Service · Cybersecurity

Vulnerability scanning

A scanner will happily produce four thousand lines against a mid-sized estate, and that is exactly where most programmes stall. The report circulates, nobody knows where to begin, and six months later the same file reappears with the same lines in it. Our work is not producing the list: it is cutting it down to what matters for you, putting a date against each item kept, then checking the fix actually landed everywhere, including on the server everyone had forgotten.

Monthly
or quarterly, depending on the estate
Sorting
by real exposure, not raw score
CERT-FR
bulletins watched between scans
Open items
a list that empties

Where this service reaches

A scan does not replace a penetration test: it finds weaknesses that are already known and published, repeatably and without human input, which makes it the right tracking tool between two deeper examinations.

Put your scope to an engineer

External surface

Everything that answers from the internet: web servers, mail gateways, remote access, services published long ago that nobody recalls. This is the part attackers look at first.

Internal network

Servers, workstations, network gear and printers, with particular attention to systems whose support has ended and which nevertheless still do useful work every day.

Web applications

Your sites, your extranet and your portals, modules and extensions included, since those versions usually age much faster than the platform hosting them.

Weak configuration

Factory passwords, shares open to everyone, legacy protocols still enabled, outdated encryption on a certificate renewed out of habit year after year.

Prioritising

Each finding is put back in your context: a critical flaw on an isolated server with no route in from outside ranks below a medium weakness on the gateway your clients sign into.

Following fixes through

We track each item to closure, with a date, an owner and a check at the next scan. This is the step one-off reports never cover.

The way an engagement runs

Scans run outside production hours, and their intensity is adjusted for fragile systems that are better examined gently.

01

Scoping

We agree the perimeter, the permitted time slots and which systems need careful handling, such as controllers or telephony servers.

02

First pass

The opening photograph. It is always heavier than expected, and comparing it with later ones tells you far more than its absolute size.

03

Treatment plan

A short table: what gets fixed this week, what waits for the next maintenance window, and what you knowingly accept and why.

04

Regular cycle

Scan, sort, fix, verify. After two or three cycles the curve comes down and the report can be read in ten minutes.

A severity score does not tell you whether it affects you. A top rating on a component you never enabled deserves less attention than a middling weakness on the portal where your clients upload documents. Sorting is always done with your context in mind: exposure, what data is reachable, and whether a workaround exists.

Questions and answers

The risk is real on ageing systems or delicate industrial equipment, and very small on an ordinary estate. We begin in non-intrusive mode, exclude the machines you flag as fragile and schedule passes outside production hours.

A scan is automated, repeatable and hunts for weaknesses that have already been published. A penetration test is run by a person who chains several minor weaknesses together to reach a goal, as an attacker would. The two go together: a monthly scan and a test before a significant release.

The internet-facing perimeter deserves a monthly pass, because it changes by itself the moment a service is published. Internally, quarterly suits most companies. A significant warning relayed by CERT-FR obviously triggers a targeted pass outside the calendar.

Yes for anything within the systems we administer: patching, configuration, hardening. For line-of-business software the fix has to come from its vendor, and we prepare the technical request to send them, which saves three rounds of email.

A summary a board can read, the detailed technical list with public references, and the tracking table updated after each cycle. That table also serves as evidence when a client or an auditor asks how you handle vulnerabilities.

Find out what is exposed at your end

Tell us how many servers and machines you run, which sites face the internet and what rhythm would suit you. We will propose a scope and a cadence.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.