Vulnerability Assessment

Vulnerability assessment is the periodic sweep of your entire surface: what is exposed, at which version and which known flaws it carries. It does not replace a penetration test, but it is what stops someone walking in through a flaw published eight months ago — which is how most intrusions happen.

The problem is not finding, it is deciding

Any tool returns thousands of findings. The work is separating the thirty that matter from the three thousand that do not, and a scanner cannot do that: someone who understands your architecture can.
Real exploitability: a vulnerability with a public exploit and active exploitation is not the same as a theoretical one nobody has managed to reproduce.
Exposure: the same flaw on an internet-facing server and on a machine in a segmented network with no egress do not deserve the same urgency.
Asset criticality: the generic score does not know which of your servers bills customers and which hosts the internal noticeboard.
False positives: we review them before anything reaches you. A report full of noise gets ignored entirely, and that is worse than not having one.

What we cover

External perimeter: everything published, including the asset someone spun up for a test and never switched off.
Internal network: servers, workstations, network devices and printers, which remain a routine entry point.
Web applications and APIs, with manual verification of the relevant findings.
Cloud and containers: images, service configuration and permissions.
Configuration: not just patches, but unnecessary services, obsolete ciphers and default credentials.

How we work

1
Inventory
First you have to know what is there. In almost every organisation, assets turn up that were on nobody’s list.
2
Sweep
Authenticated wherever possible, because an unauthenticated scan sees a fraction of what exists.
3
Manual triage
We review false positives and manually verify what deserves verification. Half the noise falls away here.
4
Prioritisation
Every finding is ordered by exploitability, exposure and asset criticality, not by the out-of-the-box score.
5
Remediation plan
Grouped by action rather than by finding: a single patch usually closes dozens of lines in the report.
6
Tracking
Comparison against the previous sweep, to see whether technical debt is falling or just moving.

What you get

Inventory of detected assets and services.
Prioritised report with triaged findings and the reasoning behind the ranking.
Remediation plan grouped by action and effort.
Comparison against the previous assessment, to measure improvement.
Executive summary showing the trend on a single page.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

Does this replace a penetration test?
No. Vulnerability assessment tells you which known flaws you carry; a penetration test shows how far someone gets by chaining them, and finds what no tool detects, such as business logic flaws. They complement each other: frequent sweeps, periodic pentests.
How often?
Monthly or quarterly for the external perimeter, quarterly or half-yearly for internal. What matters is the series: one sweep is a snapshot, twelve are a trend.
Can you do it without credentials?
We can, but you will see much less. Authenticated assessment detects outdated software and configurations that are invisible from outside. If the goal is to simulate an external attacker’s view, then unauthenticated makes sense.
Does it count for compliance?
Yes. The ENS, ISO 27001, PCI DSS and NIS2 all require documented vulnerability management. The report and the trend serve as evidence for the auditor.
Start by knowing what you have exposed
Half an hour with an auditor to agree the scope and the frequency that suits you, without paying for sweeps you cannot act on.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
ENES