Vulnerability Assessment Services for UK Businesses
We scan and manually review your internet-facing systems, internal network, cloud accounts and web applications, then hand you a ranked, de-duplicated list of what to fix first — with the false positives already removed.
What is a vulnerability assessment?
A vulnerability assessment is a systematic review of your IT systems to identify known security weaknesses — missing patches, weak configurations, exposed services and poor access controls — and rank them by risk. Unlike a penetration test, it prioritises breadth of coverage over exploitation, producing a prioritised list of what to fix first.
What a vulnerability assessment covers
A vulnerability assessment answers a simple question: if someone went looking for a way into this business today, what would they find? To answer it properly we look from the outside in and from the inside out, because the two produce very different pictures. External scanning shows what is reachable from the public internet — your website, mail servers, VPN endpoints, remote desktop gateways and anything a previous supplier left exposed. Internal assessment shows what an attacker could reach once a single laptop is compromised, which is almost always far more than the business expects.
We combine automated scanning with manual review. Automated tools are excellent at breadth and terrible at judgement — they will flag hundreds of issues, many of which do not apply to your setup. A consultant reviews every medium-and-above finding, discards what is not genuinely exploitable in your environment, and explains the ones that are.
- External attack surface — public IPs, domains, exposed services and forgotten hosts
- Internal network — servers, workstations, printers, network devices and shares
- Microsoft 365, Google Workspace, Azure and AWS configuration and identity settings
- Web applications and APIs — OWASP Top 10 classes of weakness
- Patch levels and end-of-life software still in production
- Password policy, MFA coverage, privileged accounts and dormant users
Vulnerability assessment vs penetration testing
These two get used interchangeably in sales conversations, and they should not be. A vulnerability assessment is broad and non-destructive: it enumerates weaknesses across everything in scope and tells you which matter most. A penetration test is narrow and adversarial: a tester actively chains weaknesses together to prove what an attacker could actually achieve.
For most small and medium businesses the right sequence is vulnerability assessment first. There is limited value in paying someone to creatively break into a network that still has unpatched internet-facing services — you already know the answer. Fix the known weaknesses, then commission a penetration test to validate that your defences hold against a determined attacker.
- Assessment answers "what is weak?" — testing answers "what can be done with it?"
- Assessment covers everything in scope; testing goes deep on a defined target
- Assessment is typically repeated quarterly; testing annually or after major change
- Assessment is the cheaper and faster of the two, and the right first step
How we rank findings so you know what to do on Monday
A raw scanner report is close to useless to a business owner. Ours is ordered by the only thing that matters: what to do first. We take the technical severity, then adjust it for your context — is the affected system reachable from the internet, does it hold personal or payment data, is there a public exploit in circulation, is it listed in the CISA Known Exploited Vulnerabilities catalogue, and how hard is the fix?
The result is a short critical list, a medium-term list, and a backlog. Most clients clear the critical list within a fortnight. That is the point of the exercise.
- Critical — exploitable from the internet, fix within days
- High — exploitable with a foothold or valid credentials, fix within weeks
- Medium — meaningful weakness requiring specific conditions, schedule it
- Low / informational — hardening opportunities and good practice
Continuous assessment, not an annual snapshot
A one-off assessment is a photograph of a moving target. New vulnerabilities are published every day, and your own estate changes as staff join and leave, suppliers deploy things, and new SaaS tools get signed up for on a company card.
For clients who want ongoing assurance we run scheduled assessments — commonly monthly external scanning with a quarterly full internal review — and alert you between cycles when something newly published affects software you actually run. It costs a fraction of a full re-engagement and catches the drift.
- Monthly external attack surface scanning with change alerts
- Quarterly authenticated internal assessment
- Out-of-cycle alerts when a critical vulnerability affects your stack
- Trend reporting so you can show improvement over time to insurers and customers
What you receive
Every assessment produces three documents: a two-page executive summary a director can read and act on, a full technical findings report with evidence and reproduction steps, and a remediation tracker as a spreadsheet your IT provider can work through and tick off. We then walk you through all three on a call.
Sixty days later we retest everything you have fixed, free of charge, and reissue the report. That closing document is what you send to a customer, an insurer or a prospective client who has asked about your security posture.
Included in every engagement
Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.
Master Services Agreement (MSA)
The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.
UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified
Vulnerability Assessment — your questions answered
How long does a vulnerability assessment take?
Will the assessment disrupt our systems or take anything offline?
How often should a small business run a vulnerability assessment?
Do we need a vulnerability assessment for Cyber Essentials?
What is the difference between vulnerability scanning and a vulnerability assessment?
Can you assess our cloud accounts as well as our network?
Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.
You might also need
Ready to talk about vulnerability assessment?
Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.