Enterprise Endpoint Protection & Vulnerability Management

CyberNetwork Healthcare Logistics · Expadox Limited internship, cohort 3

Team project · 14-day sprint · 4 monitored endpoints, 3 office locations

The problem

CyberNetwork is a healthcare logistics company running Windows workstations, Linux servers, and a small number of macOS laptops across three offices. Going in, there was no trusted asset inventory, no vulnerability baseline, patches applied manually and inconsistently, and no endpoint detection in place. A competitor in the same sector had just been hit with ransomware through an unpatched machine with an exposed RDP port. The team had 14 days to build a full endpoint protection and vulnerability management program before a board meeting, with evidence at every stage rather than assurances.

Business case slide: the challenge and strategic objective for the CyberNetwork endpoint protection program
The business case presented to the board: the gaps going in, and the objective for the 14-day sprint.

My role

This was a team build. My specific contributions:

Endpoint security architecture diagram showing Wazuh, Action1, and Tailscale connecting CYB-SVR-L001, CYB-PC-L005, and the Windows workstations
The security architecture, showing the Tailscale mesh tying together endpoints across office locations, with CYB-SVR-L001 hosting the Wazuh manager.

Solution architecture

Five capabilities running on one integrated control plane, with clear tool ownership at each stage: discover, assess, detect, remediate, verify.

Solution architecture slide showing five capabilities: asset visibility, vulnerability, detection and response, patch management, and remediation tracking
Asset visibility (Wazuh + Action1 + manual validation), vulnerability scanning and patch management (Action1), detection and response (Wazuh), and remediation tracking (Python + spreadsheet).

Governance and remediation workflow

Every finding moves through the same six-step loop: discover, prioritise, assign, remediate, re-scan, close. Priority is set by CVSS severity, EPSS exploit likelihood, and business impact together, not severity alone, and each severity tier carries its own response SLA.

Governance slide showing the six-step verified remediation loop and SLA targets by severity
The verified remediation loop and board-level SLA targets by severity.
SeverityTargetAction
Critical24 hoursIsolate and notify CISO
High7 daysDaily status
Medium30 daysWeekly review
Low90 daysMonthly review

Asset inventory

The monitored environment covers four endpoints across three offices: three Windows workstations and one Linux server hosting the Wazuh manager, indexer, and dashboard, all at 100% agent coverage across Wazuh and Action1.

Asset inventory table listing four managed endpoints with OS, hardware specs, and agent deployment status
Full asset inventory, hardware specs, and agent deployment status.

Outcomes

By day 14, risk exposure and mean time to respond had both moved down, while patch compliance and CIS security configuration score both moved up, tracked through a before/after scorecard rather than asserted. The board pack delivered alongside the program:

Executive outcomes slide showing risk exposure down, response speed down, patch compliance up, and control strength up, plus the board pack contents
Executive outcomes and the five-part board pack: scorecard, Wazuh dashboard, Action1 compliance view, executive risk report, and Notion evidence library.

Delivery assurance

Success was defined against three criteria the program had to satisfy by day 14: full coverage of known endpoints, verified controls in place, and retained evidence at every stage rather than a one-time claim.

Delivery assurance slide showing coverage, control, and evidence criteria that had to be true by day 14
The coverage, control, and evidence checklist the program was measured against.
One requirement didn't make it into the final delivery: a fully automated Python script to drive the remediation loop end to end. Given the 14-day window, remediation tracking ran through the Python and spreadsheet workflow manually rather than as a scheduled automation. Building that automation layer is the clear next iteration on this program.

Full documentation

The complete project report, including architecture notes, process detail, and additional screenshots from every team member, is documented on Notion.

View full report on Notion →