stale entries, and removing inactive or unnecessary devices from the portal as needed. The platform does not currently provide automated device lifecycle management, so this review is a manual, ongoing partner responsibility.
  • Participating in quarterly security posture reviews

See the Service Plan for a full breakdown of responsibilities.

What are the deliverables from SonicSentry?

  • Cloud architecture provisioning and guided onboarding
  • Custom automation and software policy configuration tailored to your environment
  • Risk-based vulnerability triage and advisory, including custom package creation as new vulnerabilities emerge
  • Training, support, and documentation
  • Ongoing and quarterly reviews to guide what to patch and in what order

See the Service Plan for full deliverable details.

How do I contact support?

To contact SonicSentry support, visit the SonicSentry Support Portal. When asked to select a product, choose Vulnerability Management.

Support hours and targets:

  • Hours: Monday through Friday, 8:00am to 5:00pm EST (no after-hours or weekend support)
  • Target Analysis & Response Time: 4 hours
  • Target Resolution Time: 2 business days

How is this licensed?

  • Per installed agent.

How am I licensed and billed for this offering?

  • This offering is consumption-based and month to month.
  • Licenses are based on installed agents for that month.
  • Accounts are audited on the last business day of the month.
  • Changes to installed agents made during the month are reflected in the following audit.
  • An invoice is sent on the first business day of the month based on audited numbers.
  • Email mssaccounting@sonicwall.com for all billing questions or concerns.
 

Related Articles

  • MSS FW Best Practices: Security Services
    Read More
  • Cylance - Recommended Agent Versions
    Read More
  • MDR for Windows Defender Admin Functions
    Read More
not finding your answers?