Vulnerability assessment.
Broad coverage across a large estate, with every finding manually validated before it reaches your report. This is the lighter option, and we would rather describe it honestly than sell it as something it is not.
At a glance
- Typical duration
- 3 days to 1 week
- Coverage
- Broad, across many hosts or applications
- Exploitation
- Validation only, no chaining or impact demonstration
- Best for
- Between engagements, or large estates
- Retest
- Included
What we look for.
A vulnerability assessment enumerates weaknesses across a wide surface and confirms which ones are real. It does not chain them together, escalate privileges or demonstrate business impact. That is the honest boundary, and knowing it is what stops you buying the wrong thing.
What we test.
What you receive.
Risk posture in plain language for leadership and the board, with the two or three things that actually matter.
Severity, proof-of-concept evidence, reproduction steps and specific remediation, written for the engineer who has to fix it.
Findings mapped to SOC 2, ISO 27001, PCI DSS and HIPAA controls so your auditor can use the report directly.
A shareable letter confirming scope, dates and outcome, reissued free after we verify your fixes.
Who needs this.
- Large estates where testing everything deeply is not affordable
- Organisations wanting quarterly coverage between annual penetration tests
- Teams building a baseline before committing to a full engagement
- Businesses with an internal requirement for periodic scanning plus validation
Frequently asked.
Is this enough for our SOC 2 or customer security review?
Usually not. When an auditor or enterprise customer asks for evidence of security testing, they generally mean a penetration test. Ask them specifically, and if the answer is ambiguous, assume penetration test.
What is the real difference from a penetration test?
Depth and proof. An assessment tells you a vulnerability exists. A penetration test shows what an attacker achieves with it, which is what changes remediation priority.
Can we upgrade mid-engagement?
Yes. If an assessment surfaces something that clearly warrants exploitation, we will tell you, quote the difference and let you decide. We will not quietly expand scope.
How often should we run one?
Quarterly is common alongside an annual penetration test. If you ship weekly, more frequent coverage on the changing surface is worth more than a larger annual engagement.
Related services.
Your web application is your largest attack surface and the one your customers touch. We test it the way an attacker would: authenticated, unauthenticated, and everywhere your framework defaults do not reach.
SVC 03NetworkThe perimeter is one phishing email deep. We test what an attacker reaches from outside, and separately what they achieve once they are already inside.
Ready to find out what an attacker would find?
Tell us about your environment and we will come back with a scoped quote and a start date. No discovery-call marathon, no obligation.