Vulnerability Assessments
Scanners produce long lists, and most of what they flag does not matter. The value is in the filtering: separating the finding that gives an attacker a foothold from the forty that are theoretical, already mitigated, or false. We scan, validate by hand, and give you a ranked list short enough that your team can actually work through it.
1
Scope
What is in range
2
Scan
Internal and external
3
Validate
Remove the noise
4
Rank
By real exposure
5
Re scan
Confirm closure
How We Assess
01
Scoping and Asset Discovery
We agree the ranges to be scanned, then discover what is actually in them. Organisations routinely have more exposed than their asset register suggests, and forgotten hosts are exactly where unpatched services survive.
- Agreed IP ranges and hostnames in scope
- Discovery of live hosts and exposed services
- Identification of assets absent from the register
- Systems excluded from scanning, recorded with reasons
02
Authenticated and Unauthenticated Scanning
Unauthenticated scanning shows what an outsider sees. Authenticated scanning shows what is actually installed, including the patch levels an external scan can only guess at. Running both gives a materially more accurate picture.
- External scanning of internet facing services
- Internal scanning across the network
- Authenticated scanning for accurate patch state
- Configuration and hardening checks
03
Manual Validation
This is the step that distinguishes a report from a scanner export. We verify findings by hand, discard false positives, and identify where a compensating control already reduces the risk to something acceptable.
- Verification of each significant finding
- False positives removed rather than passed on
- Compensating controls taken into account
- Chained findings that combine into a larger issue
04
Risk Ranking
Severity scores from a scanner ignore your context. A critical rating on an isolated test server matters less than a moderate one on an internet facing system holding personal information. We rank by exposure in your environment.
- Ranking by exploitability and exposure, not raw CVSS
- Business context applied per asset
- Quick wins separated from structural work
- Realistic remediation effort estimated per item
05
Reporting and Re scan
You receive a report your technical team can act on directly, and we re scan afterwards. A finding is closed when a scan confirms it, not when a ticket is marked complete.
- Technical detail with affected hosts listed
- Executive summary of overall exposure
- Remediation guidance per finding
- Re scan and closure confirmation report
What You Receive
- Asset discovery results including systems not on your register
- Validated findings with false positives removed
- Risk ranking based on exposure in your environment
- Remediation guidance per finding with effort estimates
- Executive summary of overall exposure
- Re scan report confirming closure
Indicative Timeline
A vulnerability assessment normally runs one to two weeks. Scanning is quick; validation and ranking take the time, and that is where the difference between a useful report and a scanner export lies.
- Scoping and asset discovery: two to three days
- Scanning, internal and external: two to four days
- Manual validation and ranking: three to five days
- Re scan: scheduled after remediation
What We Scan
Coverage spans everything reachable, because attackers do not restrict themselves to the systems on your inventory.
External Perimeter
Internet facing services, remote access and anything exposed that should not be.
Internal Network
Servers, workstations and network devices as seen from inside a compromised position.
Web Applications
Application level weaknesses that infrastructure scanning does not reach.
Network Devices
Firewalls, switches and access points, including default credentials and stale firmware.
Cloud Configuration
Exposed storage, over permissive access policies and absent multi factor authentication.
Patch State
Missing operating system and third party patches, established through authenticated scanning.
Frequently Asked Questions
How is this different from a penetration test?
A vulnerability assessment finds and ranks weaknesses across a broad estate. A penetration test attempts to exploit them and shows what an attacker reaches. Assessments give breadth at lower cost, tests give depth. Most organisations need assessments regularly and tests periodically.
Will scanning disrupt our systems?
Scanning is generally non disruptive, but fragile legacy systems occasionally respond badly. We agree exclusions in advance, schedule around operational peaks and stop immediately if anything behaves unexpectedly.
How often should we scan?
Quarterly is a reasonable baseline for most organisations, monthly for internet facing systems, and after any significant infrastructure change. Annual scanning tells you what was true last year.
What is authenticated scanning and do we need it?
Scanning with valid credentials, which reveals actual installed patch levels rather than inferring them from service banners. It produces a considerably more accurate result and we recommend it for internal scanning.
Do you help fix what you find?
The report includes remediation guidance per finding. Where you want the work performed rather than described, that can be delivered through our managed services and is quoted separately.
What if we cannot fix everything?
Nobody fixes everything. The ranking exists so you address what carries genuine exposure first, and can make an informed decision to accept the rest. Documented risk acceptance is a legitimate outcome; silent inaction is not.
Related Services
This sits inside our Cyber Security Assessments practice. Related work: Penetration Testing where you need exploitation rather than enumeration, and IT General Controls Reviews for the control environment behind the findings.
