Vulnerability Management & Testing

Vulnerability management, testing, and remediation processes at FMIS

FMIS Vulnerability Management

Vulnerability Management & Testing

FMIS applies a structured approach to identifying, assessing, and resolving security vulnerabilities across both development and hosted environments. This combines ongoing monitoring, automated scanning, and independent testing.

Security and compliance enquiries
Security & compliance

If you have questions about security, data protection, or require documentation for a review, get in touch with our team.

Email our team Privacy policy Cookie policy
General enquiries: +44 (0) 1227 773003 Mon–Fri, 9:00–17:00 (BST/GMT)

FMIS Vulnerability Management Approach

Approach

Vulnerability management is integrated into both system development and day-to-day operations.

  • Code is reviewed and scanned during development
  • Systems are monitored and assessed in production environments
  • Findings are logged, prioritised, and resolved through defined processes

This ensures that potential risks are identified early and managed consistently.

FMIS Code Scanning

Code and system scanning

FMIS uses a combination of code-level and system-level scanning to detect vulnerabilities.

  • Code scanning identifies issues during development
  • System scanning validates the security of hosted environments
  • Findings are reviewed and addressed as part of controlled processes

Recent system-level scanning has confirmed that hosted environments are securely configured, with no outstanding critical issues following remediation.

FMIS Independent Code Testing and Penetration Testing

Independent testing

FMIS carries out regular independent testing to validate its security posture.

This includes annual infrastructure and application penetration testing (ITHC). Findings are reviewed and addressed through defined remediation processes.

This provides an external assessment of system security in addition to internal controls.

FMIS Bug Tracking and Remediation

Remediation and tracking

All identified vulnerabilities are managed through a structured process.

  • Issues are logged and assessed based on severity
  • Remediation actions are defined and implemented
  • Updates are tested and verified before release

This ensures that vulnerabilities are addressed in a controlled and traceable way.

FMIS Continuous Improvement

Continuous review

Vulnerability management is reviewed as part of the wider ISMS.

  • Results are reviewed during internal audits and management reviews
  • Processes are updated based on findings and evolving risks
  • Security controls are refined over time

This supports ongoing improvement rather than one-off remediation.

Further information

If you require additional detail on vulnerability management or testing processes, please contact:

privacy@fmis.co.uk

FMIS Lease Accounting version 12.47 product update

What is new in FMIS Lease Accounting version 12.47

FMIS Lease Accounting version 12.47 includes reporting and import performance improvements, together with additional support for defined data-conversion scenarios.
FMIS Fixed Assets Integration with AccountMate Software

AccountMate Fixed Asset Integration with FMIS

FMIS integrates with AccountMate to transfer fixed asset General Ledger posting data through a controlled process, reducing manual re-entry.
Industrial asset and value blocks showing accumulated depreciation and the remaining net book value

Net Book Value (NBV) Explained : Formula, Calculation, and Examples

What net book value is, the net book value formula, and how to calculate it, with worked examples and how it differs from market value and carrying value.
Business machinery, vehicles and IT equipment connected to an approved capital allowances record

Capital Allowances Explained: A UK Guide for Businesses

A plain-English guide to capital allowances for UK businesses in 2026, covering the Annual Investment Allowance, full expensing, writing down allowances, and how to claim