What the assessment covers
Coverage we hold any assessment to, whether it is a one-off exercise or the first cycle of a running programme.
Credentialed and agent-based scanning
Authenticated scans and agents see installed software and patch state properly, instead of guessing from open ports.
Discovery
Live hosts, services, exposed interfaces and forgotten assets found first, because unknown assets are the ones that get breached.
Web application scanning
Application-layer checks against your web estate, including authenticated areas that unauthenticated scans never reach.
Configuration and benchmark audits
Hosts, databases and network devices audited against CIS benchmarks and your own hardening standard.
Risk-based prioritisation
Findings ranked on exploit availability, exposure and asset criticality, so the top of the list is genuinely the top.
False positive validation
Anything material is verified by an engineer before it reaches your report, which is what makes the report credible.
Compliance profiles
Scan policies aligned to PCI DSS, ISO 27001 and regulator requirements, with exportable evidence.
Scheduled and ad-hoc scans
Recurring scans for the estate and on-demand scans after a change or a newly published vulnerability.
Remediation-ready reporting
Findings grouped by owner and by fix, not by host, so remediation is one task instead of two hundred.
From an unmapped estate to a fix list somebody will actually work through
Scanning is the easy part. Everything after it is what makes the exercise worth running.
One-off assessment
A point-in-time assessment with a defined scope, validated findings, a prioritised report and a retest once you have remediated.
Continuous programme
Recurring scans, tracked remediation, SLA reporting and trend over time, run as a managed service.
Work that usually follows
Vulnerability management
A scan is a snapshot. Exposure needs a running process with owners and SLAs.
Penetration testing
Scanning finds the weakness. Testing proves what an attacker could do with it.
Risk assessment
Technical findings become business risk only once someone rates and owns them.
