Vulnerability Assessments

Scanners produce long lists, and most of what they flag does not matter. The value is in the filtering: separating the finding that gives an attacker a foothold from the forty that are theoretical, already mitigated, or false. We scan, validate by hand, and give you a ranked list short enough that your team can actually work through it.

1

Scope

What is in range

2

Scan

Internal and external

3

Validate

Remove the noise

4

Rank

By real exposure

5

Re scan

Confirm closure

How We Assess

01

Scoping and Asset Discovery

We agree the ranges to be scanned, then discover what is actually in them. Organisations routinely have more exposed than their asset register suggests, and forgotten hosts are exactly where unpatched services survive.

02

Authenticated and Unauthenticated Scanning

Unauthenticated scanning shows what an outsider sees. Authenticated scanning shows what is actually installed, including the patch levels an external scan can only guess at. Running both gives a materially more accurate picture.

03

Manual Validation

This is the step that distinguishes a report from a scanner export. We verify findings by hand, discard false positives, and identify where a compensating control already reduces the risk to something acceptable.

04

Risk Ranking

Severity scores from a scanner ignore your context. A critical rating on an isolated test server matters less than a moderate one on an internet facing system holding personal information. We rank by exposure in your environment.

05

Reporting and Re scan

You receive a report your technical team can act on directly, and we re scan afterwards. A finding is closed when a scan confirms it, not when a ticket is marked complete.

What You Receive

Indicative Timeline

A vulnerability assessment normally runs one to two weeks. Scanning is quick; validation and ranking take the time, and that is where the difference between a useful report and a scanner export lies.

What We Scan

Coverage spans everything reachable, because attackers do not restrict themselves to the systems on your inventory.

External Perimeter

Internet facing services, remote access and anything exposed that should not be.

Internal Network

Servers, workstations and network devices as seen from inside a compromised position.

Web Applications

Application level weaknesses that infrastructure scanning does not reach.

Network Devices

Firewalls, switches and access points, including default credentials and stale firmware.

Cloud Configuration

Exposed storage, over permissive access policies and absent multi factor authentication.

Patch State

Missing operating system and third party patches, established through authenticated scanning.

Frequently Asked Questions

A vulnerability assessment finds and ranks weaknesses across a broad estate. A penetration test attempts to exploit them and shows what an attacker reaches. Assessments give breadth at lower cost, tests give depth. Most organisations need assessments regularly and tests periodically.

Scanning is generally non disruptive, but fragile legacy systems occasionally respond badly. We agree exclusions in advance, schedule around operational peaks and stop immediately if anything behaves unexpectedly.

Quarterly is a reasonable baseline for most organisations, monthly for internet facing systems, and after any significant infrastructure change. Annual scanning tells you what was true last year.

Scanning with valid credentials, which reveals actual installed patch levels rather than inferring them from service banners. It produces a considerably more accurate result and we recommend it for internal scanning.

The report includes remediation guidance per finding. Where you want the work performed rather than described, that can be delivered through our managed services and is quoted separately.

Nobody fixes everything. The ranking exists so you address what carries genuine exposure first, and can make an informed decision to accept the rest. Documented risk acceptance is a legitimate outcome; silent inaction is not.

Related Services

This sits inside our Cyber Security Assessments practice. Related work: Penetration Testing where you need exploitation rather than enumeration, and IT General Controls Reviews for the control environment behind the findings.

Discuss a vulnerability assessment