What we check

  • Websites and web applications: known vulnerabilities, outdated software, misconfigurations, HTTPS and security headers.
  • Internet-facing systems: open ports and services, exposed admin panels, remote access (VPN, remote desktop), and email protection (SPF, DKIM, DMARC).
  • Cloud and office suites: the basic security settings of Microsoft 365, Google Workspace or AWS.

How we work

  • Written authorisation first. We agree and sign what will be scanned, when, and who to contact. Nothing outside it is touched.
  • Recognised tools, checked by a person. Scanners find candidates; every finding is verified by hand, so the report has no false alarms and no padding.
  • Safe by design. No exploitation, no attempts to access your data, no denial-of-service. Scans run at agreed times.

What you get

  • An executive summary in plain language.
  • A technical report: each confirmed finding with its severity (CVSS), evidence and how to fix it, ranked fix now, fix next, fix later.
  • A debrief call, and an optional rescan after you fix the issues.

How it differs from a penetration test

A vulnerability assessment finds and confirms weaknesses; it does not try to exploit them. For most small businesses it is the right first step. If you need a full penetration test, we will tell you, and arrange it with a qualified specialist.