Skip to main content
REF-INF-007

Vulnerability Assessment

Gives organizations an understanding of their current security posture and identifies areas for improvement, combining automated tools and manual techniques.

Extreme close view of a server board with gold contacts
Objectives

What this achieves.

01

Identify vulnerabilities

Combines automated tools and manual techniques to scan for known vulnerabilities, misconfigurations, and threats.

02

Assess risk

Weighs each vulnerability by potential impact and likelihood of exploitation.

03

Recommend remediation

Provides specific steps to reduce the risk posed by each finding.

04

Improve security posture

Regular assessment helps prevent breaches and data loss over time.

Approach

Five phases.

1

Preparation

Define assessment scope, identify systems to evaluate, and secure access credentials.

2

Information Gathering

Collect intelligence through reconnaissance, public records, and personnel interviews.

3

Vulnerability Scanning

Scan target systems, networks, and applications for known vulnerabilities and misconfigurations.

4

Vulnerability Analysis

Determine impact and likelihood of exploitation, prioritized by risk level.

5

Reporting

Document findings, risk assessments, and remediation guidance.

Executive Summary Detailed Report Vulnerability Evidence Recommendations Knowledge Transfer
Deliverables

What you receive.

01

Executive Summary

A high-level overview of the results: the vulnerabilities found, their impact and severity, and a risk rating.

02

Detailed Report

Detailed information on every vulnerability found, including its description and the evidence of its existence.

03

Vulnerability Evidence

Screenshots, log files, and other evidence demonstrating that each vulnerability exists and what it exposes.

04

Recommendations

Actionable fixes for the vulnerabilities found, and for the overall security posture behind them.

05

Knowledge Transfer

A presentation and discussion with your team covering the findings, the severe vulnerabilities, and the major risks.

FAQ

Common questions.

Is this just an automated scan?

No. Scanning is one phase. The assessment combines automated tools with manual techniques, and adds information gathering through reconnaissance, public records, and personnel interviews before anything is scanned.

How are findings prioritized?

Each vulnerability is weighed by potential impact and likelihood of exploitation during the analysis phase, so the report is ordered by risk rather than by scanner severity alone.

How often should this run?

Regularly. Improving security posture over time depends on repeat assessment, since new vulnerabilities and misconfigurations appear as the environment changes.

What do we receive?

An executive summary, a detailed report, vulnerability evidence, recommendations with specific remediation steps, and knowledge transfer.

Ready to scope Vulnerability Assessment?

Request an Assessment
Request an Assessment Email Us