Service · Cybersecurity

Vulnerability scanning

The first scan of a company network with a few dozen machines can produce hundreds of findings and a long PDF nobody has time to read. A scanner fixes nothing by itself. It becomes useful only when someone picks which holes are closed this week, names the person doing it and agrees how the result will be proven.

Outside
external scan
Inside
internal scan
KEV
exploited-in-the-wild first
Due date
on every fix

Included in this service

What we introduce is a working rhythm rather than a tool: scan, triage, patch, verify, repeat. Depending on scale and licensing we use Greenbone/OpenVAS, Tenable Nessus or Microsoft Defender Vulnerability Management, among others.

Talk the scope through with an engineer

Scanner setup

Network zones, schedules, maintenance windows and login details so the scanner can look inside hosts and spot missing patches, not merely open ports.

External surface

Anything an outsider can reach: website, online shop, mail server, VPN gateway, firewall admin panel, forgotten subdomains and old test servers.

Internal network

Servers, workstations, switches, printers, NAS boxes, CCTV recorders and production equipment with web panels.

Prioritisation

Each finding is ranked on its CVSS rating, its presence in the CISA KEV catalogue, its EPSS probability and how exposed that particular system is.

Remediation tasks

Every vulnerability gets an owner, a deadline and a description of the fix. When the task is closed, the scanner checks the host once more.

Metrics

Time to close critical findings, how large the backlog has grown and the systems that keep reappearing on the list each month.

How we work together

How long the first cycle takes depends on the size of the network. After that the process runs on the schedule set in the contract and you receive a short report.

01

Baseline

The first scan shows where you start from. The numbers look alarming, which is perfectly normal, since usually no one has measured this before.

02

Triage

The same flaw on an isolated test server and on the VPN gateway are two very different stories. We strip out noise and false positives.

03

Patching

We close gaps on internet-facing and business-critical systems first, then work our way down.

04

Cadence

Scans run to schedule, plus an extra one after warnings about vulnerabilities under active exploitation.

The number to watch is how long the dangerous findings stay open, not how many there are. Zero vulnerabilities does not exist. Critical flaws on public-facing systems should be gone within days, and the long tail must not keep growing for months. Put that figure in front of the board; it doubles as evidence of the vulnerability management expected from organisations covered by NIS2 and the Polish KSC act.

Questions and answers

A scanner looks for known software and configuration flaws, quickly and regularly. A penetration tester thinks like an attacker and uncovers logic errors, such as being able to view another customer's order in a web shop. Scanning is everyday hygiene; a pen test is a periodic exercise for your most important applications.

Your in-house IT person, or our administrators under a managed support contract. Fixes outside the contract are billed at PLN 190/hour excl. VAT. The key thing is a name and a date against every item, so nothing lingers as “something for IT”.

A badly tuned aggressive scan can hang an old printer or a controller on the shop floor. So production equipment gets a gentle profile, and heavier tests wait for a slot you approve, for instance early on a Saturday.

Sometimes the vendor has not released a fix, or the ERP insists on an outdated Java version. In that case we apply compensating controls: isolation in a separate network segment, a blocked port, an extra firewall rule. The exception is recorded with a justification and a review date.

Start regular vulnerability scanning

Give us a short outline of your infrastructure. After a first pass we point out which gaps deserve attention before anything else.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.