Skip to main content

For agencies

The 30-minute monthly playbook for an agency's client portfolio.

Published 2026-05-25 · Approx. 12-minute read · Designed for portfolios of 5-50 sites

An agency owner running ten retainer clients doesn't have a SOC analyst on staff. They have themselves, and maybe a junior who does the WordPress updates on Tuesday afternoons. Four of the sites run WordPress with whatever plugin stack the original brief asked for. Two are on Shopify. One is a custom Node app the previous developer wrote. Three are static sites someone moved off Squarespace last year.

Nobody has scanned any of them since launch.

Hiring a security person would be overkill for that agency. What it needs is 30 minutes a month, spent in the same order every time, catching configuration drift before it turns into an incident. Here's the routine.

You can run it in Vantyris, with every client domain in one workspace, weekly monitoring and the portfolio dashboard. Or use free tools: SSL Labs, Security Headers and a manual SPF and DMARC check per domain. Vantyris is quicker because it's one tab instead of four. The free tools save you the credit cost. Pick whichever fits your retainer maths.

Before the first month: the one-time setup

Put every client domain in one workspace and verify it

Open a Vantyris workspace and add each client domain as a target. Each one verifies with a DNS TXT record. If you can't get at the client's DNS, upload a verification file to their web server or add a meta tag to the homepage instead. Verification is the legal footing for everything after it, because it records that you have permission to scan. Keep each client's written authorisation in your CRM as well.

Allow 5 to 15 minutes per target, less if you have direct DNS access. Get all ten done on day one of the setup month and the gate is out of the way.

Run the baseline scan on every target

Once a target verifies, run a verified scan on it. That costs one credit per target. The starter pack is $10€10£10A$15¥1,500AED 40 for five credits, and $100€100£100A$150¥15,000AED 400 buys a hundred. The first scan is your baseline. Read the report and decide which findings are real. Anything you already knew about and chose to live with goes to “Accepted risk” with a written reason. A client on a legacy subdomain that can't take HSTS is one example. Acceptances expire after 90 days, so nothing stays hidden forever.

File the full PDF in each client's project folder. It's the “before” picture for every retainer review that follows.

Enrol every verified target in weekly monitoring

Each monitoring scan costs one credit, so 10 retainer clients on a weekly cadence use about 43 credits a month. Set the cadence to weekly. Send the alerts to the agency owner, or to a shared mailbox like security@youragency.com that somebody actually reads.

Monitoring emails you about three things only: a new high or critical finding, a score drop of 10 points or more against the previous scan, or a TLS certificate within 14 days of expiry. Nothing else, so the inbox stays quiet.

Decide how each client sees the evidence

The simplest proof for a client is a share link to their latest report. It's read-only, nobody needs an account to open it, and it expires after the period you set, up to 90 days. The public trust page works differently. There's one per workspace and it lists every domain in it, so think twice before switching it on in a workspace full of clients.

The 30-minute monthly process

Block out the first Monday of every month, 9:00 to 9:30. Get a coffee and open the dashboard.

Minutes 0-5: open the portfolio dashboard

The portfolio dashboard at /app/portfolio ranks every target worst first. Start with the numbers at the top: how many targets, the average score, and the total count of critical and high findings. If the average moved more than 5 points since last month, something changed across the portfolio and you want to know what.

Then read down the list. Targets with critical or high findings sit at the top. Anything marked “stale” hasn't been scanned in over 30 days and needs a look.

Minutes 5-10: read this month's monitoring alerts

Open the mailbox the alerts go to. Every alert is one of the three types above. Here's what to do with each.

Minutes 10-20: triage anything still on the worst-first list

Some clients won't have raised an alert this month and will still have unresolved findings from earlier months. Open the top three sites on the worst-first list and work through each one.

Minutes 20-25: hand off to your team

Send a one-line message about each assigned finding to whoever is responsible, in Slack, Asana or wherever your team already talks. Attach the single-issue work-order PDF for that finding, so they get the details without needing a Vantyris login.

Minutes 25-30: client communication

For each retainer client, decide whether anything this month is worth telling them about. Usually it's one of these.

Quarterly: the retainer review

Every three months, download the full-history CSV from the portfolio page and open it in a spreadsheet. Four questions are worth asking of it.

Take the numbers into your retainer reviews. “Your site went from a B to an A this quarter” is a line a client understands, and it fits on one slide.

Once a year: insurance and Cyber Essentials

Once a year, each retainer client renews their PI or business insurance, and the form may ask about external vulnerability scanning. Send the client a share link to their latest verified report, set to stay live for as long as the underwriter needs it, up to 90 days. What the insurer does with it is up to the insurer. Your client at least has a dated answer instead of a blank.

If a client is going for Cyber Essentials this year, every verified Vantyris report already includes a CE alignment section that maps each finding to the five NCSC control areas. Treat it as the starting checklist for their submission. The certificate itself still has to come from a certification body. You can subcontract that, or point the client to IASME.

If you want to run this without Vantyris

You can. The routine matters more than the tool. Here's the free version.

Expect roughly 90 to 120 minutes a month for ten clients instead of 30. The finding history lives in your spreadsheet, and a client can't check a spreadsheet the way they can open a share link. On cost, put your own hourly rate against that extra hour or so each month and you'll know which side of the line you're on.

Try the portfolio dashboard with your own client list.

Open a workspace, verify one or two client domains and run a verified scan. You'll see the report and the portfolio view with real client data in them. The starter pack is $10€10£10A$15¥1,500AED 40 for five credits.

Editorial

Vantyris editorial team · methodology v1.0.0