Setup
The scanner is installed, and zones, schedules and credentials for authenticated scanning are configured.
The first scan produces hundreds of findings, and that is often where it ends: the report lands in a folder. The value lies not in scanning but in what follows, namely which findings get fixed and in what order.
We do not just install a tool, we set up a working cycle: scan, assess, fix, scan again.
The scanner is installed, and zones, schedules and credentials for authenticated scanning are configured.
Everything visible from the internet: websites, mail server, VPN and firewall. These are scanned more often than internal assets.
Servers, PCs, network devices, printers and databases.
We combine the CVSS score with lists of vulnerabilities known to be exploited in the wild and with how exposed the system is in your environment.
Tasks with an owner and deadline, followed by a rescan once the work is done.
Is the number of findings falling, which ones have stayed open longest, and where is the bottleneck?
Expect the first round to need two or three weeks. From then on the scanner keeps its own calendar.
The first scan sets the starting point. It usually looks alarming, and that is perfectly normal.
We filter out the noise. A flaw on a locked-down internal box and the identical flaw on your public web server carry very different weight.
We close issues in priority order, starting with anything facing the internet and your critical systems.
Scheduled scans and follow-up. New vulnerabilities appear every month.
The metric that matters is not the number of findings but how long the dangerous ones stay open. Zero vulnerabilities is neither achievable nor necessary. What counts is that critical, internet-facing issues are fixed within days and the rest does not pile up. That figure is worth showing to management, and it also documents your vulnerability handling under NIS2.
Your own IT staff, or us under a support agreement. Either way, each ticket carries a named person and a due date, because findings nobody owns simply stay open.
A scanner finds known flaws. A manual penetration test finds logic errors and chains of weaknesses that automation misses. For webshops and customer portals, an annual manual test on top of scanning is worth it.
Not with careful configuration. Aggressive checks can crash old equipment, so production is scanned gently and heavier tests run in an agreed window.
Externally at least weekly, internally at least monthly. After major changes, or when CFCS or a vendor issues a critical warning, we run an extra scan.
Tell us about your infrastructure. We will run an initial scan and show you what to fix first.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.