Vulnerability assessment
Recurring scanning with a human triage layer, so your engineers fix what matters instead of chasing false positives.
What the engagement covers.
External attack surface
Continuous discovery of domains, hosts, and services you expose, including the ones nobody remembers owning.
Internal assets
Authenticated scanning of servers, workstations, and network devices for missing patches and weak configuration.
Cloud and containers
Configuration and image scanning for AWS, Azure, Google Cloud, and Kubernetes workloads.
Human triage
A consultant reviews every result, removes false positives, confirms exploitability, and groups findings by root cause.
Trend reporting
Month over month view of new, fixed, and lingering issues so leadership can see whether the program is working.
How it runs.
Onboard
Asset inventory agreed, scanning credentials provisioned, and safe scanning windows set for sensitive systems.
Scan
Scheduled scans run at the agreed cadence. Newly discovered assets are flagged before they are added to scope.
Triage
Results are reviewed by a consultant and delivered as a short list of confirmed, prioritized findings with fixes.
Review
A monthly call to walk through the trend, unblock fixes, and adjust scope as your environment changes.
What you receive.
- Confirmed findings list, prioritized by exploitability
- Monthly trend report for leadership
- Asset inventory kept current as your footprint changes
- Direct access to the consultant who triaged your results
Who it is for.
- Teams without a dedicated security engineer
- Companies with compliance requirements for regular scanning
- Organizations that grew by acquisition and are unsure what they expose
Questions about vulnerability assessment.
Why not just run a scanner ourselves?
You can, and many clients do. The value we add is triage: turning hundreds of raw results into the handful that are real, exploitable, and worth an engineer's afternoon.
Monthly or quarterly?
Monthly for internet-facing assets and anything in scope for PCI DSS. Quarterly is reasonable for stable internal environments. We recommend after seeing your footprint.
Does this replace a penetration test?
No. Scanning finds known weaknesses at scale; a penetration test finds logic flaws and chains that no scanner sees. Most clients run both.
Scope a vulnerability assessment engagement.
Tell us about the system and the deadline. You will get a fixed-price proposal after one scoping call.