Skip to main content
GullySystem

Vulnerability Assessment: Finding and Ranking Known Weaknesses

A broad, structured scan of your applications, servers and network for known weaknesses, delivered as a ranked list rather than a raw export. GullySystem runs it as a standalone check or as the first step before deeper testing.

What a Vulnerability Assessment Is

This is breadth work: systems are checked against known issues — outdated software versions, missing patches, weak configurations, exposed services — and every result is ranked by what it would actually mean for your business rather than left as a raw tool output. It is not an attempt to break into anything, which is what separates it from a penetration test.

What It Usually Turns Up

  • Software running a version with a publicly known weakness that was never updated after go-live
  • A server or service reachable from the internet that nobody remembers turning on
  • Default settings left in place because nobody changed them after installation
  • A previous scan report with hundreds of items and no order of importance, sitting unopened in a folder

What's Covered in the Assessment

External Exposure Scan

Everything reachable from outside your office or data centre, mapped and checked against known issues.

Internal Systems Review

Servers, workstations and network devices checked from inside your environment, where access is agreed in advance.

Patch and Version Checks

Software and services compared against current versions to flag what has fallen behind.

Business-Ranked Results

Every finding written with what it would mean for your business, not only its technical severity.

Vulnerability Assessment vs Penetration Testing

  • A vulnerability assessment lists what could be a problem, across a wide surface, quickly
  • A penetration test picks specific items and tries to actually exploit them, to prove what a real attacker could do
  • Most businesses run an assessment first and use it to decide whether — and where — deeper penetration testing is worth the spend

How Often to Run One

Software and infrastructure both drift over time as patches lapse and configurations change, so a single assessment is a snapshot rather than a standing guarantee. Many businesses repeat it on a schedule tied to their release cycle or after any significant infrastructure change, rather than only once before an audit.

FAQ

Frequently asked questions

Is a vulnerability assessment the same as a penetration test?

No. An assessment finds and ranks known weaknesses across a wide set of systems. A penetration test takes specific findings and attempts to actually exploit them by hand, inside an agreed scope, to prove real-world impact. Many engagements run an assessment first and use it to scope a penetration test where one is warranted.

Is our business too small for this to be useful?

If you run any system reachable from the internet — a website, an API, a remote-access server — the assessment is still useful, since automated attacks scan indiscriminately regardless of company size. If everything you run sits behind a single office network with no public-facing service, the value is smaller and we will tell you so.

What determines the price of the scan?

The number of systems, servers and external addresses in scope, and whether the review is external only or includes an internal network review as well. A handful of public-facing systems costs less to cover than a full internal-and-external estate.

What determines how quickly results come back?

The size of what is in scope and how quickly access — network details, credentials for an internal look where agreed — is provided. External-only scans move faster than assessments that also cover internal systems requiring scheduled access.

Does it matter what our systems run on?

No. The approach adapts to whatever mix of cloud, on-premise servers, and network equipment you actually have. You do not need a uniform environment for this to work.

What do you need to supply before scanning begins?

A list of the domains, IP addresses and servers to include, written confirmation that you are authorised to have them tested, and one contact who can answer questions if something unexpected turns up during the scan.

Talk to us

Tell us what you need.

Send a short brief and one of our engineers will come back to you — usually the same day.

  • No obligation
  • We reply the same working day
  • Your details stay private

Your details are private and secure. Protected by reCAPTCHA.