automated and manually verified
Vulnerability Scanning & Management
Security vulnerabilities are one of the greatest risks facing modern businesses. Our vulnerability scanning and management service helps you identify threats at an early stage, assess risks and continuously protect your systems – not as a one-off assessment, but as an ongoing process.
Request a serviceAll ServicesVulnerability Management
Procedure
Frequency
continuous & forward-looking
Coverage
Your entire IT landscape
Objective
Closed gaps rather than just identified ones
When the service is worth it
- Between annual penetration tests, there is no visibility of newly emerging vulnerabilities.
- New systems, applications or Cloud services are constantly being added without anyone systematically keeping track of them.
- Patches are applied irregularly, usually only once a critical vulnerability has made the headlines.
- An audit in accordance with ISO 27001, BSI Basic Protection or NIS2 requires evidence of an effective vulnerability management system.
- There are too many systems to keep an overview of manually, and too little capacity to assess each report individually.
- A scanner is already running, but nobody prioritises or follows up on the results consistently.
Bruce Schneier
“Security is not a product, but a process.”
Scanning is the start, not the end result
A vulnerability scanner identifies vulnerabilities, but does not fix them. This is precisely where Vulnerability Management most often fails in practice: there is an ongoing scan, but no reliable process for dealing with the findings. Actual risk mitigation takes place where vulnerabilities are patched, not where they are discovered.
That is why we deliberately separate two services that belong together:
Vulnerability scanning
Automated and manual tests to systematically and continuously identify vulnerabilities in your IT infrastructure.
vulnerability management
Development and implementation of a structured plan for risk minimisation: prioritisation, responsibilities, fixed cycles and follow-up until a vulnerability is actually resolved.
What we cover
The scope is tailored individually to your infrastructure – from individual critical systems to your entire IT landscape:
How the process works
Reliable vulnerability management operates as a clearly structured, continuous control loop:
Scoping & Asset Mapping
We determine which systems are scanned and at what frequency, closely aligned with asset criticality and change velocity.
Continuous Scanning
Automated scans run on the agreed schedule, combined with manual validation to filter out false positives and ensure actionable findings.
Context-Aware Prioritization
Not every identified vulnerability carries the same urgency. We evaluate findings based on actual exploitability and risk within your specific infrastructure.
Remediation Tracking
We keep track of whether prioritized vulnerabilities are effectively resolved and escalate promptly if critical security gaps remain unpatched.
Reporting
Regular, concise reports on your current security posture—tailored for your engineering team, external audits, and executive management.
What’s in it for you
Proactively prevent attacks
Close security vulnerabilities, ideally before attackers can exploit them.
Ensuring compliance
Meet regulatory requirements (NIS2, ISO 27001, BSI) through regular, documented reviews.
Creating transparency
A clear, up-to-date picture of the security status of your IT landscape at all times – rather than an outdated snapshot.
Targeted use of resources
Focus on the truly critical and exploitable vulnerabilities – rather than unprioritised mountains of PDFs.
Systematically improving security levels
Through regular scanning and continuous Tracking, your progress in security becomes measurable and verifiable.
Scanning is not the same as a penetration test
A scan checks systems against a database of known vulnerabilities and provides a broad, continuous overview in a short space of time. It does not show whether a finding is actually exploitable or can be chained with other findings to form an attack path – that is what a manual penetration test achieves.
The two complement each other perfectly: scanning and management provide an ongoing view between two test dates, whilst the penetration test offers a more in-depth, manual assessment at regular intervals. Anyone who would also like to know what is actually visible from the outside before scanning begins will find a suitable starting point in our Attack Surface Analysis.
Vulnerability Scanning & Management
We check your systems at regular intervals. During the initial consultation, we clarify the scope and frequency.
- Continuous monitoring rather than a one-off snapshot
- Results manually verified – no sea of false positives
- Prioritised according to actual risk
- Tracked until the vulnerability is resolved
Results & Compliance
You will receive a structured final report containing our findings and prioritised recommended actions. This serves as robust evidence of:
Confidentiality & Data Protection
Research & Best Practices
We conduct our own security research and publish our findings as part of responsible disclosure processes (e.g. vulnerabilities in federal systems, Path Traversal in monitoring software).
Case Study: From Scan to Resolution
- Initial situation: A medium-sized e-commerce provider had hundreds of unfiltered scanner reports, without knowing which vulnerabilities posed a genuine risk.
- Approach: Introduction of continuous scanning with automated pre-filtering and manual context assessment by our analysts.
- Result: The action list was reduced to 8 genuinely critical vulnerabilities, which were rectified within 48 hours. Follow-up is now an integral part of the monthly cycle.
Frequently Asked Questions
Answers to the most frequently asked questions about our Vulnerability Scanning and Management Service.
Does this replace an annual penetration test?
No. Scanning detects known, automatically recognisable patterns. The manual penetration test also checks whether the findings can actually be exploited and chained together. The two complement each other perfectly.
Who closes the identified vulnerabilities?
The task of patching the vulnerabilities falls to your team or your service provider. We provide the prioritised list and follow up to ensure this has been done, provided this is included in the scope of services.
How often are scans carried out?
We determine this together during the scoping phase, depending on the criticality of the systems and the rate of change in your environment. Critical, externally accessible systems are usually checked more frequently than internal peripheral systems.
What happens if a scan reveals a critical finding?
We report critical findings immediately and out of turn, regardless of the regular reporting cycle.
Are false positives also reported to us?
We manually verify automated hits before they are added to your prioritised list, so that you do not waste time on false positives.

