SECOMPSSECOMPS
Home/Services/Vulnerability Assessment
SVC 07

Vulnerability assessment.

Broad coverage across a large estate, with every finding manually validated before it reaches your report. This is the lighter option, and we would rather describe it honestly than sell it as something it is not.

At a glance

Typical duration
3 days to 1 week
Coverage
Broad, across many hosts or applications
Exploitation
Validation only, no chaining or impact demonstration
Best for
Between engagements, or large estates
Retest
Included
01Overview

What we look for.

A vulnerability assessment enumerates weaknesses across a wide surface and confirms which ones are real. It does not chain them together, escalate privileges or demonstrate business impact. That is the honest boundary, and knowing it is what stops you buying the wrong thing.

02Coverage

What we test.

Automated discoveryHost, service and application enumeration across the agreed scope, including assets you may have forgotten.
Manual validationEvery reported finding confirmed by a human, because unvalidated scanner output wastes more engineering time than it saves.
False positive removalThe noise stripped out before it reaches your backlog, with a note on why each was discarded.
Severity and prioritisationRanked by exploitability and business context rather than raw CVSS score.
Patch and configuration guidanceSpecific remediation per finding, with the fix that actually closes it rather than a generic reference.
Coverage reportWhat was in scope, what was reachable, and explicitly what was not tested.
03Deliverables

What you receive.

01Executive summary

Risk posture in plain language for leadership and the board, with the two or three things that actually matter.

02Technical findings

Severity, proof-of-concept evidence, reproduction steps and specific remediation, written for the engineer who has to fix it.

03Compliance annex

Findings mapped to SOC 2, ISO 27001, PCI DSS and HIPAA controls so your auditor can use the report directly.

04Attestation letter

A shareable letter confirming scope, dates and outcome, reissued free after we verify your fixes.

04Fit

Who needs this.

  • Large estates where testing everything deeply is not affordable
  • Organisations wanting quarterly coverage between annual penetration tests
  • Teams building a baseline before committing to a full engagement
  • Businesses with an internal requirement for periodic scanning plus validation
05Questions

Frequently asked.

Is this enough for our SOC 2 or customer security review?

Usually not. When an auditor or enterprise customer asks for evidence of security testing, they generally mean a penetration test. Ask them specifically, and if the answer is ambiguous, assume penetration test.

What is the real difference from a penetration test?

Depth and proof. An assessment tells you a vulnerability exists. A penetration test shows what an attacker achieves with it, which is what changes remediation priority.

Can we upgrade mid-engagement?

Yes. If an assessment surfaces something that clearly warrants exploitation, we will tell you, quote the difference and let you decide. We will not quietly expand scope.

How often should we run one?

Quarterly is common alongside an annual penetration test. If you ship weekly, more frequent coverage on the changing surface is worth more than a larger annual engagement.

Ready to find out what an attacker would find?

Tell us about your environment and we will come back with a scoped quote and a start date. No discovery-call marathon, no obligation.