Vulnerability Scanning & Management

Security vulnerabilities are one of the greatest risks facing modern businesses. Our vulnerability scanning and management service helps you identify threats at an early stage, assess risks and continuously protect your systems – not as a one-off assessment, but as an ongoing process.

Request a serviceAll Services

Vulnerability Management

Procedure

automated and manually verified

Frequency

continuous & forward-looking

Coverage

Your entire IT landscape

Objective

Closed gaps rather than just identified ones

When the service is worth it

  • Between annual penetration tests, there is no visibility of newly emerging vulnerabilities.
  • New systems, applications or Cloud services are constantly being added without anyone systematically keeping track of them.
  • Patches are applied irregularly, usually only once a critical vulnerability has made the headlines.
  • An audit in accordance with ISO 27001, BSI Basic Protection or NIS2 requires evidence of an effective vulnerability management system.
  • There are too many systems to keep an overview of manually, and too little capacity to assess each report individually.
  • A scanner is already running, but nobody prioritises or follows up on the results consistently.

Bruce Schneier

“Security is not a product, but a process.”

Scanning is the start, not the end result

A vulnerability scanner identifies vulnerabilities, but does not fix them. This is precisely where Vulnerability Management most often fails in practice: there is an ongoing scan, but no reliable process for dealing with the findings. Actual risk mitigation takes place where vulnerabilities are patched, not where they are discovered.

That is why we deliberately separate two services that belong together:

Vulnerability scanning

Automated and manual tests to systematically and continuously identify vulnerabilities in your IT infrastructure.

vulnerability management

Development and implementation of a structured plan for risk minimisation: prioritisation, responsibilities, fixed cycles and follow-up until a vulnerability is actually resolved.

What we cover

The scope is tailored individually to your infrastructure – from individual critical systems to your entire IT landscape:

External Systems: Publicly accessible servers, web applications, network services, and client portals.
Internal Infrastructure: Corporate networks, servers, Active Directory environments, and internal workstations.
Web Applications & APIs: Continuous testing against known vulnerability patterns and the OWASP Top 10.
Cloud Environments: Configurations and exposed assets across hybrid architectures and cloud platforms.
Software Dependencies & CVEs: Outdated libraries, frameworks, and packages with publicly documented vulnerabilities.

How the process works

Reliable vulnerability management operates as a clearly structured, continuous control loop:

1

Scoping & Asset Mapping

We determine which systems are scanned and at what frequency, closely aligned with asset criticality and change velocity.

2

Continuous Scanning

Automated scans run on the agreed schedule, combined with manual validation to filter out false positives and ensure actionable findings.

3

Context-Aware Prioritization

Not every identified vulnerability carries the same urgency. We evaluate findings based on actual exploitability and risk within your specific infrastructure.

4

Remediation Tracking

We keep track of whether prioritized vulnerabilities are effectively resolved and escalate promptly if critical security gaps remain unpatched.

5

Reporting

Regular, concise reports on your current security posture—tailored for your engineering team, external audits, and executive management.

What’s in it for you

Proactively prevent attacks

Close security vulnerabilities, ideally before attackers can exploit them.

Ensuring compliance

Meet regulatory requirements (NIS2, ISO 27001, BSI) through regular, documented reviews.

Creating transparency

A clear, up-to-date picture of the security status of your IT landscape at all times – rather than an outdated snapshot.

Targeted use of resources

Focus on the truly critical and exploitable vulnerabilities – rather than unprioritised mountains of PDFs.

Systematically improving security levels

Through regular scanning and continuous Tracking, your progress in security becomes measurable and verifiable.

Scanning is not the same as a penetration test

A scan checks systems against a database of known vulnerabilities and provides a broad, continuous overview in a short space of time. It does not show whether a finding is actually exploitable or can be chained with other findings to form an attack path – that is what a manual penetration test achieves.

The two complement each other perfectly: scanning and management provide an ongoing view between two test dates, whilst the penetration test offers a more in-depth, manual assessment at regular intervals. Anyone who would also like to know what is actually visible from the outside before scanning begins will find a suitable starting point in our Attack Surface Analysis.

Vulnerability Scanning & Management

We check your systems at regular intervals. During the initial consultation, we clarify the scope and frequency.

  • Continuous monitoring rather than a one-off snapshot
  • Results manually verified – no sea of false positives
  • Prioritised according to actual risk
  • Tracked until the vulnerability is resolved

Results & Compliance

You will receive a structured final report containing our findings and prioritised recommended actions. This serves as robust evidence of:

NIS2: Full compliance with regulatory requirements for continuous vulnerability identification and remediation.
ISO 27001 (Control A.8.8): Mandates and validates effective technical vulnerability management.
BSI IT-Grundschutz: Verifiable proof of structured vulnerability and risk management practices.

Confidentiality & Data Protection

Every engagement is secured by a strict Non-Disclosure Agreement (NDA).
Hosting and processing of scan data takes place exclusively in German, ISO 27001-certified data centers.
Full GDPR compliance and permanent, secure deletion of all project data upon completion.

Research & Best Practices

We conduct our own security research and publish our findings as part of responsible disclosure processes (e.g. vulnerabilities in federal systems, Path Traversal in monitoring software).

Case Study: From Scan to Resolution

  • Initial situation: A medium-sized e-commerce provider had hundreds of unfiltered scanner reports, without knowing which vulnerabilities posed a genuine risk.
  • Approach: Introduction of continuous scanning with automated pre-filtering and manual context assessment by our analysts.
  • Result: The action list was reduced to 8 genuinely critical vulnerabilities, which were rectified within 48 hours. Follow-up is now an integral part of the monthly cycle.

Frequently Asked Questions

Answers to the most frequently asked questions about our Vulnerability Scanning and Management Service.

No. Scanning detects known, automatically recognisable patterns. The manual penetration test also checks whether the findings can actually be exploited and chained together. The two complement each other perfectly.

The task of patching the vulnerabilities falls to your team or your service provider. We provide the prioritised list and follow up to ensure this has been done, provided this is included in the scope of services.

We determine this together during the scoping phase, depending on the criticality of the systems and the rate of change in your environment. Critical, externally accessible systems are usually checked more frequently than internal peripheral systems.

We report critical findings immediately and out of turn, regardless of the regular reporting cycle.

We manually verify automated hits before they are added to your prioritised list, so that you do not waste time on false positives.