Key takeaways
- Modern organisations depend on third-party software and integrations, so the attack surface extends well past the systems they own and manage directly.
- The CAF Bank disruption in July 2026 followed a previously unknown vulnerability in third-party software connected to its online banking portal.
- Vulnerability Management as a Service gives organisations a continuous view of weaknesses across devices and servers, with the most urgent issues prioritised.
- Unusual account activity is often the first practical sign of a problem, which is why detection belongs alongside prevention rather than after it.
- ramsac includes both vulnerability management and 24/7 monitoring in totalIT secure and totalIT premium, because neither layer covers the other’s gaps.
Most conversations about cybersecurity start with the systems an organisation owns. The laptops, the servers, the Microsoft 365 tenant, the line of business application everyone logs into on a Monday morning. That is a sensible place to start. It is no longer the whole picture.
Very few organisations now run on software they control end to end. Payroll connects to the bank. The CRM connects to the website. A portal built by one supplier talks to a platform run by another. Each of those connections is useful. Each one also widens the ground an organisation needs to keep an eye on.
A disruption at CAF Bank this summer showed what that can look like in practice.
What happened at CAF Bank
CAF Bank provides banking services to more than 14,000 charities and non-profit organisations across the UK. In July 2026 it detected suspicious and attempted fraudulent activity affecting a small number of customer accounts, and suspended access to its online banking service on 24 July while it investigated.
The investigation identified a previously unknown vulnerability in the way third-party software connected to its online banking portal. The bank was clear that its core banking system was not affected and that customer funds remained secure. Online services were restored in early August, after around ten days.
The disruption was still significant for the organisations that rely on those services. Charities reported difficulty paying staff and suppliers on time, and long waits to complete time-sensitive payments by phone.
Two things are worth drawing out of that, and neither is a criticism of how CAF Bank handled it. A vulnerability described as previously unknown is, by definition, one that nobody had published a patch for. What the incident illustrates is more useful than blame: how far a modern attack surface extends, and how organisations find out that something is wrong.

Your attack surface is bigger than the systems you manage
The first lesson is about scope. When an organisation reviews its security, it usually reviews what it can see on its own network. The software estate that matters is larger than that. It also changes constantly.
The National Vulnerability Database logs over 100 new software vulnerabilities every day. Some affect software you have never installed. Some affect an application sitting on a single forgotten laptop. Some affect a platform your finance team logs into every week that you have never thought of as your responsibility, because a supplier runs it.
Knowing that a vulnerability exists is the easy part. The harder questions are whether it affects you, where the vulnerable software is installed, and how urgently you need to act. As we wrote when a set of Zoom flaws was disclosed in August, patching alone is not enough if nobody has a reliable view of what is installed and what state it is in.
This is why vulnerability management has moved from a periodic exercise to an ongoing one. An annual assessment tells you where you stood on the day of the test. It says very little about the ten months that follow.
What Vulnerability Management as a Service involves
Vulnerability Management as a Service, usually shortened to VMaaS, is a managed way of keeping that view current. Rather than relying on users noticing update prompts, or an IT manager working through vendor announcements by hand, the work runs continuously in the background.
In practice it does four things:
- It scans workstations and servers on an ongoing basis, so you have a current picture of where weaknesses sit across the estate rather than a snapshot from last year.
- It prioritises what it finds, which matters because a long list of vulnerabilities with no sense of severity is difficult for any team to act on sensibly.
- It patches supported third-party software automatically, closing known weaknesses without waiting for someone to notice them.
- It reports monthly on what has been found, what has been fixed, and what still needs a decision, so the picture stays visible to the people accountable for it.
ramsac’s VMaaS starts with an initial assessment across your devices, followed by a few weeks of baselining work to bring old software up to date and remove what is no longer needed. After that it settles into continuous management. The service also supports Cyber Essentials and Cyber Essentials Plus requirements, which many charities and professional services firms need to hold anyway.
There is a limit worth stating plainly. Vulnerability management works on weaknesses that are already known. It shortens the window between a vulnerability becoming public and the same weakness being closed in your environment. A great deal of real-world exploitation happens inside that window. What it cannot do is close a flaw nobody has discovered yet, which is why it forms one layer rather than the whole answer.

Unusual activity is a signal worth watching
The second lesson from the CAF incident sits on the other side of that limit. The issue came to attention because activity on a small number of accounts did not look right.
That pattern is familiar. In our experience, the most common breaches our clients see come from human error and compromised accounts, and the first indication is often external and late. A customer mentions phishing emails arriving from a familiar address. A supplier says an invoice everyone believed had been paid never arrived. By that point the organisation is responding to consequences rather than to the event.
Cybersecurity monitoring exists to move that moment earlier. ramsac’s secure+ service runs 24/7 from our Security Operations Centre, watching for the signals that tend to precede real damage: account compromise, credential theft, mailbox rules forwarding messages elsewhere, token theft, ransomware behaviour and suspicious processes on a device. Alerts are investigated by our security team rather than passed to a client’s IT lead to interpret.
Preventative controls reduce how often something gets through. Monitoring shortens how long it goes unnoticed once it does. An organisation needs both, because the second question a board asks after an incident is almost always how long it had been happening.
Security that works in layers
Neither of these services is a complete answer on its own. We would be cautious of anyone presenting one as such. We could not say that VMaaS or secure+ would have prevented what happened at CAF Bank, because the vulnerability was described as previously unknown and no patching service closes a flaw that has not been found.
What layered security does is change your position when something goes wrong:
- Fewer known weaknesses are available to be exploited, because they are found and closed on a continuous cycle.
- Suspicious behaviour is spotted by someone whose job is to watch for it, rather than by a customer or supplier weeks later.
- When an incident does occur, there are logs, alerts and a rehearsed response, so the investigation starts from evidence rather than from guesswork.
Both VMaaS and secure+ are included in our totalIT secure and totalIT premium services, alongside the rest of our managed cybersecurity work. They sit together deliberately, because the gap each one leaves is the gap the other covers.
The question to ask this Cybersecurity Awareness Month
Cybersecurity is not only about patching the systems you already know about. It is about having visibility of vulnerabilities across your whole environment, an understanding of the third-party software and suppliers your organisation depends on, and monitoring capable of spotting unusual activity when it happens.
A useful exercise for October is to ask three questions of your own organisation. Which third-party applications and integrations touch our data or our payments? Who would notice if one of them started behaving unusually, and how quickly? And when did we last see a full list of the vulnerabilities present across our devices?
If those questions are difficult to answer, that is the finding, and it is a common one. We are happy to talk it through. A cybersecurity audit is a straightforward first step, and gives you a clear view of where your weaknesses sit before you decide what to do about them.
Understand your cybersecurity posture
Download our cybersecurity brochure to see how ramsac supports your organisation across the six core elements of cyber resilience: Govern, Identify, Protect, Detect, Respond and Recover. Discover how our services work together to reduce risk, strengthen security and help your business stay resilient.
FAQs: Vulnerability Management
Vulnerability management is the ongoing process of identifying weaknesses in the software across your devices and servers, judging how serious each one is, and fixing the ones that matter most. It runs continuously rather than as a one-off test.
VMaaS stands for Vulnerability Management as a Service. It is a managed service where a provider runs the scanning, prioritisation, patching and reporting on your behalf, instead of your own team doing it manually.
A penetration test is a point-in-time exercise where specialists attempt to break into your environment. Vulnerability management runs continuously in the background and keeps a current view of known weaknesses across your estate. Most organisations benefit from both.
No. It reduces the number of known weaknesses available to an attacker and shortens the time a published vulnerability stays open in your environment. It cannot close a vulnerability nobody has discovered yet, which is why monitoring and detection sit alongside it.
Because your data and your payments often pass through software your suppliers run. A weakness in a supplier’s system can disrupt your organisation even when your own systems are working correctly, as the charities affected by the CAF Bank outage found.








