Service · IT security

Vulnerability scans

Launching a vulnerability scan takes minutes. An hour later the tool produces a report with several hundred entries, colour-coded and sorted by score. In many companies nothing happens next, because nobody knows where to begin and half the entries concern servers looked after by the software partner. A few months on, the next report arrives listing the same issues. Our approach differs: the scan is the smallest part of the job. What matters is judging which weakness can actually be exploited in your environment, deciding who is responsible for fixing it, and having someone chase it until it is truly closed. A flaw in an internet-facing VPN gateway for which attack tools already circulate is more urgent than twenty medium findings on an internal test box. Warnings from CERT.at about actively exploited vulnerabilities feed into that judgement, just as vendor advisories do.

Monthly
internal and external, critical systems more often
Priority
by exploitability, not just by score
A ticket per finding
with an owner and a deadline
Rescan
as proof the fix worked

Everything this covers

We scan what attackers find interesting and skip reports nobody reads.

Settle the details with an engineer

External scan

Every public IP address and domain: firewall, VPN, mail server, website, web shop, customer portal. This is where hours count when a new flaw becomes public.

Internal scan

Servers, workstations, network gear, printers and NAS devices on the company network, with authenticated checks for more accurate results, plus agents on laptops that rarely visit the office.

Web scans

Websites and shops checked for outdated plugins, missing security headers, exposed admin areas and known flaws in WordPress, Shopware or Magento.

Cloud configuration

Microsoft 365, Azure or AWS reviewed for risky settings such as public storage, admins without multi-factor or overly broad permissions.

Rating and ranking

Each finding is assessed for your environment: reachable or not, are exploits available, which data is at stake. The outcome is a few clear tasks instead of an endless list.

Follow-up

Findings become tickets, are passed to whoever owns the system and are rescanned. Once a month you get a brief overview of open items and the trend.

Our working method

The first run usually uncovers the biggest legacy problems. After that the aim is to keep things clean for good.

01

Agree the scope

A list of addresses, networks, websites and cloud tenants, coordination with hosts and software partners, scan windows outside core hours.

02

First scan and clean-up

A full pass with ratings. Critical items go straight into remediation; typically these are missing updates and forgotten systems.

03

Routine operation

Monthly scans, plus a prompt targeted extra scan whenever CERT.at or a vendor issues a critical warning.

04

Reporting

A short monthly summary for management and a technical list for the people doing the work. On request, also as evidence for a customer or insurer.

A report with 400 findings is not a security measure; it is something to file. Your business only becomes safer once the five genuinely dangerous holes are closed. So we measure success not by how many scans run, but by how long critical findings stay open.

Frequently asked questions

Normally not. We scan outside core hours and treat fragile devices such as old printers or production controllers gently with adjusted settings, or leave them out on purpose.

A vulnerability scan is broad and automated, looking for known weaknesses on a regular and comparatively inexpensive basis. A penetration test goes deep: specialists deliberately try to chain flaws together and exploit them. Each complements the other.

We settle that beforehand. For systems we manage, we do it ourselves. For systems run by software partners or hosts, we pass on the finding with a recommendation and keep chasing.

NIS2 obliges entities in scope to manage risk, and handling vulnerabilities is part of that. The directive does not prescribe particular tools, but regular scans with documented remediation are an obvious and easily evidenced way to meet it.

Know which weaknesses really matter

Give us a rough idea of what should be scanned. We will suggest scope and frequency and tell you what the first run would focus on.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.