Turn vulnerability findings into a controlled remediation process.
A connected Microsoft Excel system for IT and security teams that need to prioritise findings, link them to affected assets and retain clear ownership, targets, evidence and closure history.
A complete look at what you are buying
Turn scattered scanner findings and manual discoveries into a structured vulnerability-management workflow that separates technical vulnerability data, asset context and asset-specific remediation activity.
What the system includes
- Management dashboard with automatically calculated KPIs, ageing, priority and remediation-health views.
- Prioritised Action Queue for active remediation work requiring attention.
- Two-way Explorer: select a vulnerability to see affected assets, or an asset to see linked vulnerabilities.
- Vulnerability Catalogue for CVEs, severity, exploit evidence, affected technology, remediation guidance and source references.
- Asset Register for business service, site, ownership, criticality, internet exposure and support context.
- Affected Assets register preserving a separate owner, status, target, treatment, change record, evidence and closure for each vulnerability-to-asset relationship.
- Bulk Link Builder for creating multiple exposure relationships efficiently.
- Controlled Scanner Import staging area before operational records are created.
- Risk Acceptance register with accountable ownership, compensating controls, approval evidence and review/expiry dates.
- Change, CAB, maintenance-window, reboot and remediation-plan tracking.
- Closure evidence, verification dates and technical verifier fields.
- Configurable scoring, priority thresholds, SLA targets, duplicate warnings and data-quality signals.
Controlled scanner import
- Scanner findings land in a staging area rather than silently overwriting live registers.
- Use the supplied CSV structure to map scanner exports into a predictable format.
- Review asset matching, existing catalogue records, duplicate links and missing information before transferring data.
- The design is scanner-agnostic: you retain the external/plugin reference needed for traceability without locking the workbook to one vendor.
Optional live threat intelligence
- CISA Known Exploited Vulnerabilities can be used as a known-exploitation signal.
- FIRST EPSS probability and percentile data can be used as additional prioritisation context.
- Ready-to-paste Power Query resources are supplied, with a manual-paste route for organisations where external refreshes are restricted.
- Threat intelligence is decision support, not an automatic risk decision: source data and business context still require review.
What you receive
- Blank operational Microsoft Excel workbook (.xlsx)
- Fully worked fictional demonstration workbook (.xlsx)
- 15-page Customer User Guide (.pdf)
- Scanner Import CSV template
- CISA KEV Power Query resource
- FIRST EPSS Power Query resource
Designed for practical IT teams
Before you buy
Excel & file requirements
- Core registers, formulas, validations and dashboards are intended for supported desktop Microsoft Excel.
- Microsoft Excel 365 is recommended; the Explorer uses modern dynamic-array behaviour (Excel 365 / Excel 2021+).
- Core workbook format is macro-free .xlsx — no VBA or embedded credentials.
- Optional Power Query refresh availability depends on Excel edition, platform, network/proxy and organisational policy.
- Google Sheets, Apple Numbers and unsupported older spreadsheet applications are not guaranteed to preserve formulas, validation, formatting or refresh behaviour.
Important limitations
- The workbook does not scan networks, discover vulnerabilities, deploy patches or verify technical remediation automatically.
- Scanner results and public threat intelligence can be incomplete or change over time and must be validated.
- Priority scoring is an operational aid; the purchaser remains responsible for business-risk judgement, approvals, evidence and applicable legal/regulatory duties.
Clear terms before you purchase
After verified payment, the purchase is linked to the customer account using the checkout email. Secure download links are generated on demand.
For the purchaser's own use or internal operations of the purchasing organisation. Reusable source templates must not be resold or redistributed.
Direct checkout includes the required immediate-supply acknowledgement. Statutory rights for faulty or non-conforming digital content are unaffected.
Product and access help is available at support@practicalitpacks.com.
Ready to put it to work?
Add it to your Practical IT Packs cart for secure direct checkout, or use Etsy if you prefer the marketplace route.