Cybersecurity operations

Turn vulnerability findings into a controlled remediation process.

A connected Microsoft Excel system for IT and security teams that need to prioritise findings, link them to affected assets and retain clear ownership, targets, evidence and closure history.

Core structureConnected vulnerability, asset and remediation registers
Designed capacity200 vulnerabilities · 150 assets · 500 exposures
Threat contextOptional CISA KEV + FIRST EPSS enrichment
DeliveryBlank workbook, demo, guide and supporting import/query files
Overview

A complete look at what you are buying

Turn scattered scanner findings and manual discoveries into a structured vulnerability-management workflow that separates technical vulnerability data, asset context and asset-specific remediation activity.

Product detail

What the system includes

  • Management dashboard with automatically calculated KPIs, ageing, priority and remediation-health views.
  • Prioritised Action Queue for active remediation work requiring attention.
  • Two-way Explorer: select a vulnerability to see affected assets, or an asset to see linked vulnerabilities.
  • Vulnerability Catalogue for CVEs, severity, exploit evidence, affected technology, remediation guidance and source references.
  • Asset Register for business service, site, ownership, criticality, internet exposure and support context.
  • Affected Assets register preserving a separate owner, status, target, treatment, change record, evidence and closure for each vulnerability-to-asset relationship.
  • Bulk Link Builder for creating multiple exposure relationships efficiently.
  • Controlled Scanner Import staging area before operational records are created.
  • Risk Acceptance register with accountable ownership, compensating controls, approval evidence and review/expiry dates.
  • Change, CAB, maintenance-window, reboot and remediation-plan tracking.
  • Closure evidence, verification dates and technical verifier fields.
  • Configurable scoring, priority thresholds, SLA targets, duplicate warnings and data-quality signals.
Product detail

Controlled scanner import

  • Scanner findings land in a staging area rather than silently overwriting live registers.
  • Use the supplied CSV structure to map scanner exports into a predictable format.
  • Review asset matching, existing catalogue records, duplicate links and missing information before transferring data.
  • The design is scanner-agnostic: you retain the external/plugin reference needed for traceability without locking the workbook to one vendor.
Product detail

Optional live threat intelligence

  • CISA Known Exploited Vulnerabilities can be used as a known-exploitation signal.
  • FIRST EPSS probability and percentile data can be used as additional prioritisation context.
  • Ready-to-paste Power Query resources are supplied, with a manual-paste route for organisations where external refreshes are restricted.
  • Threat intelligence is decision support, not an automatic risk decision: source data and business context still require review.
Included files

What you receive

  • Blank operational Microsoft Excel workbook (.xlsx)
  • Fully worked fictional demonstration workbook (.xlsx)
  • 15-page Customer User Guide (.pdf)
  • Scanner Import CSV template
  • CISA KEV Power Query resource
  • FIRST EPSS Power Query resource
Who it is for

Designed for practical IT teams

IT managersSecurity analystsVulnerability management teamsSystem ownersMSPsConsultantsSmall and growing organisations
Compatibility

Before you buy

Excel & file requirements

  • Core registers, formulas, validations and dashboards are intended for supported desktop Microsoft Excel.
  • Microsoft Excel 365 is recommended; the Explorer uses modern dynamic-array behaviour (Excel 365 / Excel 2021+).
  • Core workbook format is macro-free .xlsx — no VBA or embedded credentials.
  • Optional Power Query refresh availability depends on Excel edition, platform, network/proxy and organisational policy.
  • Google Sheets, Apple Numbers and unsupported older spreadsheet applications are not guaranteed to preserve formulas, validation, formatting or refresh behaviour.

Important limitations

  • The workbook does not scan networks, discover vulnerabilities, deploy patches or verify technical remediation automatically.
  • Scanner results and public threat intelligence can be incomplete or change over time and must be validated.
  • Priority scoring is an operational aid; the purchaser remains responsible for business-risk judgement, approvals, evidence and applicable legal/regulatory duties.
Delivery, licence & support

Clear terms before you purchase

Direct delivery

After verified payment, the purchase is linked to the customer account using the checkout email. Secure download links are generated on demand.

Licence

For the purchaser's own use or internal operations of the purchasing organisation. Reusable source templates must not be resold or redistributed.

Digital content

Direct checkout includes the required immediate-supply acknowledgement. Statutory rights for faulty or non-conforming digital content are unaffected.

Support

Product and access help is available at support@practicalitpacks.com.

Ready to put it to work?

Add it to your Practical IT Packs cart for secure direct checkout, or use Etsy if you prefer the marketplace route.