Secuwall
Assessment & Code Analysis

Vulnerability Assessment

Broad, repeatable coverage across the whole estate

A broad digital estate being mapped and assessed for prioritized validated exposures
Controlled security analysis

A vulnerability assessment and a penetration test answer different questions. A VA asks "where are we weak?" across everything you own; a pentest asks "can this specific weakness be exploited into a breach?" on a narrow path. The VA is broad, automated, and repeatable — which makes it the right instrument for routine hygiene, compliance cycles, and tracking whether your posture is improving over time. We validate the output and strip false positives before it reaches you.

Scope

What we cover.

  • Every in-scope asset across the digital estate
  • Credentialed or uncredentialed scanning, depending on objectives
  • Missing patches, misconfigurations, and end-of-life software
  • Findings correlated against CVE databases
  • False positive reduction and risk-based prioritization by our analysts
Methodology

How the engagement runs.

I

Introduction

A vulnerability assessment is a systematic process of identifying, quantifying, and prioritising the security weaknesses present across your network. It produces a comprehensive inventory of assets, the vulnerabilities attached to them, and the risk each one carries.

The goal is a prioritized, actionable report your IT and security teams can work from to reduce attack surface and make informed risk decisions.

Vulnerability assessment

Broad and largely automated — every asset gets a light scan. Comprehensive by design. Answers: what are our weaknesses?

Penetration testing

Narrow and manual — one path, actively proven through exploitation. Answers: can our weaknesses be used to cause a breach?

II

Assessment phases

1

Planning and scoping

  • Objectives — the driver for the assessment: routine hygiene, a compliance audit, a post-incident review, or evaluating a newly built network segment.
  • Scope — target segments documented and approved: IP ranges, VLANs, physical sites, or asset groups. Out-of-scope named explicitly, including industrial control systems, third-party equipment, and anything where a scan could cause operational failure. Those need special handling, not a default scan.
  • Scan type.
    • Uncredentialed — scanning from outside with no internal access, showing what an unauthenticated attacker sees: open ports, service versions, network-level issues
    • Credentialed — scanning with read-only credentials you supply. This is the recommended approach, because it surfaces the local vulnerabilities invisible from the network: missing OS patches, insecure local configuration, vulnerable installed software
  • Rules of engagement — an agreed testing window, scanner source addresses shared so you can whitelist them (otherwise your intrusion prevention blocks the scan and the assessment is incomplete), and a named contact for progress and issues.
2

Discovery and enumeration

  • Host discovery — sweeping the scoped ranges to identify every live host: servers, workstations, printers, routers, and the things nobody remembered were there.
  • Service enumeration — comprehensive TCP and UDP port scanning per host, mapping every running service.
  • Version detection — fingerprinting each service to its precise version and identifying the host operating system. This is what makes accurate matching against vulnerability databases possible.
3

Vulnerability scanning

  • Scan execution — commercial and open-source scanners run against the discovered assets, both credentialed and uncredentialed as scoped, with safe non-intrusive check policies in sensitive environments.
  • Data collection — each host and service tested against a large database of known vulnerabilities, common misconfigurations, and default credentials. The raw output routinely runs to thousands of potential issues, which is precisely why the next phase exists.
4

Validation and reporting

  • Data aggregation — results from every scan and segment consolidated into a single dataset.
  • False positive reduction — high-impact findings manually reviewed and validated. Scanners get it wrong, typically by reading a service banner when a backported patch has already been applied. We confirm through non-intrusive manual checks.
  • Correlation — identifying patterns and root causes. A hundred servers sharing a critical finding usually means one misconfiguration or one missing patch in a master image, not a hundred separate problems.
  • Risk assessment — technical severity alone is not risk. Each finding is contextualized.
    • Asset criticality — a medium-severity issue on a domain controller usually outranks a critical one on an isolated test box
    • Data sensitivity — does the system hold personal, financial, or proprietary data?
    • Exploitability — is there a simple public exploit available?
    • Impact — what actually happens to the business if it is exploited?
  • Executive summary — plain business language for management, with a risk heat map, key trends such as weak patch management, and the most critical risks stated clearly.
  • Technical report — a prioritized list of every validated vulnerability, each with description, affected IPs and hostnames, risk rating, evidence, and step-by-step remediation.
5

Remediation and re-scan

  • Debrief meeting to present the findings.
  • Support for your technical teams as they apply the fixes.
  • Targeted re-scan of the patched systems after the remediation window, verifying each issue is genuinely resolved.
Deliverables

What you get at the end.

Executive summary in plain business language, with risk heat maps and trends
Prioritized technical list of every validated vulnerability
Affected assets, evidence, risk ratings, and remediation steps
Re-scan verification

Who it's for

IT and security teams needing recurring hygiene coverage, compliance evidence, or a post-incident sweep.

Need a scope for this engagement?

Tell us what's in your environment and we'll come back with a scoped plan.

Talk to us