We're a 10-person medical device spare parts distribution company based in Hamburg. The requirement for "regular vulnerability scanning and management" has been popping up more and more in enterprise security audit questionnaires from our clients. Our office runs 12 Windows and Mac computers, 1 local file server and a public-facing B2B ordering portal.
We've been looking into solutions marketed as vulnerability management tools but prices range anywhere from €1,500 to €5,000 a year. We don't have a dedicated in-house cybersecurity person; I handle IT myself with some part-time external support.
What exactly should a vulnerability management tool detect and report for a business of our size? We want to avoid overly complex systems that churn out hundreds of meaningless alerts every single day. What should we verify before buying, and what are realistic expectations?