Vai al contenuto

Vulnerability assessment for companies

Cataloguing known weaknesses before somebody else finds them - and knowing which of the hundreds found actually matter.

In breve

A vulnerability assessment catalogues the known weaknesses in your systems and ranks them by severity. It is not a penetration test, which simulates a real attack: it is broader, repeatable and the step that comes first. The value is not in the list — a tool produces hundreds of findings — but in the reasoned reading of which ones matter in your context, and in the check after the fixes.

It is not a penetration test

One catalogues, the other tries to get in. Commissioning the second without having done the first means paying to discover the obvious.

The value is in the reading

A tool finds hundreds of problems. Knowing which of the ten critical ones genuinely are critical for you is the work worth paying for.

It has to be repeated

A single assessment photographs one day. The useful measure is how many critical findings are still open compared with the previous cycle.

What it does, and what it does not

A vulnerability assessment examines your systems and produces a list of the weaknesses already known and already catalogued: out-of-date versions, weak configurations, exposed services that should not be, default credentials never changed.

It is the most efficient way of answering a simple and uncomfortable question: if somebody looked at our company from outside right now, what would they see?

It does not do two other things, and it is worth knowing that in advance. It does not try to get in — that is a penetration test, which is a different job. And it does not find unknown vulnerabilities: it looks for catalogued ones, which are also the ones exploited in the overwhelming majority of real attacks.

Why it comes before the penetration test

The two terms get used as synonyms, and the confusion leads to buying the wrong thing, almost always the more expensive one.

Commissioning a penetration test at a company that has never carried out a catalogue means paying skilled people to discover things a tool would have found on its own. The result is a document listing unpatched servers and default passwords, with an attack-simulation invoice attached.

The sensible order is: catalogue first, fix what emerges, then — if the context justifies it — test what remains.

The real work starts after the list

On an ordinary company network a tool produces hundreds of findings. Closing them all is impossible and unnecessary, because the severity the tool declares is calculated in the abstract and knows nothing about your company.

A concrete example: a vulnerability classified critical on a server unreachable by anyone outside the internal network matters less than one classified medium on a service published to the internet. A tool does not know that; a person who has looked at your infrastructure does.

That is why the part worth paying for is not the scan — which is almost free — but the reasoned reading: reordering by real risk, and separating what has to be closed now from what can be planned and what can be accepted in the knowledge that it is being accepted.

Without that step the same thing always happens: weeks are spent on harmless findings while a remote access without a second factor stays open.

It has to be repeated, or it photographs one day

New vulnerabilities appear every week and infrastructure changes constantly. A single assessment says how things stood that day.

The value lies in the comparison between one cycle and the next, and the useful measure is not how many we have — a number with no absolute meaning — but how many of the critical ones are still open compared with last time. It is a measure of process: it says something about how the company is run, not only about how it is configured.

How we do it

The scope is agreed beforehand. Which systems, from which position — outside, inside, as an authenticated user — and what is excluded. An assessment without a defined scope produces results that cannot be compared over time.

Fragile systems are handled with care. Some checks can stress old equipment. They are identified in advance and examined in agreed windows, rather than discovered by stopping something.

The document is readable by the people who decide. Not the tool’s raw output: the findings in order of real risk, what to do about each, and how much time it takes.

There is a check after the fixes. Otherwise the question that matters most stays open — whether the problem was genuinely closed.

The rest

See also cybersecurity and NIS2 for the governance picture, IT security for the operational side, and incident response for what to do once something has already happened.

The first step

We agree the scope and tell you what to expect before starting. The first assessment is free and without obligation.

Frequently asked questions

What is the difference between a vulnerability assessment and a penetration test?

The first is a catalogue: a tool examines the systems and lists the known weaknesses, ranked by severity. It is broad, repeatable and relatively inexpensive. The second is an attack simulation carried out by people, who genuinely try to get in by chaining together weaknesses that individually would look minor. It is deeper, more expensive, and photographs a single moment. The sensible order is to catalogue and fix first, then test what remains.

How many vulnerabilities will you find?

On an ordinary company network, hundreds. It is the number that alarms people and means almost nothing, because the severity a tool declares takes no account of context. A critical vulnerability on a system nobody can reach matters less than a medium one on a service published to the internet. What we hand over is the list reordered by real risk, not the tool's raw output.

How often should it be repeated?

It depends how much your infrastructure changes, but below twice a year the comparison loses meaning. New vulnerabilities appear every week and systems change constantly: the value is not in any single assessment but in the repetition, because the useful question is not how many we have but how many of the critical ones are still open compared with last time.

Can the assessment cause disruption?

A properly conducted catalogue is non-invasive and runs during normal working hours. Some deeper checks can stress old or fragile systems, which is why the scope is agreed beforehand and sensitive systems are examined in agreed windows. A supplier who does not ask that question before starting is one to be wary of.

What do you deliver at the end?

A document with the findings ordered by real risk in your context, practical guidance on what to do about each, and the distinction between what has to be closed now, what can be planned and what can be knowingly accepted. Plus a check after the fixes, because otherwise the most important question stays open - whether the problem was actually closed.

What of your infrastructure is exposed?

An assessment says what is reachable from outside and in what order it is worth closing. We start from a conversation about your situation.