Vulnerability Assessment

The first step to improving your security is knowing where you're exposed. A vulnerability assessment gives you a complete picture of your technical risks, prioritized by criticality.

Vulnerability assessment vs. pentesting: what does your company need?

A vulnerability assessment (VA) identifies and classifies known vulnerabilities in your systems through scanning and technical review, without actively exploiting them. Pentesting goes a step further: an expert attempts to exploit those vulnerabilities to demonstrate real impact. A VA is ideal as a periodic review or starting point; pentesting is necessary to demonstrate real impact, meet advanced regulatory requirements, or prepare for a Red Team.

What the vulnerability assessment covers

  • Vulnerability scanning of internal network and external perimeter
  • Identification of active CVEs in your technology stack
  • Review of security configurations (hardening)
  • Assessment of outdated and unsupported software (EOL)
  • Analysis of unnecessarily exposed services
  • Prioritization by CVSS v3.1/v4.0 and real exploitability (CISA KEV)
  • IT asset inventory as a by-product of the scan
  • Available as a recurring monthly or quarterly service

Process

  1. Scope definition: We identify all in-scope assets: IPs, network ranges, web applications, servers.
  2. Automated scanning: Scanning with specialized tools (Nessus, OpenVAS, Nuclei) to detect CVEs and misconfigurations.
  3. Manual validation: Our experts review and validate the results to remove false positives and add context.
  4. Intelligent prioritization: We classify findings by real criticality: CVSS v4 plus active exploitability plus business impact.
  5. Report and follow-up: We deliver the report with a remediation roadmap and follow up until closure.

Deliverables

  • Inventory of assets identified during the scan
  • Prioritized list of vulnerabilities with CVSS v4 and exploitability
  • Executive report with overall risk summary
  • Technical report detailing each vulnerability and remediation recommendation
  • Evolution comparison if delivered as a recurring service

When a vulnerability assessment is enough

  • Periodic security review without needing to demonstrate exploitability
  • Audit prior to a pentest to narrow down the scope
  • Inventory of security technical debt in legacy systems
  • Verification of remediation after a previous pentest
  • Compliance with internal or client audit requirements

Frequently asked questions

Is a vulnerability assessment enough to comply with NIS2 or ISO 27001?

It depends on the required maturity level. NIS2 and ISO 27001 require continuous vulnerability management, which a recurring VA can cover. To demonstrate real impact or prepare for Red Team evaluations, pentesting is required.

How often should I run a vulnerability assessment?

We recommend a monthly cycle for critical assets and quarterly for the rest. After significant infrastructure changes (a new application, cloud migration, etc.) we always recommend a one-off assessment.

Does the VA include web applications?

Yes. The scope can include network infrastructure, servers, web applications and APIs. We also offer the vulnerability assessment as a first step before a full web pentest.