Vulnerability Assessment
The first step to improving your security is knowing where you're exposed. A vulnerability assessment gives you a complete picture of your technical risks, prioritized by criticality.
Vulnerability assessment vs. pentesting: what does your company need?
A vulnerability assessment (VA) identifies and classifies known vulnerabilities in your systems through scanning and technical review, without actively exploiting them. Pentesting goes a step further: an expert attempts to exploit those vulnerabilities to demonstrate real impact. A VA is ideal as a periodic review or starting point; pentesting is necessary to demonstrate real impact, meet advanced regulatory requirements, or prepare for a Red Team.
What the vulnerability assessment covers
- Vulnerability scanning of internal network and external perimeter
- Identification of active CVEs in your technology stack
- Review of security configurations (hardening)
- Assessment of outdated and unsupported software (EOL)
- Analysis of unnecessarily exposed services
- Prioritization by CVSS v3.1/v4.0 and real exploitability (CISA KEV)
- IT asset inventory as a by-product of the scan
- Available as a recurring monthly or quarterly service
Process
- Scope definition: We identify all in-scope assets: IPs, network ranges, web applications, servers.
- Automated scanning: Scanning with specialized tools (Nessus, OpenVAS, Nuclei) to detect CVEs and misconfigurations.
- Manual validation: Our experts review and validate the results to remove false positives and add context.
- Intelligent prioritization: We classify findings by real criticality: CVSS v4 plus active exploitability plus business impact.
- Report and follow-up: We deliver the report with a remediation roadmap and follow up until closure.
Deliverables
- Inventory of assets identified during the scan
- Prioritized list of vulnerabilities with CVSS v4 and exploitability
- Executive report with overall risk summary
- Technical report detailing each vulnerability and remediation recommendation
- Evolution comparison if delivered as a recurring service
When a vulnerability assessment is enough
- Periodic security review without needing to demonstrate exploitability
- Audit prior to a pentest to narrow down the scope
- Inventory of security technical debt in legacy systems
- Verification of remediation after a previous pentest
- Compliance with internal or client audit requirements
Frequently asked questions
Is a vulnerability assessment enough to comply with NIS2 or ISO 27001?
It depends on the required maturity level. NIS2 and ISO 27001 require continuous vulnerability management, which a recurring VA can cover. To demonstrate real impact or prepare for Red Team evaluations, pentesting is required.
How often should I run a vulnerability assessment?
We recommend a monthly cycle for critical assets and quarterly for the rest. After significant infrastructure changes (a new application, cloud migration, etc.) we always recommend a one-off assessment.
Does the VA include web applications?
Yes. The scope can include network infrastructure, servers, web applications and APIs. We also offer the vulnerability assessment as a first step before a full web pentest.