Cyber Key Security

Discover · Prioritise · Remediate · Retest

Vulnerability assessments

Findings ranked by what an attacker and an auditor would actually care about.

A vulnerability assessment is a structured review of systems you authorise us to examine. You get a ranked list, owners, and a retest option — not a 400-page export from a scanner.

Scanner output is not a programme

PCI DSS, SOC 2, and ISO 27001 all expect you to find and treat weaknesses on a cadence. Dumping CVSS 9.8s into a ticket pile without asset context or exploitability wastes the only engineers who can patch. We assess, we explain, and we stay for verification.

What you receive

Scope and discovery

Agreed ranges, cloud accounts, and applications. We discover what is live so the report is not limited to last year’s spreadsheet.

Authenticated and unauthenticated testing

Unauthenticated shows the internet’s view. Authenticated shows missed patches and misconfig behind login. We recommend both where it is safe and authorised.

Prioritisation

Exploitability, exposure, and business impact on top of CVSS. Internet-facing and data-bearing systems jump the queue.

Remediation owners and retest

Each accepted finding has an owner and a due date. Retest confirms closure — which is what PCI and ISO surveillance want to see.

How we align to industry practice

We use recognised references so your report language matches what auditors already know.

CVE / NVD and CVSS as input, not gospel

Identifiers and scores start the conversation. We overlay whether the service is reachable, whether a fix exists, and whether compensating controls already reduce risk.

OWASP for applications

When web or API scope is included, we structure application findings in language your developers can map to their backlog.

CIS and hardening baselines

Where configuration is the issue, we point to a baseline — not a vague “harden the server.”

Cadence for compliance

Quarterly or continuous programmes produce the evidence PCI authenticated scanning, SOC 2 monitoring, and ISO A.8 technical controls expect.

Engagement shape

  1. 1. Rules and windows

    Authorisation, contacts, production freeze dates, and what is out of bounds.

  2. 2. Assess

    Discovery, scanning, and manual validation of noisy or critical results so you do not chase ghosts.

  3. 3. Report

    Executive summary plus technical detail, ranked, with remediation guidance.

  4. 4. Close

    You patch; we retest the agreed set. Optional retainer for the next cycle.

What good looks like

  • A living inventory, not a one-off IP list
  • A board-readable summary and an engineer-readable annex
  • Tickets that match real risk, not scanner vanity metrics
  • Retest evidence you can file for PCI, SOC 2, or ISO

FAQ

Is this a penetration test?
No. A vulnerability assessment identifies and ranks weaknesses. A penetration test attempts to achieve agreed objectives using those weaknesses, under a tighter rules of engagement. Many clients run both on a yearly plan.
Will you scan production?
Only with written authorisation and a window. We discuss load, authenticated credentials, and freeze periods first.
Cloud and on-prem together?
Yes. Hybrid estates are the default. Scope is still explicit: accounts, subscriptions, VLANs, SaaS admin planes.
Do you guarantee zero criticals?
No honest assessor does. We guarantee a clear ranking, practical remediation, and a retest of what you claim to have fixed.

Talk to an expert today

+359 895 155 438
info@cyberks.com

Call now

Talk to an expert today

Findings ranked by what an attacker and an auditor would actually care about.

Call nowFree consultation