Skip to content
MD-5

// Vulnerability Assessment

Vulnerability Assessment

A fast, affordable baseline: automated scanning across your estate with every result validated, so you get a list of real issues, not 400 pages of noise.

Overview

Not every organization needs a full penetration test on day one. A vulnerability assessment gives you broad coverage quickly: which of your systems have known vulnerabilities, weak configurations or outdated software.

The difference from running a scanner yourself is validation. Every finding is checked by a tester, false positives are removed, and what’s left is ranked by real-world risk with a clear fix.

Who this is for

  • Small businesses wanting a first, affordable security baseline
  • Teams between annual penetration tests
  • Organizations answering a cyber-insurance questionnaire

What gets tested

Coverage

  • Internet-facing hosts, websites and services
  • Known CVEs in operating systems, services and web frameworks
  • TLS, email security (SPF, DKIM, DMARC) and DNS configuration
  • Common misconfigurations and default credentials

What you receive

  • Validated findings, false positives removed
  • Risk-ranked remediation plan
  • Summary suitable for insurers and management

Standards followed

  • CVSS v3.1 / v4.0
  • CIS Benchmarks (where applicable)

Read the full testing methodology.

// Process

How the engagement runs

  1. 01 Day 0

    Scope

    A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.

  2. 02 Days 1 to 10

    Test

    Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.

  3. 03 +3 days

    Report

    A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.

  4. 04 When you’re ready

    Retest

    Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.

// FAQ

Vulnerability Assessment questions

Is a vulnerability assessment the same as a penetration test?

No. An assessment identifies and validates known weaknesses; a penetration test goes further and attempts to exploit them and find logic flaws. Many clients start with an assessment and move to a pentest.

Can this be recurring?

Yes. Quarterly or monthly assessments are available at a reduced rate, with trend reporting.

// Further reading

// Also available

Other services

Web App Pentest

An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.

API Pentest

Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.

Network Pentest

External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.