Skip to content

Service

Cybersecurity risk assessment

Four different things get sold under similar names at wildly different prices, and buying the wrong one is common. This page explains what each actually does, which one your situation calls for, and what you should expect to receive at the end.

Start here if you have never assessed

Scanning

not penetration testing

A test will confirm what a scan would have told you, at several times the cost.

Four things, often confused

Assessment types, what each reveals and how often to run it
TypeNatureFrequency
Vulnerability scanWhat is missing or misconfiguredAutomated, frequentMonthly or quarterly
Penetration testWhether findings are actually exploitable in your environmentManual, scopedAnnually or on major change
Risk assessmentWhat matters to this business and in what orderAnalyticalAnnually, and after material change
Compliance gap reviewDistance from a named standardFramework specificDriven by the framework

What you should receive

A report that lists 400 findings sorted by scanner severity is not an assessment, it is an export. These five make the difference.

  • A findings register with severity, affected systems and a named owner per item
  • Remediation effort estimated in hours or days, so it can be scheduled rather than admired
  • An executive summary written for whoever holds the budget, in business language
  • The raw scan output, because you own it and a future provider will want it
  • A retest of anything remediated, so closure is verified rather than assumed

Severity is not priority

Scanners assign severity based on the vulnerability in isolation. Priority depends on your environment, and the two frequently disagree.

A critical rated flaw on an internal system unreachable from outside, behind segmentation, on a machine holding nothing sensitive, may be genuinely low priority. A medium rated misconfiguration on an internet facing service handling authentication may be the most urgent item on the list.

Reordering findings by actual risk to this business is the analytical work, and it is the part an automated tool cannot do. It is also the reason two assessments of the same environment can produce very different remediation plans.

Common questions

Answered before you ask.

Do we need a penetration test or a vulnerability scan?

Almost every business should be scanning regularly, and comparatively few need a penetration test annually. Scanning finds missing patches and misconfigurations, which is where the overwhelming majority of real risk lives at this scale. A penetration test tells you whether a skilled person can chain those findings into something serious, which is genuinely valuable but considerably more expensive. If you have never scanned, start there, because a test will simply confirm what a scan would have told you for a fraction of the cost.

How often should we assess?

Scanning monthly or quarterly, because the environment changes continuously and a scan is a snapshot. Risk assessment annually and after anything material: a new location, an acquisition, a significant system change or a new compliance obligation. Penetration testing annually where the risk profile or a contractual requirement justifies it, and otherwise on major change rather than on a calendar.

Will a scan disrupt our systems?

Standard scanning is passive enough that people rarely notice it, and it is normally scheduled outside business hours regardless. Certain older equipment, particularly industrial control systems and some medical devices, can respond badly to being probed, so those are identified during scoping and either excluded or tested with a gentler configuration.

What happens to the findings afterwards?

This is the question that separates a useful assessment from an expensive PDF. Findings go into the roadmap with owners and dates, high severity items are remediated immediately rather than scheduled, and remediation is retested to confirm closure. An assessment that produces a report nobody actions has converted a security budget into a filing cabinet.

Get findings you can actually schedule.

Every item comes with severity, an owner and an effort estimate, so remediation goes into a plan rather than into a drawer.

CallFree assessment