02 / VULNERABILITY ASSESSMENT

Find the weaknesses.
Set the right priorities.

We examine agreed IT systems for technical weaknesses and test whether selected findings can be exploited. You get a clear view of risk and advice on what your IT team or service provider should prioritise.

Request a quote
SUITABLE FOR

For businesses that need an up-to-date view of exposed systems, accessible services and known vulnerabilities, whether as an initial check or regular follow-up.

01 / SCOPE AND DELIVERABLES

From insight to action.

Read the service description (Norwegian) PDF ↗
01

Mapping entry points

We identify open ports, services and system versions, and investigate known vulnerabilities within the agreed part of your IT environment.

02

Checking web services

Web servers and services are examined for known weaknesses and insecure settings that could create opportunities for an attacker.

03

Controlled validation

Selected findings are tested to assess whether they can actually be exploited. Active testing follows the scope and boundaries agreed in advance.

04

A report you can use

The report covers findings, severity, relevant CVE references and recommended actions. Critical findings are highlighted, with logs or screenshots where possible.

Daily, weekly or monthly scans with PDF reports can be arranged. The assessment is a snapshot of the agreed systems, and testing and reporting are treated confidentially.

HOW WE GET STARTED

01

Agree the systems

We agree the systems, timing and boundaries for discovery and active testing.

02

Assess and evaluate

Findings are examined and assessed against risk and potential consequences.

03

Follow up

IT receives a basis for prioritising remediation. Further scans can be agreed.

02 / REGULATIONS AND DOCUMENTATION

Supporting your security work.

See requirements and scope

Our assessment of how the service can support your work. Applicable requirements depend on your organisation and how the service is used.

Requirements for organisations in scope

Norwegian Digital Security Act

Documented vulnerabilities can support risk assessment and the prioritisation of technical measures.

NSM guidance
Risk-appropriate requirements

GDPR / privacy

Results can inform the evaluation of security measures around systems that process personal data.

GDPR, including Article 32
Requirements for entities in scope

DORA

Vulnerability assessments can form part of an entity’s risk-based testing programme and follow-up of findings.

DORA: testing and training

Useful to know before we start.

Is this just an automated scan?

The service description covers discovery, analysis, controlled testing of selected weaknesses and reporting. The precise scope and level of active testing are agreed before starting.

Which tools are used?

The service description lists Nmap for discovery, Nikto for examining web services and Metasploit for controlled testing. The value for your business is understanding the findings and what needs to be fixed.

What is a CVE?

A CVE is a reference identifier for a publicly known vulnerability. It helps you find information about the weakness and relevant updates.

NEXT STEP / A NO-OBLIGATION CONVERSATION

Get a clearer view of your risk

Briefly describe the systems or services you would like assessed, and whether you need a one-off assessment or ongoing follow-up.

We agree needs, scope and pricing before starting.
An enquiry carries no obligation to purchase.

How can we help?

Choose a service and tell us a little about your needs.

I would like

Opens your email app with a draft to Eddie. Review it and send it yourself. This form does not store your details.