B BROCENT
All Services

BCS Platform · Endpoint Security Engine

Vulnerability scanning & patch management — every endpoint's security posture, visible in real time, continuously verified

A self-hosted vulnerability scanning and patch management engine that unifies device inventory, patch status, software compliance and vulnerability exposure — sharing one device profile with the BCS Beam remote-support agents, instead of keeping yet another disconnected ledger.

TL;DR: BCS Vulnerability Scanning & Patch Management is the endpoint security engine inside the BCS Beam support suite, delivered with Brocent's managed services rather than sold as standalone software: it continuously scans every managed endpoint for patch gaps, unauthorised software and CIS baseline drift; advanced automation is off by default and enabled explicitly per customer, with enrollment keys isolated per customer.

APAC EMEA USCA LATAM

9

advanced capabilities, each independently switchable

1

unified device profile recognised across three agents

Off by default

advanced automation enabled explicitly per customer

Per device

isolated keys — one compromised device never drags in the rest

Included with managed services

The endpoint security engine of the BCS Beam support suite — not standalone software for sale

This engine is part of Brocent's BCS platform, switched on alongside your managed IT service — it shares one device profile with the BCS Beam remote-support agents, so security posture and support history always reconcile.

Core capabilities

From “knowing what devices exist” to “knowing whether they comply”

A device inventory is only the starting point — the real value is patch gaps, unauthorised software and policy drift being found before they are exploited.

🗃️

Device inventory

Continuously collects hardware, operating system and installed-software facts for every managed endpoint, sharing one device profile with the remote-support agents.

Live
🩹

Patch management & automation

Scans for patch gaps, builds policy-driven deployment plans and can optionally auto-deploy — scanning and deployment are two separately switchable stages.

Live
🧬

Software compliance scanning

Compares installed software against an approved list and flags unauthorised or high-risk software — instead of investigating what was installed only after an incident.

Live
🚨

Alerts & auto-remediation

Rule hits raise alerts automatically, and supported scenarios can close the loop with automated remediation actions — no manual one-by-one triage.

Live
📐

CIS baseline policy packs

Built-in policy sets aligned to industry security baselines, deployed to device groups in one step — replacing item-by-item manual configuration checks.

Live
🛰️

Network discovery

Detects not-yet-managed devices on the same network segment without installing any agent, closing the “invisible assets” blind spot.

On request
🎯

Detection validation

Actively verifies that alert rules genuinely catch known issues — avoiding “rules deployed but never actually effective”.

On request
⚙️

Remote script execution

Pushes and runs operational scripts on endpoints with the full agent installed — for bulk remediation, software deployment or configuration checks.

Live
🏷️

Customer / group mapping

Devices are assigned to their customer group by dynamic tags — new devices are classified automatically on enrollment, with no manual per-device assignment.

Live

Deep dives

The four most-asked-about capabilities, opened up one by one

Device inventory, patching, software compliance, CIS baselines — not just four feature cards. Below is the actual data structure and working UI each one presents.

🗃️

Device inventory — one profile, recognised across three agents

Continuously collects hardware fingerprints, OS versions, installed software and last-heartbeat times; on the same endpoint, the enrollment status of the BCS Beam strong-identity client, the day-to-day assistance agent and the endpoint security agent are shown side by side — not three ledgers that never reconcile.

Device details — FIN-WKS-0412
FIN-WKS-0412 Windows 11 23H2
FIN-WKS-0413 Windows 11 23H2
SRV-EDGE-021 Windows Server 2022
POS-STORE-118 Windows 10 22H2
FIN-LAP-0007 Windows 11 24H2
FIN-WKS-0412 Compliant
Asset tag FA-••••2291
Last heartbeat 2 minutes ago
CPU / memory Intel i7-1355U · 16GB
Disk 512GB SSD · encrypted
Internal IP 10.•.•.142
Installed software 128 items
Cross-agent enrollment status
Strong-identity client Assistance agent Endpoint security agent
Device details — hardware fingerprint and cross-agent enrollment status (sample data) Illustrative UI
🩹

Patch management — scanning and deployment separated, each stage independently switchable

The scanning stage finds each device's missing patches, tags severity and release date, and builds a deployment plan; the deployment stage is authorised separately — optional auto-deploy, or manual approval per device group. Neither stage drags the other along.

Patch gaps
Critical 3 Important 12 Moderate 48
SRV-EDGE-021 KB5034441 Critical 2026-08-13 To deploy
POS-STORE-118 KB5031354 Critical 2026-08-06 Awaiting approval
FIN-WKS-0413 KB5032190 Important 2026-07-30 Scheduled
FIN-LAP-0007 KB5030310 Moderate 2026-07-22 Deployed
Patch gap list — scheduled by severity (sample data) Illustrative UI
🧬

Software compliance scanning — unauthorised software flagged before it is exploited

Continuously compares each device's installed software against the customer's own approved list; unauthorised, end-of-life (EOL) or high-risk-category hits are flagged automatically with a first-seen date, ready for operations to review or escalate item by item.

Software compliance
POS-STORE-118 Unregistered remote access tool 1.2.0 Unauthorised 2026-08-24
SRV-EDGE-021 Legacy archiving utility 4.1.0 End of life 2026-08-11
FIN-WKS-0413 Personal cloud sync client 3.8.2 High-risk category 2026-08-02
FIN-LAP-0007 Browser extension (unknown origin) Unauthorised 2026-07-28
Software compliance violations list (sample data) Illustrative UI
📐

CIS baseline policy packs — per-control checks, not one “compliant” headline score

Built-in policy packs aligned to common industry baselines (CIS workstation / server benchmarks), deployable to chosen device groups in one step; every control reports its own passing-device count instead of being folded into one vague compliance percentage — so you can pinpoint exactly which baseline fails on which devices.

CIS baseline checks
1.1.4 Minimum password length ≥ 14 characters 1,806 / 1,842
2.3.1 Guest account disabled 1,842 / 1,842
18.9.1 Disk encryption (BitLocker) enabled 1,620 / 1,842
9.3.1 Firewall enabled for all policy domains 1,824 / 1,842
2.2.5 Screen lock timeout ≤ 10 minutes 1,400 / 1,842
CIS workstation baseline checks — passing-device counts per control (sample data) Illustrative UI

Remote operations & key isolation

“Remote access” here means script-level operations — not screen sharing

The endpoint security engine provides no remote desktop view — screen sessions belong to BCS Beam's remote-support agents. Its “unattended access” serves operations automation: pushing and executing scripts on enrolled endpoints without an end user present to confirm. The security boundary therefore isn't “whether someone is watching the screen”, but the isolation granularity of keys and permissions.

Customer A enrollment key Customer B enrollment key Customer A's endpoints Accept their own key only Customer B's endpoints Accept their own key only ✕ No cross-access

Per-customer keys mean that even if one customer's enrollment key leaks, an attacker cannot use it to enroll into — or operate — any other customer's endpoints.

Per-customer enrollment key isolation
🔑

The key is the boundary

Script execution is inherently riskier than screen sharing — a script can do bulk, silent operations a screen session never could. So the permission choke point moves forward to enrollment:

  • Script execution requires the full agent on the endpoint — lightweight inventory probes can never trigger it
  • Advanced automation (network discovery, auto-remediation, script execution) is enabled explicitly per customer, never switched on wholesale at deployment
  • The device-tag-to-customer mapping is maintained independently, preventing scripts from ever being pushed to the wrong customer's device group

Layered enablement

Advanced capabilities off by default, enabled per customer on demand

The opposite of “everything on after install” — scanning, deployment, alerting, script execution: every advanced automation capability is an independent switch, enabled only when a customer explicitly needs it, shrinking the surface for mis-operation and over-collection.

Patch scanning

Enabled on demand — finding gaps never means auto-deploying

Patch auto-deployment

Independent of the scanning switch, authorised separately

Software compliance scanning

Compares against unauthorised / high-risk software lists

Alert auto-remediation

Runs remediation actions automatically on rule hits

Agentless network discovery

Detects unmanaged devices on the network segment

Detection validation

Actively verifies alert rules genuinely work

Audit & evidence

No screen recordings — but every scan and every fix is fully on record

The endpoint security engine does no screen sharing, so “compliance evidence” here isn't a recording — it's the complete event stream of every policy comparison, alert trigger and remediation-script run: who, when, on which device, doing what.

📊

Policy comparison trail

Every baseline check's comparison result is archived independently — any device's compliance state at any point in time is traceable.

🧯

Remediation trail

Auto-remediation and manually pushed scripts both record execution time, operator and result — not merely “this once ran”.

📥

CSV export

Device inventory, compliance state and usage data are exportable — ready to feed your own audit workflow or quarterly reports.

UI previews

Login page and device overview

The interfaces below are illustrative and all data is sample data — they show the information structure the product actually presents, not screenshots of a real customer environment.

Sign in
E

Sign in

Email address
name@company.com
Password
••••••••••
Sign in
Login page — the live, rebranded production design Illustrative UI
Device overview

Device overview (sample data)

1,842

Managed devices

63

Open patch gaps

7

Unauthorised software hits

96.4%

Baseline compliance

FIN-WKS-0412 Windows 11 23H2 Up to date Compliant
SRV-EDGE-021 Windows Server 2022 3 pending Needs review
POS-STORE-118 Windows 10 22H2 Unauthorised software Non-compliant
Device overview and compliance board Illustrative UI

One full pass from detection to remediation

From endpoint heartbeat to reviewed and archived

The steps below cycle in the real processing order (an animated illustration, in place of a screen recording).

01

Heartbeat report

Endpoints periodically report hardware and software inventory

02

Policy comparison

Checked against baseline policies / approved software lists

03

Issue found

A patch gap or unauthorised software hit

04

Alert raised

An alert event is generated by severity

05

Remediation runs

Authorised scenarios execute remediation scripts automatically

06

Review & archive

Results are written to the audit record, awaiting the next heartbeat

Make every endpoint's security posture visible

The endpoint security engine ships with Brocent's managed IT services. Contact your account manager — or talk to us — about enabling vulnerability scanning and patch management across your device fleet.

BCS Beam Support Suite · Endpoint Security Engine

All screenshots, interfaces and data on this page are illustrative, redacted samples used to explain product capability — they contain no real customer information or device identifiers.