A Vulnerability Assessment systematically scans and evaluates your IT environment to identify security weaknesses across systems, applications, networks, and internet-facing assets.
GRX Technologies helps organisations see where they stand today and which areas need attention first.
Unlike a penetration test, GRX Technologies does not actively exploit identified vulnerabilities or attempt to gain unauthorised access to targeted systems. Instead, identified findings are manually reviewed and validated to confirm their accuracy and reduce false-positive results.
Vulnerability scanning and assessment activities will only commence after GRX Technologies has received explicit, signed authorisation from the client.
The assessment is limited to the systems, domains, IP addresses, applications, and other assets specifically agreed within the scope of the engagement.
Assessment of internet-facing infrastructure, including public IP addresses, domains, open ports, exposed services, and externally accessible systems. This helps identify security weaknesses that may be visible to potential external threats.
Assessment of authorised internal systems and infrastructure, including servers, workstations, network devices, and other in-scope assets, identifying weaknesses within the internal environment.
Following remediation activities, GRX Technologies can verify whether previously identified vulnerabilities have been appropriately addressed and whether the associated security risks have been reduced.
A follow-up scan is conducted after vulnerabilities have been fixed or mitigated. Results are compared against the original assessment to confirm which findings have been resolved and identify any remaining issues.
We generally assess from an external, black-box perspective, simulating the visibility available to a potential malicious outsider without actively exploiting identified vulnerabilities.
Gathering relevant information about the organisation's externally accessible IT infrastructure.
Identifying accessible systems, services, ports, technologies, and potential vulnerabilities within the authorised scope.
Using appropriate security assessment tools and techniques to identify potential vulnerabilities and configuration weaknesses.
Reviewing identified vulnerabilities to confirm their validity and reduce false-positive findings.
Evaluating confirmed findings based on their potential impact and providing appropriate remediation or mitigation recommendations.
Documenting the findings and providing management and technical recommendations to improve the organisation's security posture.
Upon completion, GRX Technologies provides a comprehensive report containing:
A management-level overview of significant vulnerabilities, associated business risks, and recommended actions.
Detailed findings, supporting technical information, risk considerations, affected assets, and recommended remediation or mitigation measures.
Where a re-scan is conducted, a summary of vulnerabilities that have been resolved, remain outstanding, or require further action.
A presentation covering key findings, significant vulnerabilities, business risks, and recommended improvements.
Every finding is verified. The assessment gives an overall view of your security posture and helps prioritise areas requiring attention. All vulnerabilities identified through automated scanning are manually verified by GRX Technologies before being included as confirmed findings.
Tell us about your environment and we'll scope an assessment that fits.