BCS Platform · Endpoint Security Engine
Vulnerability scanning & patch management — every endpoint's security posture, visible in real time, continuously verified
A self-hosted vulnerability scanning and patch management engine that unifies device inventory, patch status, software compliance and vulnerability exposure — sharing one device profile with the BCS Beam remote-support agents, instead of keeping yet another disconnected ledger.
TL;DR: BCS Vulnerability Scanning & Patch Management is the endpoint security engine inside the BCS Beam support suite, delivered with Brocent's managed services rather than sold as standalone software: it continuously scans every managed endpoint for patch gaps, unauthorised software and CIS baseline drift; advanced automation is off by default and enabled explicitly per customer, with enrollment keys isolated per customer.
9
advanced capabilities, each independently switchable
1
unified device profile recognised across three agents
Off by default
advanced automation enabled explicitly per customer
Per device
isolated keys — one compromised device never drags in the rest
The endpoint security engine of the BCS Beam support suite — not standalone software for sale
This engine is part of Brocent's BCS platform, switched on alongside your managed IT service — it shares one device profile with the BCS Beam remote-support agents, so security posture and support history always reconcile.
On this page
Core capabilities
From “knowing what devices exist” to “knowing whether they comply”
A device inventory is only the starting point — the real value is patch gaps, unauthorised software and policy drift being found before they are exploited.
Device inventory
Continuously collects hardware, operating system and installed-software facts for every managed endpoint, sharing one device profile with the remote-support agents.
LivePatch management & automation
Scans for patch gaps, builds policy-driven deployment plans and can optionally auto-deploy — scanning and deployment are two separately switchable stages.
LiveSoftware compliance scanning
Compares installed software against an approved list and flags unauthorised or high-risk software — instead of investigating what was installed only after an incident.
LiveAlerts & auto-remediation
Rule hits raise alerts automatically, and supported scenarios can close the loop with automated remediation actions — no manual one-by-one triage.
LiveCIS baseline policy packs
Built-in policy sets aligned to industry security baselines, deployed to device groups in one step — replacing item-by-item manual configuration checks.
LiveNetwork discovery
Detects not-yet-managed devices on the same network segment without installing any agent, closing the “invisible assets” blind spot.
On requestDetection validation
Actively verifies that alert rules genuinely catch known issues — avoiding “rules deployed but never actually effective”.
On requestRemote script execution
Pushes and runs operational scripts on endpoints with the full agent installed — for bulk remediation, software deployment or configuration checks.
LiveCustomer / group mapping
Devices are assigned to their customer group by dynamic tags — new devices are classified automatically on enrollment, with no manual per-device assignment.
LiveDeep dives
The four most-asked-about capabilities, opened up one by one
Device inventory, patching, software compliance, CIS baselines — not just four feature cards. Below is the actual data structure and working UI each one presents.
Device inventory — one profile, recognised across three agents
Continuously collects hardware fingerprints, OS versions, installed software and last-heartbeat times; on the same endpoint, the enrollment status of the BCS Beam strong-identity client, the day-to-day assistance agent and the endpoint security agent are shown side by side — not three ledgers that never reconcile.
Patch management — scanning and deployment separated, each stage independently switchable
The scanning stage finds each device's missing patches, tags severity and release date, and builds a deployment plan; the deployment stage is authorised separately — optional auto-deploy, or manual approval per device group. Neither stage drags the other along.
Software compliance scanning — unauthorised software flagged before it is exploited
Continuously compares each device's installed software against the customer's own approved list; unauthorised, end-of-life (EOL) or high-risk-category hits are flagged automatically with a first-seen date, ready for operations to review or escalate item by item.
CIS baseline policy packs — per-control checks, not one “compliant” headline score
Built-in policy packs aligned to common industry baselines (CIS workstation / server benchmarks), deployable to chosen device groups in one step; every control reports its own passing-device count instead of being folded into one vague compliance percentage — so you can pinpoint exactly which baseline fails on which devices.
Remote operations & key isolation
“Remote access” here means script-level operations — not screen sharing
The endpoint security engine provides no remote desktop view — screen sessions belong to BCS Beam's remote-support agents. Its “unattended access” serves operations automation: pushing and executing scripts on enrolled endpoints without an end user present to confirm. The security boundary therefore isn't “whether someone is watching the screen”, but the isolation granularity of keys and permissions.
The key is the boundary
Script execution is inherently riskier than screen sharing — a script can do bulk, silent operations a screen session never could. So the permission choke point moves forward to enrollment:
- ✓ Script execution requires the full agent on the endpoint — lightweight inventory probes can never trigger it
- ✓ Advanced automation (network discovery, auto-remediation, script execution) is enabled explicitly per customer, never switched on wholesale at deployment
- ✓ The device-tag-to-customer mapping is maintained independently, preventing scripts from ever being pushed to the wrong customer's device group
Layered enablement
Advanced capabilities off by default, enabled per customer on demand
The opposite of “everything on after install” — scanning, deployment, alerting, script execution: every advanced automation capability is an independent switch, enabled only when a customer explicitly needs it, shrinking the surface for mis-operation and over-collection.
Patch scanning
Enabled on demand — finding gaps never means auto-deploying
Patch auto-deployment
Independent of the scanning switch, authorised separately
Software compliance scanning
Compares against unauthorised / high-risk software lists
Alert auto-remediation
Runs remediation actions automatically on rule hits
Agentless network discovery
Detects unmanaged devices on the network segment
Detection validation
Actively verifies alert rules genuinely work
Audit & evidence
No screen recordings — but every scan and every fix is fully on record
The endpoint security engine does no screen sharing, so “compliance evidence” here isn't a recording — it's the complete event stream of every policy comparison, alert trigger and remediation-script run: who, when, on which device, doing what.
Policy comparison trail
Every baseline check's comparison result is archived independently — any device's compliance state at any point in time is traceable.
Remediation trail
Auto-remediation and manually pushed scripts both record execution time, operator and result — not merely “this once ran”.
CSV export
Device inventory, compliance state and usage data are exportable — ready to feed your own audit workflow or quarterly reports.
UI previews
Login page and device overview
The interfaces below are illustrative and all data is sample data — they show the information structure the product actually presents, not screenshots of a real customer environment.
ENDPOINT MANAGEMENT
Device-level security posture, vulnerability and compliance monitoring across every managed endpoint — updated in real time.
Sign in
Device overview (sample data)
1,842
Managed devices
63
Open patch gaps
7
Unauthorised software hits
96.4%
Baseline compliance
One full pass from detection to remediation
From endpoint heartbeat to reviewed and archived
The steps below cycle in the real processing order (an animated illustration, in place of a screen recording).
Heartbeat report
Endpoints periodically report hardware and software inventory
Policy comparison
Checked against baseline policies / approved software lists
Issue found
A patch gap or unauthorised software hit
Alert raised
An alert event is generated by severity
Remediation runs
Authorised scenarios execute remediation scripts automatically
Review & archive
Results are written to the audit record, awaiting the next heartbeat
Pricing
Two capabilities, two transparent price lists
Vulnerability scanning and patch management can each be bought as a one-time assessment or a managed, always-on service — pricing is public and tiered by asset / endpoint count.
Vulnerability scanning pricing
External, internal, authenticated and web-application scans, delivering a CVSS-scored, prioritised, remediation-ready report.
View vulnerability scanning pricing →Patch management pricing
Managed OS and third-party patching with a monthly patch-compliance report — patched / pending / failed at a glance.
View patch management pricing →Make every endpoint's security posture visible
The endpoint security engine ships with Brocent's managed IT services. Contact your account manager — or talk to us — about enabling vulnerability scanning and patch management across your device fleet.
BCS Beam Support Suite · Endpoint Security Engine
All screenshots, interfaces and data on this page are illustrative, redacted samples used to explain product capability — they contain no real customer information or device identifiers.