Pillar 02
A systematic sweep of everything you own, ranked by what it would actually cost you — breadth where a penetration test gives depth.
An assessment answers a different question to a penetration test. A test asks “can someone get in, and how far?” An assessment asks “what is exposed across everything we have, and what should we fix first?” Most businesses need the second before the first is worth commissioning.
What we check
The inventory is usually wrong. We establish what actually exists and answers on your networks — including the things nobody remembers deploying.
What each host is running, at which version, and whether that version is still supported by anyone.
Discovered software matched against published advisories, with the false positives stripped out by hand rather than left in the export.
Default credentials, permissive shares, weak TLS, unnecessary services and administrative interfaces facing the wrong way.
Reused, weak and previously breached passwords, checked without ever holding your users’ plaintext.
Every finding rated by exploitability and business impact, so remediation effort goes where it changes your exposure.
How it works
The ranges, domains and hosts in scope, agreed and signed before discovery begins.
Full enumeration of the authorised estate, building the inventory as it goes.
Automated findings are confirmed by hand. A scanner result nobody has verified is not a finding, it is a rumour.
A prioritised remediation plan, ordered so the first week of work removes the most risk.
What we usually find
Across assessments the same handful of exposures recur, almost regardless of the size of the business. None of them are exotic. All of them are the kind of thing that accumulates quietly when nobody is looking.
An operating system, database or framework past end of life, still in production because the application on top of it has never been touched. Unsupported means unpatched, permanently, and it is usually discovered only when someone goes looking.
Router, firewall, printer, NAS and hypervisor administration panels reachable from networks they were never meant to be reachable from. Frequently still carrying the credentials they shipped with.
Self-signed or long-expired certificates on internal services, which trains staff to click through warnings — and removes the one signal that would tell them an interception is happening.
Service accounts created for a migration finished years ago, contractors whose access was never revoked, and shared logins whose password is known to people who no longer work there.
What you get
What actually exists on your networks, which is regularly not what the asset register says.
Ordered by exploitability and business impact, not by a scanner’s default severity.
A list ordered so the first week of effort removes the largest share of exposure.
Automated findings are confirmed by hand before they reach you. A scanner result nobody verified is a rumour, not a finding.
A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.
Book a free callarrow_forward