Services

Vulnerability Assessment Services for UK Businesses

We scan and manually review your internet-facing systems, internal network, cloud accounts and web applications, then hand you a ranked, de-duplicated list of what to fix first — with the false positives already removed.

SCOPE
External, Internal, Cloud & Web App
RANKING
CVSS + Real Exploitability
VERIFICATION
Human-Reviewed, False Positives Removed
RETEST
Free Retest Within 60 Days
In short

What is a vulnerability assessment?

A vulnerability assessment is a systematic review of your IT systems to identify known security weaknesses — missing patches, weak configurations, exposed services and poor access controls — and rank them by risk. Unlike a penetration test, it prioritises breadth of coverage over exploitation, producing a prioritised list of what to fix first.

What a vulnerability assessment covers

A vulnerability assessment answers a simple question: if someone went looking for a way into this business today, what would they find? To answer it properly we look from the outside in and from the inside out, because the two produce very different pictures. External scanning shows what is reachable from the public internet — your website, mail servers, VPN endpoints, remote desktop gateways and anything a previous supplier left exposed. Internal assessment shows what an attacker could reach once a single laptop is compromised, which is almost always far more than the business expects.

We combine automated scanning with manual review. Automated tools are excellent at breadth and terrible at judgement — they will flag hundreds of issues, many of which do not apply to your setup. A consultant reviews every medium-and-above finding, discards what is not genuinely exploitable in your environment, and explains the ones that are.

  • External attack surface — public IPs, domains, exposed services and forgotten hosts
  • Internal network — servers, workstations, printers, network devices and shares
  • Microsoft 365, Google Workspace, Azure and AWS configuration and identity settings
  • Web applications and APIs — OWASP Top 10 classes of weakness
  • Patch levels and end-of-life software still in production
  • Password policy, MFA coverage, privileged accounts and dormant users

Vulnerability assessment vs penetration testing

These two get used interchangeably in sales conversations, and they should not be. A vulnerability assessment is broad and non-destructive: it enumerates weaknesses across everything in scope and tells you which matter most. A penetration test is narrow and adversarial: a tester actively chains weaknesses together to prove what an attacker could actually achieve.

For most small and medium businesses the right sequence is vulnerability assessment first. There is limited value in paying someone to creatively break into a network that still has unpatched internet-facing services — you already know the answer. Fix the known weaknesses, then commission a penetration test to validate that your defences hold against a determined attacker.

  • Assessment answers "what is weak?" — testing answers "what can be done with it?"
  • Assessment covers everything in scope; testing goes deep on a defined target
  • Assessment is typically repeated quarterly; testing annually or after major change
  • Assessment is the cheaper and faster of the two, and the right first step

How we rank findings so you know what to do on Monday

A raw scanner report is close to useless to a business owner. Ours is ordered by the only thing that matters: what to do first. We take the technical severity, then adjust it for your context — is the affected system reachable from the internet, does it hold personal or payment data, is there a public exploit in circulation, is it listed in the CISA Known Exploited Vulnerabilities catalogue, and how hard is the fix?

The result is a short critical list, a medium-term list, and a backlog. Most clients clear the critical list within a fortnight. That is the point of the exercise.

  • Critical — exploitable from the internet, fix within days
  • High — exploitable with a foothold or valid credentials, fix within weeks
  • Medium — meaningful weakness requiring specific conditions, schedule it
  • Low / informational — hardening opportunities and good practice

Continuous assessment, not an annual snapshot

A one-off assessment is a photograph of a moving target. New vulnerabilities are published every day, and your own estate changes as staff join and leave, suppliers deploy things, and new SaaS tools get signed up for on a company card.

For clients who want ongoing assurance we run scheduled assessments — commonly monthly external scanning with a quarterly full internal review — and alert you between cycles when something newly published affects software you actually run. It costs a fraction of a full re-engagement and catches the drift.

  • Monthly external attack surface scanning with change alerts
  • Quarterly authenticated internal assessment
  • Out-of-cycle alerts when a critical vulnerability affects your stack
  • Trend reporting so you can show improvement over time to insurers and customers

What you receive

Every assessment produces three documents: a two-page executive summary a director can read and act on, a full technical findings report with evidence and reproduction steps, and a remediation tracker as a spreadsheet your IT provider can work through and tick off. We then walk you through all three on a call.

Sixty days later we retest everything you have fixed, free of charge, and reissue the report. That closing document is what you send to a customer, an insurer or a prospective client who has asked about your security posture.

What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Agreement Ready

Master Services Agreement (MSA)

The umbrella commercial agreement: scope, fees, IP, liability, confidentiality and termination. Work is ordered under Statements of Work.

UK Electronic Communications Act 2000 · eIDAS (EU) No 910/2014 · SHA-256 Verified

Request This Agreement →
Frequently asked questions

Vulnerability Assessment — your questions answered

How long does a vulnerability assessment take?
For a typical small business with under 100 devices, fieldwork takes two to four days and the report follows within a week. Larger or more complex estates are scoped individually. We agree the timeline in writing before starting.
Will the assessment disrupt our systems or take anything offline?
No. Vulnerability assessment is non-destructive by design — we identify weaknesses rather than exploiting them. Scanning is throttled and scheduled around your working hours, and we agree any sensitive or legacy systems with you in advance.
How often should a small business run a vulnerability assessment?
At minimum annually, and after any significant change such as a new office, a migration, or a new internet-facing application. Quarterly is the practical standard for businesses handling personal, health or payment data, with monthly external scanning between full assessments.
Do we need a vulnerability assessment for Cyber Essentials?
Cyber Essentials itself is a self-assessment questionnaire, and Cyber Essentials Plus adds a hands-on technical audit. A vulnerability assessment beforehand is the fastest way to find and fix the issues that would otherwise cause you to fail, which is why we usually run one first.
What is the difference between vulnerability scanning and a vulnerability assessment?
Scanning is the automated step that produces raw findings. An assessment is the full service: scanning, plus manual verification, false-positive removal, business-context risk ranking, remediation guidance and a retest. Scanning alone typically leaves you with hundreds of unranked items.
Can you assess our cloud accounts as well as our network?
Yes. Microsoft 365, Google Workspace, Azure and AWS are included as standard in scope discussions, because for most SMEs the cloud tenant now holds more sensitive data than the office network does.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about vulnerability assessment?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.