Mapping entry points
We identify open ports, services and system versions, and investigate known vulnerabilities within the agreed part of your IT environment.
02 / VULNERABILITY ASSESSMENT
We examine agreed IT systems for technical weaknesses and test whether selected findings can be exploited. You get a clear view of risk and advice on what your IT team or service provider should prioritise.
Request a quoteFor businesses that need an up-to-date view of exposed systems, accessible services and known vulnerabilities, whether as an initial check or regular follow-up.
01 / SCOPE AND DELIVERABLES
We identify open ports, services and system versions, and investigate known vulnerabilities within the agreed part of your IT environment.
Web servers and services are examined for known weaknesses and insecure settings that could create opportunities for an attacker.
Selected findings are tested to assess whether they can actually be exploited. Active testing follows the scope and boundaries agreed in advance.
The report covers findings, severity, relevant CVE references and recommended actions. Critical findings are highlighted, with logs or screenshots where possible.
Daily, weekly or monthly scans with PDF reports can be arranged. The assessment is a snapshot of the agreed systems, and testing and reporting are treated confidentially.
HOW WE GET STARTED
We agree the systems, timing and boundaries for discovery and active testing.
Findings are examined and assessed against risk and potential consequences.
IT receives a basis for prioritising remediation. Further scans can be agreed.
02 / REGULATIONS AND DOCUMENTATION
Our assessment of how the service can support your work. Applicable requirements depend on your organisation and how the service is used.
Documented vulnerabilities can support risk assessment and the prioritisation of technical measures.
NSM guidanceResults can inform the evaluation of security measures around systems that process personal data.
GDPR, including Article 32Vulnerability assessments can form part of an entity’s risk-based testing programme and follow-up of findings.
DORA: testing and trainingThe service is not a certification or a guarantee of full compliance. The regulatory information is general guidance, not legal advice. Sources checked on 18 September 2026.
The service description covers discovery, analysis, controlled testing of selected weaknesses and reporting. The precise scope and level of active testing are agreed before starting.
The service description lists Nmap for discovery, Nikto for examining web services and Metasploit for controlled testing. The value for your business is understanding the findings and what needs to be fixed.
A CVE is a reference identifier for a publicly known vulnerability. It helps you find information about the weakness and relevant updates.
NEXT STEP / A NO-OBLIGATION CONVERSATION
Briefly describe the systems or services you would like assessed, and whether you need a one-off assessment or ongoing follow-up.
We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.