Verified Scans

Visibility into real risks and clear priorities

Talk to an expert WhatsApp
Services / Vulnerability Assessment with manual verification (VA)
Defensive Services

Vulnerability Assessment (VA)

The Vulnerability Assessment service provided by ISGroup is designed to analyze and evaluate system security in order to identify known vulnerabilities.

The activity can be carried out externally or internally. In an external Vulnerability Assessment, scanning is performed from a remote host that can access the system only through the Internet.

In the second case, scanning is performed from inside the private network (Intranet), providing greater visibility into the system under review.

These two configurations simulate different attack scenarios: the first simulates an attack by an external attacker, such as an unfair business competitor; the second simulates an internal threat or compromised account, such as a disgruntled employee or a ransomware attack.

After the scanning phase, all identified vulnerabilities are reviewed to eliminate false positives. For each confirmed vulnerability, we provide a detailed description and, most importantly, precise information on how to remediate it.

Given the high number of new vulnerabilities discovered every day, it is essential to perform Vulnerability Assessment with the right frequency to ensure that system configurations remain correct and the appropriate security patches are applied.

ISGroup provides Vulnerability Assessment solutions suited to organizations of any size and requirement, while maintaining a high quality standard.

Description

A Vulnerability Assessment begins with the identification of systems and resources made available for testing, such as services and web applications. Then, using automated tools and manual testing, known security issues are identified in a non-invasive way. Vulnerability Assessments make it possible to quickly understand the security level of a network.

Identification is performed through active techniques, such as version numbers sent by services in their responses, passive techniques, or inference-based techniques, relying on characteristics that software has and cannot hide. Results are manually verified to eliminate false positives and produce a compact and detailed report for both Management and the operational staff responsible for remediation.

Output

The report is a simple and detailed document that summarizes the results of the activity and is divided into three different areas:

Executive Summary
Placed at the beginning of the report and no longer than one page, this is the high-level summary intended for Management.

Vulnerability Details
The technical section describing the identified vulnerabilities and their impact in detail, intended for the Security Manager.

Remediation Plan
A technical section with precise instructions on how to fix the identified issues, intended for the System Administrator.

Frequently asked questions about
Vulnerability Assessment

How long does a Vulnerability Assessment take?

The duration is determined by the number and type of assets, such as servers, network services, applications and devices, and whether the assessment is internal or external. Before starting, we define the assessment scope together so that activities, timing and costs can be estimated accurately.

Can a Vulnerability Assessment cause service disruptions?

ISGroup uses non-invasive techniques to minimize the impact on systems. Multi-tool scans performed with open-source and commercial solutions are manually verified by specialists to remove false positives and provide results the IT team can act on.

Are credentials or specific prerequisites required?

An external assessment examines Internet-facing systems, while an internal assessment is performed from the private network and provides greater visibility. In some scenarios, credentials or agreed access methods increase the depth of the analysis. The essential prerequisite is a precise scope covering systems, IP addresses, applications and operating procedures.

What is the difference between a Vulnerability Assessment and a Penetration Test?

A Vulnerability Assessment systematically identifies known vulnerabilities, misconfigurations and outdated systems. A Network Penetration Test and a Web Application Penetration Test simulate real attack techniques to determine how far a vulnerability can actually be exploited. In short, the first asks "what vulnerabilities are present?", while the penetration tests ask "what could an attacker do by exploiting them?". For a broader overview, read our in-depth guide to Vulnerability Assessment.

How often should a Vulnerability Assessment be performed?

We recommend a Vulnerability Assessment at least once a year and after significant changes to systems, applications or configurations. Critical or exposed infrastructure should be assessed more frequently or monitored through an ongoing Vulnerability Management service.

How much does a Vulnerability Assessment cost?

The quote considers the number of IP addresses, systems and services, internal and external infrastructure, asset types, assessment depth and any recurring scans. Once the scope is defined, we can quickly specify activities, timing and assessment cost, avoiding insufficient or unnecessary work.

How are the assessment results handled?

The report describes potential infrastructure weaknesses and is treated as confidential documentation. ISGroup operates under an ISO/IEC 27001-certified Information Security Management System that also covers Vulnerability Assessment activities.

What does the final report contain?

The report includes an Executive Summary for management, Vulnerability Details covering confirmed issues and their impact, and a Remediation Plan with corrective or mitigation actions. Results are manually verified to remove false positives and help the IT team understand what to fix and in which order.

How can I tell whether my company needs a Vulnerability Assessment?

It is useful for finding known vulnerabilities, outdated software, risky configurations or exposed services, especially after infrastructure changes, new systems, migrations or a long period without testing. If the right scope is not yet clear, ISGroup can define it with you based on your infrastructure and objective.

We've worked with

Nestle UBI Banca Libero Mediaset Repubblica Italiana Subito

The experience with ISGroup has made us grow as an organization, increasing awareness of cyber risks and skills to manage secure IT systems. We appreciated competence, autonomy, quality of reports and a truly customer-oriented approach.

Giampietro Calabrese
Giampietro Calabrese

Add Value S.r.l.

An accurate analysis allowed us to quickly identify and correct some internal vulnerabilities. The clear and concrete report helped us optimize processes and strengthen the overall security of the platform.

Gabriele di Edoardo
Gabriele di Edoardo

Alias Group S.r.l.

Thanks to ISGroup SRL support we have consolidated an Integrated Management System compliant with international standards. Technical skills and targeted training have improved development processes, product security and audit management.

Stefano Luzi Crivellini
Stefano Luzi Crivellini

Creactives S.p.A.

Working with us is pretty simple, just call the number or send an e-mail so that we can get to know each other and discuss about your IT Security needs.

Request a quotation for
Vulnerability Assessment (VA)

🎉 We want to talk to you! Book an appointment!