Услуга · Information security

Vulnerability scanners

The first run produces hundreds of findings, and that is usually where it ends: the report goes into a folder. The point is not the scan itself but what happens next - which findings are taken into work and in what order.

Schedule
not just once
Priority order
what to close first
Responsible people
for every task
Trend
progress is visible

What the work includes

What we introduce is not a program but a working cycle: scan, review, fix, verify.

Discuss the scope

Installation

We deploy the scanner and set the zones, the schedule and the credentials for authenticated scanning.

From outside

A check of what is visible from the internet. Done more often than the internal one.

Inside

Servers, workstations, network hardware, databases.

Screening

We cut out the theoretical and rank by the real danger to your infrastructure specifically.

Remediation

Tasks with owners and deadlines, and a re-check after the work is done.

Trend

Whether findings have fallen, which have been open longest, where the bottleneck is.

How it goes

The first cycle takes two to three weeks; after that the process runs itself to a schedule.

01

The first run

We obtain the baseline picture. It usually looks alarming, and that is normal.

02

Review

We separate what matters from the noise: the same finding on an isolated server and on a public one are different stories.

03

Work

We close them in turn, starting with the external perimeter and the critical systems.

04

Regularity

We set a schedule and a follow-up check: new vulnerabilities appear over a quarter.

The right metric is not the number of findings but the time to close the dangerous ones. Zero vulnerabilities is unattainable and unnecessary. What matters is that anything critical and reachable from outside is closed within days, and the rest does not pile up unchecked. That is the figure worth putting in front of management.

Questions and answers

Your administrators, or us under a support contract. What matters is that every task has a named owner and a deadline. A report with no assigned owners leads nowhere.

A scanner finds the known; a live test finds logic errors and unusual combinations. For sites with payments and user accounts it is worth bringing people in once a year in addition to the automation.

With careful configuration, no. Aggressive modes that test actual exploitation can knock over old equipment, so live systems are scanned gently and the heavy checks run in an agreed window.

We will start vulnerability scanning

Tell us about the infrastructure. We will do a first run and show what to close first.