For agencies
The 30-minute monthly playbook for an agency's client portfolio.
Published 2026-05-25 · Approx. 12-minute read · Designed for portfolios of 5-50 sites
An agency owner running ten retainer clients doesn't have a SOC analyst on staff. They have themselves, and maybe a junior who does the WordPress updates on Tuesday afternoons. Four of the sites run WordPress with whatever plugin stack the original brief asked for. Two are on Shopify. One is a custom Node app the previous developer wrote. Three are static sites someone moved off Squarespace last year.
Nobody has scanned any of them since launch.
Hiring a security person would be overkill for that agency. What it needs is 30 minutes a month, spent in the same order every time, catching configuration drift before it turns into an incident. Here's the routine.
You can run it in Vantyris, with every client domain in one workspace, weekly monitoring and the portfolio dashboard. Or use free tools: SSL Labs, Security Headers and a manual SPF and DMARC check per domain. Vantyris is quicker because it's one tab instead of four. The free tools save you the credit cost. Pick whichever fits your retainer maths.
Before the first month: the one-time setup
Put every client domain in one workspace and verify it
Open a Vantyris workspace and add each client domain as a target. Each one verifies with a DNS TXT record. If you can't get at the client's DNS, upload a verification file to their web server or add a meta tag to the homepage instead. Verification is the legal footing for everything after it, because it records that you have permission to scan. Keep each client's written authorisation in your CRM as well.
Allow 5 to 15 minutes per target, less if you have direct DNS access. Get all ten done on day one of the setup month and the gate is out of the way.
Run the baseline scan on every target
Once a target verifies, run a verified scan on it. That costs one credit per target. The starter pack is $10€10£10A$15¥1,500AED 40 for five credits, and $100€100£100A$150¥15,000AED 400 buys a hundred. The first scan is your baseline. Read the report and decide which findings are real. Anything you already knew about and chose to live with goes to “Accepted risk” with a written reason. A client on a legacy subdomain that can't take HSTS is one example. Acceptances expire after 90 days, so nothing stays hidden forever.
File the full PDF in each client's project folder. It's the “before” picture for every retainer review that follows.
Enrol every verified target in weekly monitoring
Each monitoring scan costs one credit, so 10 retainer clients on a weekly cadence use about 43 credits a month. Set the cadence to weekly. Send the alerts to the agency owner, or to a shared mailbox like security@youragency.com that somebody actually reads.
Monitoring emails you about three things only: a new high or critical finding, a score drop of 10 points or more against the previous scan, or a TLS certificate within 14 days of expiry. Nothing else, so the inbox stays quiet.
Decide how each client sees the evidence
The simplest proof for a client is a share link to their latest report. It's read-only, nobody needs an account to open it, and it expires after the period you set, up to 90 days. The public trust page works differently. There's one per workspace and it lists every domain in it, so think twice before switching it on in a workspace full of clients.
The 30-minute monthly process
Block out the first Monday of every month, 9:00 to 9:30. Get a coffee and open the dashboard.
Minutes 0-5: open the portfolio dashboard
The portfolio dashboard at /app/portfolio ranks every target worst first. Start with the numbers at the top: how many targets, the average score, and the total count of critical and high findings. If the average moved more than 5 points since last month, something changed across the portfolio and you want to know what.
Then read down the list. Targets with critical or high findings sit at the top. Anything marked “stale” hasn't been scanned in over 30 days and needs a look.
Minutes 5-10: read this month's monitoring alerts
Open the mailbox the alerts go to. Every alert is one of the three types above. Here's what to do with each.
- New high or critical finding. Open the target's latest scan and read the finding. Then decide who fixes it, you or the client's IT contractor. If it's the contractor, assign it with a due date and paste the fix guidance in as a comment.
- Score drop. Something regressed. Compare with the previous scan to find the new finding, then work out the cause. It's either something on the client's side, like a plugin update or a DNS change, or something outside it, like a newly listed KEV entry or a certificate authority losing browser trust. Fix it or accept it.
- Certificate expiring. Ask the client's web host to confirm auto-renewal is working. If it isn't, act today. An expired certificate is about the most avoidable outage a client can have.
Minutes 10-20: triage anything still on the worst-first list
Some clients won't have raised an alert this month and will still have unresolved findings from earlier months. Open the top three sites on the worst-first list and work through each one.
- Sort the findings by priority. That score starts from severity, then adds points for a KEV listing and for findings that are still open from last time or got worse. Anything above 80 is urgent.
- For each urgent finding, check its workflow status. If it's been “Assigned” for three weeks or more with no new comments, chase the assignee. If it's still “Open” and nothing has happened, either escalate it or mark it “Accepted risk” with a reason.
- For each open finding you decide to act on, add a comment naming the next step and who owns it.
Minutes 20-25: hand off to your team
Send a one-line message about each assigned finding to whoever is responsible, in Slack, Asana or wherever your team already talks. Attach the single-issue work-order PDF for that finding, so they get the details without needing a Vantyris login.
Minutes 25-30: client communication
For each retainer client, decide whether anything this month is worth telling them about. Usually it's one of these.
- Nothing to report. Skip the email. If the client ever asks for proof, send a share link to the latest report.
- You fixed things yourselves. Send a short note, something like “We fixed two medium findings this month. Summary attached.” Attach the report PDF, which opens with a one-page summary the client can read on its own. It takes about three minutes per client.
- The client has to act. This is the rare month when the client needs to do something, such as renew a certificate they manage or approve a hosting change. Email them directly with the single-issue work-order PDF attached, so they can forward it to their host as it is.
Quarterly: the retainer review
Every three months, download the full-history CSV from the portfolio page and open it in a spreadsheet. Four questions are worth asking of it.
- Is the workspace average score going up or down over the quarter?
- Which clients are improving, and which are slipping?
- For findings marked “Fixed” this quarter, how long did each one sit “Open” first?
- What share of findings ended up as “Accepted risk”? If that share keeps climbing, either you're accepting too easily or more of your clients are on legacy stacks.
Take the numbers into your retainer reviews. “Your site went from a B to an A this quarter” is a line a client understands, and it fits on one slide.
Once a year: insurance and Cyber Essentials
Once a year, each retainer client renews their PI or business insurance, and the form may ask about external vulnerability scanning. Send the client a share link to their latest verified report, set to stay live for as long as the underwriter needs it, up to 90 days. What the insurer does with it is up to the insurer. Your client at least has a dated answer instead of a blank.
If a client is going for Cyber Essentials this year, every verified Vantyris report already includes a CE alignment section that maps each finding to the five NCSC control areas. Treat it as the starting checklist for their submission. The certificate itself still has to come from a certification body. You can subcontract that, or point the client to IASME.
If you want to run this without Vantyris
You can. The routine matters more than the tool. Here's the free version.
- SSL Labs (
ssllabs.com/ssltest) for TLS, one test per client. - Security Headers (
securityheaders.com) for HTTP response headers, again one URL at a time. - MX Toolbox (
mxtoolbox.com) for the SPF, DKIM and DMARC lookups. - UptimeRobot for certificate expiry alerts. The free tier covers 50 monitors.
- A spreadsheet to track findings across clients over time.
Expect roughly 90 to 120 minutes a month for ten clients instead of 30. The finding history lives in your spreadsheet, and a client can't check a spreadsheet the way they can open a share link. On cost, put your own hourly rate against that extra hour or so each month and you'll know which side of the line you're on.
Try the portfolio dashboard with your own client list.
Open a workspace, verify one or two client domains and run a verified scan. You'll see the report and the portfolio view with real client data in them. The starter pack is $10€10£10A$15¥1,500AED 40 for five credits.
Vantyris editorial team · methodology v1.0.0