Altitude IT Case Study

Cyber Security & Compliance

Cyber Essentials Plus Remediation: When “Fully Updated” Isn't Fully Updated

A UK professional-services organisation was approaching its Cyber Essentials Plus renewal when vulnerability testing continued to find problems on Windows PCs that appeared fully patched.

We investigated what the scanner was actually detecting, found the underlying causes and helped remediate the environment through to a successful assessment.

Cyber Essentials Plus passed.

Talk to an Expert

The organisation was being maintained using established IT management, patching and security tools. Windows Update reported machines as current, automated patching had completed and newer software versions were installed. Independent vulnerability testing still found vulnerabilities on several endpoints.

The Challenge

Several apparently unrelated findings continued to appear during a time-sensitive renewal. Repeatedly pushing updates or rebuilding affected computers would have consumed time without necessarily addressing what the scanner was detecting.

Don't just ask whether the update installed. Find out exactly what the vulnerability scanner can still see.

What We Found

Several apparently unrelated findings were actually caused by a small number of underlying problems.

  • Old .NET runtimes remained after updates. A patched .NET 8.0.30 runtime was installed alongside older 8.0.21 components. The actual runtime inventory was checked, obsolete components were removed through the installed-software mechanism and the vulnerable paths were verified as absent.
  • Windows Update looked current, but an application blocked the feature upgrade. An older application compatibility issue prevented a Windows 11 feature upgrade. Removing the incompatible component allowed the repair and upgrade to complete, and the resulting operating-system version was checked directly.
  • A graphics driver looked current, but the scanner disagreed. The actual installed component was investigated, the appropriate security update was manually identified and installed, and the findings cleared after restart.
  • A removed HEVC package still appeared in results. Windows package inventories were checked directly to confirm that no installed or provisioned package remained. The result disappeared after reassessment.
  • Asset inventory mattered too. A device no longer in operational use was legitimately removed from the active inventory and scope. Operational devices were still properly remediated.

Scanner severity and Cyber Essentials significance are not necessarily the same thing. One graphics-driver finding appeared as Severity 3 in the scanning platform, but the underlying CVSS score and vulnerability criteria still mattered to the assessment. It required remediation before the assessment could be completed cleanly.

Why “Fully Patched” Doesn't Always Mean Secure

Patch-management systems primarily tell you what updates were deployed or attempted. Vendor update tools tell you what they believe is current. Windows Update tells you the Windows update state. A vulnerability scanner examines what is actually present on the endpoint. Those answers can differ.

Patch management tells you what you tried to install. Vulnerability assessment tells you what is actually there.

Targeted Remediation and Verification

Each affected endpoint was investigated individually. We identified the exact component behind the finding, removed obsolete software where appropriate, completed the required update or repair and verified the result locally before reassessment.

  1. Vulnerability detected.
  2. Exact affected component identified.
  3. Why the normal update failed investigated.
  4. Targeted remediation completed.
  5. Local technical evidence verified.
  6. Independent reassessment completed.

This included checking runtime and Windows inventories, validating affected file paths, confirming installed and provisioned packages, verifying the operating-system version and checking the active asset population.

The Result: Cyber Essentials Plus Passed

Following investigation, remediation and vulnerability reassessment, the organisation successfully passed its Cyber Essentials Plus assessment.

  • Outstanding vulnerabilities on active endpoints were resolved.
  • Obsolete .NET components that automated patching had left behind were removed.
  • An application compatibility issue blocking a Windows feature upgrade was identified.
  • The affected Windows endpoint was brought successfully onto Windows 11 25H2.
  • Graphics-driver vulnerabilities that normal update mechanisms had not cleared were remediated.
  • The HEVC component was verified as removed without unnecessarily rebuilding the workstation.
  • The active asset inventory was corrected and direct technical evidence was produced.
  • Unnecessary PC rebuilds were avoided.

Altitude IT assisted with investigation and technical remediation. The client independently completed and passed its Cyber Essentials Plus assessment; Altitude IT did not issue the certification.

What This Means for Your Business

Automated patching is essential, but difficult vulnerability findings sometimes need hands-on investigation to understand why a patch or upgrade has not produced the expected result.

Altitude IT can provide Cyber Essentials preparation, Cyber Essentials Plus remediation, vulnerability-scan interpretation, Windows endpoint troubleshooting, remediation evidence and independent technical second opinions.

Related Services

Related Case Studies