What is a vulnerability scan?
A vulnerability scan is a systematic technical review of your IT infrastructure for known security weaknesses. It identifies unpatched software, insecure configurations, open ports, outdated protocols, and other attack surfaces — before attackers can exploit them.
Unlike a penetration test (which actively simulates attacks), a vulnerability scan remains non-invasive: it scans, identifies, and assesses — without compromising systems.
Why SMEs are particularly at risk
Cybercriminals have professionalized their methods. Today, most attacks are automated: bots constantly scan the internet for vulnerable systems. That means even a small trade business, a medical practice, or a social services organization is a potential target — not because of any particular attractiveness, but because a vulnerability was found in their firewall.
The most common entry points:
- Outdated software with known security vulnerabilities
- Weak or reused passwords
- Unpatched operating systems and applications
- Misconfigured firewalls and networks
- Missing multi-factor authentication
- Unsecured remote access (RDP, VPN)
What we analyze
External scan
We check your externally exposed systems: web servers, mail servers, VPN endpoints, remote access points. These systems are directly reachable from the internet and therefore particularly exposed.
Internal scan
Within the internal network, we check what risks exist once an attacker is already inside — whether through phishing, a compromised laptop, or an insider. This is about lateral movement: how far can an attacker spread through the network?
Configuration review
Alongside automated scans, we review manual configurations: are access permissions set correctly? Does software run with least privilege? Are backups actually stored separately and not co-encryptable?
CVSS assessment
Every vulnerability found is scored using the Common Vulnerability Scoring System (CVSS) — an internationally standardized scale from 0 to 10:
- Critical (9.0–10.0): immediate action required. Systems should potentially be isolated until remediated.
- High (7.0–8.9): urgent action required within a few days.
- Medium (4.0–6.9): remediation recommended within the next maintenance window.
- Low (0.1–3.9): remediate when convenient, no urgent action needed.
The remediation plan
The outcome of a vulnerability scan isn't a technical document that disappears into an archive. We deliver a prioritized, understandable remediation plan — equally readable for IT service providers and executive management:
- What was found?
- How critical is it?
- What needs to be done — specifically?
- By when should it be done?
After the identified vulnerabilities have been remediated, we conduct a follow-up scan on request to confirm the effectiveness of the measures.
Vulnerability scan vs. penetration test
| Vulnerability scan | Penetration test | |
|---|---|---|
| Method | Non-invasive, automated + manual | Active attack by experts |
| Goal | Identify vulnerabilities | Verify exploitability |
| Effort | Low to medium | High |
| Recommendation | Starting point, regular review | After ISMS implementation, before certification |
For most SMEs, a regular vulnerability scan (at least annually, ideally every six months) is a solid foundation. A full penetration test makes sense when particularly critical systems or data need protecting.
When is a vulnerability scan especially important?
- After onboarding a new IT service provider
- After introducing new software or systems
- Before ISO 27001 certification
- After a security incident
- As part of a regular security cycle (recommended: annually)
- For regulatory requirements (KRITIS, NIS2, GDPR Art. 32)