Back to overview

Scan Service

Daily Vulnerability Scan Service

Continuous visibility of the external attack surface – with a clear assessment of what actually matters.

Automated scans run daily. A human still decides what actually matters.

The service covers FQDNs and IP addresses and all reachable services – web, mail, VPN, cloud, firewall, router, load balancer. No credentials, no changes to your IT environment, with minimal load on your systems.

Enlarged illustration for the scan service

Illustration of the daily vulnerability scan service

Situation

When an annual snapshot isn't enough.

For organisations that need to spot changes in their external attack surface early and handle them in a traceable way.

  1. 01

    Mid-sized companies with a manageable but business-critical internet presence, or public institutions with a documented review requirement.

  2. 02

    Over 60% of successful attacks exploit vulnerabilities for which a patch was already available at the time of the attack. If you don't continuously check internet-facing systems, these are exactly the vulnerabilities you miss.

  3. 03

    I make sure the systems reachable from outside are continuously reviewed and the findings are properly assessed.

Why this approach

Your public attack surface is checked every day.

All externally reachable systems and services are checked automatically every day for new vulnerabilities. So it doesn't take the next audit to notice that an update, a misconfiguration, or a newly published security flaw has become a risk.

If a vulnerability rated high or critical is detected, you're notified immediately with the full technical details: affected system, severity, possible impact and concrete guidance on remediation – including available vendor information and patch sources.

Don't check once a quarter. Know every day whether a door is open to the internet.

Process

Review daily

The scan service runs in the background: daily scans, immediate alerts on critical findings, and a monthly report with CVSS scoring and prioritised recommendations – with no credentials and no changes to your IT environment.

  1. 01

    Daily scans.

    Regular visibility of the reachable assets.

  2. 02

    Immediate alerts.

    Alerts when a finding should not wait for the monthly report.

  3. 03

    Monthly report.

    Condensed overview for follow-up and evidence.

  4. 04

    CVSS scoring.

    A consistent technical rating as a starting point.

  5. 05

    Recommendations.

    Prioritised next steps instead of an unfiltered list of findings.

  6. 06

    No intervention.

    No credentials and no changes to your IT.

Evidence

The press wanted to know if I'd really find something.

Put to the test by the press

In tests conducted with editorial teams, newsrooms gave me specific companies and public institutions and asked me to review their publicly reachable systems. Nearly all of them had vulnerabilities – some critical. The affected organisations were informed; selected cases were documented publicly by NZZ, 20 Minuten and Inside-IT.

The scan service turns that one-off test into a daily review.

The scan service supports ongoing technical evidence and documentation for, among others, NIS2, ISO 27001, TISAX, PCI-DSS and GDPR.

Contact

A short conversation is enough to clarify what matters.

Emailweb@innosec.ch LinkedIngunnar-porada