External surface
Everything that answers from the internet: web servers, mail gateways, remote access, services published long ago that nobody recalls. This is the part attackers look at first.
A scanner will happily produce four thousand lines against a mid-sized estate, and that is exactly where most programmes stall. The report circulates, nobody knows where to begin, and six months later the same file reappears with the same lines in it. Our work is not producing the list: it is cutting it down to what matters for you, putting a date against each item kept, then checking the fix actually landed everywhere, including on the server everyone had forgotten.
A scan does not replace a penetration test: it finds weaknesses that are already known and published, repeatably and without human input, which makes it the right tracking tool between two deeper examinations.
Everything that answers from the internet: web servers, mail gateways, remote access, services published long ago that nobody recalls. This is the part attackers look at first.
Servers, workstations, network gear and printers, with particular attention to systems whose support has ended and which nevertheless still do useful work every day.
Your sites, your extranet and your portals, modules and extensions included, since those versions usually age much faster than the platform hosting them.
Factory passwords, shares open to everyone, legacy protocols still enabled, outdated encryption on a certificate renewed out of habit year after year.
Each finding is put back in your context: a critical flaw on an isolated server with no route in from outside ranks below a medium weakness on the gateway your clients sign into.
We track each item to closure, with a date, an owner and a check at the next scan. This is the step one-off reports never cover.
Scans run outside production hours, and their intensity is adjusted for fragile systems that are better examined gently.
We agree the perimeter, the permitted time slots and which systems need careful handling, such as controllers or telephony servers.
The opening photograph. It is always heavier than expected, and comparing it with later ones tells you far more than its absolute size.
A short table: what gets fixed this week, what waits for the next maintenance window, and what you knowingly accept and why.
Scan, sort, fix, verify. After two or three cycles the curve comes down and the report can be read in ten minutes.
A severity score does not tell you whether it affects you. A top rating on a component you never enabled deserves less attention than a middling weakness on the portal where your clients upload documents. Sorting is always done with your context in mind: exposure, what data is reachable, and whether a workaround exists.
The risk is real on ageing systems or delicate industrial equipment, and very small on an ordinary estate. We begin in non-intrusive mode, exclude the machines you flag as fragile and schedule passes outside production hours.
A scan is automated, repeatable and hunts for weaknesses that have already been published. A penetration test is run by a person who chains several minor weaknesses together to reach a goal, as an attacker would. The two go together: a monthly scan and a test before a significant release.
The internet-facing perimeter deserves a monthly pass, because it changes by itself the moment a service is published. Internally, quarterly suits most companies. A significant warning relayed by CERT-FR obviously triggers a targeted pass outside the calendar.
Yes for anything within the systems we administer: patching, configuration, hardening. For line-of-business software the fix has to come from its vendor, and we prepare the technical request to send them, which saves three rounds of email.
A summary a board can read, the detailed technical list with public references, and the tracking table updated after each cycle. That table also serves as evidence when a client or an auditor asks how you handle vulnerabilities.
Tell us how many servers and machines you run, which sites face the internet and what rhythm would suit you. We will propose a scope and a cadence.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.