What it does, and what it does not
A vulnerability assessment examines your systems and produces a list of the weaknesses already known and already catalogued: out-of-date versions, weak configurations, exposed services that should not be, default credentials never changed.
It is the most efficient way of answering a simple and uncomfortable question: if somebody looked at our company from outside right now, what would they see?
It does not do two other things, and it is worth knowing that in advance. It does not try to get in — that is a penetration test, which is a different job. And it does not find unknown vulnerabilities: it looks for catalogued ones, which are also the ones exploited in the overwhelming majority of real attacks.
Why it comes before the penetration test
The two terms get used as synonyms, and the confusion leads to buying the wrong thing, almost always the more expensive one.
Commissioning a penetration test at a company that has never carried out a catalogue means paying skilled people to discover things a tool would have found on its own. The result is a document listing unpatched servers and default passwords, with an attack-simulation invoice attached.
The sensible order is: catalogue first, fix what emerges, then — if the context justifies it — test what remains.
The real work starts after the list
On an ordinary company network a tool produces hundreds of findings. Closing them all is impossible and unnecessary, because the severity the tool declares is calculated in the abstract and knows nothing about your company.
A concrete example: a vulnerability classified critical on a server unreachable by anyone outside the internal network matters less than one classified medium on a service published to the internet. A tool does not know that; a person who has looked at your infrastructure does.
That is why the part worth paying for is not the scan — which is almost free — but the reasoned reading: reordering by real risk, and separating what has to be closed now from what can be planned and what can be accepted in the knowledge that it is being accepted.
Without that step the same thing always happens: weeks are spent on harmless findings while a remote access without a second factor stays open.
It has to be repeated, or it photographs one day
New vulnerabilities appear every week and infrastructure changes constantly. A single assessment says how things stood that day.
The value lies in the comparison between one cycle and the next, and the useful measure is not how many we have — a number with no absolute meaning — but how many of the critical ones are still open compared with last time. It is a measure of process: it says something about how the company is run, not only about how it is configured.
How we do it
The scope is agreed beforehand. Which systems, from which position — outside, inside, as an authenticated user — and what is excluded. An assessment without a defined scope produces results that cannot be compared over time.
Fragile systems are handled with care. Some checks can stress old equipment. They are identified in advance and examined in agreed windows, rather than discovered by stopping something.
The document is readable by the people who decide. Not the tool’s raw output: the findings in order of real risk, what to do about each, and how much time it takes.
There is a check after the fixes. Otherwise the question that matters most stays open — whether the problem was genuinely closed.
The rest
See also cybersecurity and NIS2 for the governance picture, IT security for the operational side, and incident response for what to do once something has already happened.
The first step
We agree the scope and tell you what to expect before starting. The first assessment is free and without obligation.