AGIDAT – Datenschutz | Informationssicherheit

Vulnerability Scan & Security Analysis

Identify attack surfaces before attackers do — technical security analysis for SMEs.

What is a vulnerability scan?

A vulnerability scan is a systematic technical review of your IT infrastructure for known security weaknesses. It identifies unpatched software, insecure configurations, open ports, outdated protocols, and other attack surfaces — before attackers can exploit them.

Unlike a penetration test (which actively simulates attacks), a vulnerability scan remains non-invasive: it scans, identifies, and assesses — without compromising systems.

Why SMEs are particularly at risk

Cybercriminals have professionalized their methods. Today, most attacks are automated: bots constantly scan the internet for vulnerable systems. That means even a small trade business, a medical practice, or a social services organization is a potential target — not because of any particular attractiveness, but because a vulnerability was found in their firewall.

The most common entry points:

  • Outdated software with known security vulnerabilities
  • Weak or reused passwords
  • Unpatched operating systems and applications
  • Misconfigured firewalls and networks
  • Missing multi-factor authentication
  • Unsecured remote access (RDP, VPN)

What we analyze

External scan

We check your externally exposed systems: web servers, mail servers, VPN endpoints, remote access points. These systems are directly reachable from the internet and therefore particularly exposed.

Internal scan

Within the internal network, we check what risks exist once an attacker is already inside — whether through phishing, a compromised laptop, or an insider. This is about lateral movement: how far can an attacker spread through the network?

Configuration review

Alongside automated scans, we review manual configurations: are access permissions set correctly? Does software run with least privilege? Are backups actually stored separately and not co-encryptable?

CVSS assessment

Every vulnerability found is scored using the Common Vulnerability Scoring System (CVSS) — an internationally standardized scale from 0 to 10:

  • Critical (9.0–10.0): immediate action required. Systems should potentially be isolated until remediated.
  • High (7.0–8.9): urgent action required within a few days.
  • Medium (4.0–6.9): remediation recommended within the next maintenance window.
  • Low (0.1–3.9): remediate when convenient, no urgent action needed.

The remediation plan

The outcome of a vulnerability scan isn't a technical document that disappears into an archive. We deliver a prioritized, understandable remediation plan — equally readable for IT service providers and executive management:

  1. What was found?
  2. How critical is it?
  3. What needs to be done — specifically?
  4. By when should it be done?

After the identified vulnerabilities have been remediated, we conduct a follow-up scan on request to confirm the effectiveness of the measures.

Vulnerability scan vs. penetration test

Vulnerability scanPenetration test
MethodNon-invasive, automated + manualActive attack by experts
GoalIdentify vulnerabilitiesVerify exploitability
EffortLow to mediumHigh
RecommendationStarting point, regular reviewAfter ISMS implementation, before certification

For most SMEs, a regular vulnerability scan (at least annually, ideally every six months) is a solid foundation. A full penetration test makes sense when particularly critical systems or data need protecting.

When is a vulnerability scan especially important?

  • After onboarding a new IT service provider
  • After introducing new software or systems
  • Before ISO 27001 certification
  • After a security incident
  • As part of a regular security cycle (recommended: annually)
  • For regulatory requirements (KRITIS, NIS2, GDPR Art. 32)