External scan
Every public IP address and domain: firewall, VPN, mail server, website, web shop, customer portal. This is where hours count when a new flaw becomes public.
We scan what attackers find interesting and skip reports nobody reads.
Every public IP address and domain: firewall, VPN, mail server, website, web shop, customer portal. This is where hours count when a new flaw becomes public.
Servers, workstations, network gear, printers and NAS devices on the company network, with authenticated checks for more accurate results, plus agents on laptops that rarely visit the office.
Websites and shops checked for outdated plugins, missing security headers, exposed admin areas and known flaws in WordPress, Shopware or Magento.
Microsoft 365, Azure or AWS reviewed for risky settings such as public storage, admins without multi-factor or overly broad permissions.
Each finding is assessed for your environment: reachable or not, are exploits available, which data is at stake. The outcome is a few clear tasks instead of an endless list.
Findings become tickets, are passed to whoever owns the system and are rescanned. Once a month you get a brief overview of open items and the trend.
The first run usually uncovers the biggest legacy problems. After that the aim is to keep things clean for good.
A list of addresses, networks, websites and cloud tenants, coordination with hosts and software partners, scan windows outside core hours.
A full pass with ratings. Critical items go straight into remediation; typically these are missing updates and forgotten systems.
Monthly scans, plus a prompt targeted extra scan whenever CERT.at or a vendor issues a critical warning.
A short monthly summary for management and a technical list for the people doing the work. On request, also as evidence for a customer or insurer.
A report with 400 findings is not a security measure; it is something to file. Your business only becomes safer once the five genuinely dangerous holes are closed. So we measure success not by how many scans run, but by how long critical findings stay open.
Normally not. We scan outside core hours and treat fragile devices such as old printers or production controllers gently with adjusted settings, or leave them out on purpose.
A vulnerability scan is broad and automated, looking for known weaknesses on a regular and comparatively inexpensive basis. A penetration test goes deep: specialists deliberately try to chain flaws together and exploit them. Each complements the other.
We settle that beforehand. For systems we manage, we do it ourselves. For systems run by software partners or hosts, we pass on the finding with a recommendation and keep chasing.
NIS2 obliges entities in scope to manage risk, and handling vulnerabilities is part of that. The directive does not prescribe particular tools, but regular scans with documented remediation are an obvious and easily evidenced way to meet it.
Give us a rough idea of what should be scanned. We will suggest scope and frequency and tell you what the first run would focus on.
Your enquiry has arrived
Our reply reaches you within one working day. Outages that leave your staff unable to work are dealt with first.
We could not find that town. Try another spelling, or choose whichever provincial capital lies closest; as everything is handled remotely, you get the same service in all nine Austrian states.