Vulnerability Assessment
See what an attacker would see. We scan your website and the systems you expose to the internet, check every finding by hand to remove false alarms, and give you a clear, ranked plan to fix what matters.
What we check
- Websites and web applications: known vulnerabilities, outdated software, misconfigurations, HTTPS and security headers.
- Internet-facing systems: open ports and services, exposed admin panels, remote access (VPN, remote desktop), and email protection (SPF, DKIM, DMARC).
- Cloud and office suites: the basic security settings of Microsoft 365, Google Workspace or AWS.
How we work
- Written authorisation first. We agree and sign what will be scanned, when, and who to contact. Nothing outside it is touched.
- Recognised tools, checked by a person. Scanners find candidates; every finding is verified by hand, so the report has no false alarms and no padding.
- Safe by design. No exploitation, no attempts to access your data, no denial-of-service. Scans run at agreed times.
What you get
- An executive summary in plain language.
- A technical report: each confirmed finding with its severity (CVSS), evidence and how to fix it, ranked fix now, fix next, fix later.
- A debrief call, and an optional rescan after you fix the issues.
How it differs from a penetration test
A vulnerability assessment finds and confirms weaknesses; it does not try to exploit them. For most small businesses it is the right first step. If you need a full penetration test, we will tell you, and arrange it with a qualified specialist.