Service
Cybersecurity risk assessment
Four different things get sold under similar names at wildly different prices, and buying the wrong one is common. This page explains what each actually does, which one your situation calls for, and what you should expect to receive at the end.
Start here if you have never assessed
Scanning
not penetration testing
A test will confirm what a scan would have told you, at several times the cost.
Four things, often confused
| Type | Nature | Frequency |
|---|---|---|
| Vulnerability scanWhat is missing or misconfigured | Automated, frequent | Monthly or quarterly |
| Penetration testWhether findings are actually exploitable in your environment | Manual, scoped | Annually or on major change |
| Risk assessmentWhat matters to this business and in what order | Analytical | Annually, and after material change |
| Compliance gap reviewDistance from a named standard | Framework specific | Driven by the framework |
What you should receive
A report that lists 400 findings sorted by scanner severity is not an assessment, it is an export. These five make the difference.
- A findings register with severity, affected systems and a named owner per item
- Remediation effort estimated in hours or days, so it can be scheduled rather than admired
- An executive summary written for whoever holds the budget, in business language
- The raw scan output, because you own it and a future provider will want it
- A retest of anything remediated, so closure is verified rather than assumed
Severity is not priority
Scanners assign severity based on the vulnerability in isolation. Priority depends on your environment, and the two frequently disagree.
A critical rated flaw on an internal system unreachable from outside, behind segmentation, on a machine holding nothing sensitive, may be genuinely low priority. A medium rated misconfiguration on an internet facing service handling authentication may be the most urgent item on the list.
Reordering findings by actual risk to this business is the analytical work, and it is the part an automated tool cannot do. It is also the reason two assessments of the same environment can produce very different remediation plans.
Common questions
Answered before you ask.
Do we need a penetration test or a vulnerability scan?
Almost every business should be scanning regularly, and comparatively few need a penetration test annually. Scanning finds missing patches and misconfigurations, which is where the overwhelming majority of real risk lives at this scale. A penetration test tells you whether a skilled person can chain those findings into something serious, which is genuinely valuable but considerably more expensive. If you have never scanned, start there, because a test will simply confirm what a scan would have told you for a fraction of the cost.
How often should we assess?
Scanning monthly or quarterly, because the environment changes continuously and a scan is a snapshot. Risk assessment annually and after anything material: a new location, an acquisition, a significant system change or a new compliance obligation. Penetration testing annually where the risk profile or a contractual requirement justifies it, and otherwise on major change rather than on a calendar.
Will a scan disrupt our systems?
Standard scanning is passive enough that people rarely notice it, and it is normally scheduled outside business hours regardless. Certain older equipment, particularly industrial control systems and some medical devices, can respond badly to being probed, so those are identified during scoping and either excluded or tested with a gentler configuration.
What happens to the findings afterwards?
This is the question that separates a useful assessment from an expensive PDF. Findings go into the roadmap with owners and dates, high severity items are remediated immediately rather than scheduled, and remediation is retested to confirm closure. An assessment that produces a report nobody actions has converted a security budget into a filing cabinet.
Related
What sits alongside this.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Managed detection and response
24 by 7 human review of security alerts, with authority to contain.
IT compliance and risk
HIPAA, CMMC, PCI DSS and cyber insurance requirements.
Network and infrastructure
Firewalls, switching, Wi-Fi, servers and remote access, monitored.
How to choose an IT provider
The questions to ask, the red flags, and a scoring sheet.
Get findings you can actually schedule.
Every item comes with severity, an owner and an effort estimate, so remediation goes into a plan rather than into a drawer.