Service · Cybersecurity

Vulnerability scanning

Running a scanner is easy. In a few hours you can produce a report hundreds of pages long. The hard part is stopping that report from ending up in a drawer. Think of an eighty-room hotel in Antalya that commissioned a scan last year. The report lists three hundred issues, most of them rated medium, and because nobody knew where to begin, none were fixed. Since then a flaw that attackers are actively using has appeared in the remote access appliance in front of the property management system, and it sits in the report as just another line. We treat scanning as an ongoing process rather than an event. External addresses, the internal network, websites and cloud settings are scanned on a schedule, and every finding is judged in the context of your environment: not only by its score but by whether it is exposed and being exploited in the wild. Important findings become tickets with an owner and a deadline, and once fixed, a rescan confirms the result.

Monthly
internal and external scans, critical systems more often
Priority
driven by exploitability, not just CVSS score
One ticket per issue
with an owner and a due date
Rescan
as proof that the fix worked

What the work covers in practice

We concentrate on what an attacker would find interesting and spare you reports nobody will read.

Agree the scope with the engineer who will do the work

Internet-facing scan

Every public IP and domain, including firewall, VPN gateway, mail server, websites and remote access devices. Each exposed service and its version is checked regularly.

Internal scan

Servers, workstations, network gear, printers and NAS boxes on your LAN. Authenticated scanning shows missing patches and weak settings far more accurately than an anonymous sweep.

Website checks

Sites and online stores are checked for stale plugins, missing security headers, exposed admin pages and forgotten backup files.

Cloud posture

Risky settings in Microsoft 365, Azure or AWS: public storage buckets, admins without a second factor, over-generous app consents.

Triage

For each finding we ask whether it is reachable from the internet, whether a working exploit exists and how important the system is to the business. You get a short, ordered list rather than a phone book.

Follow-through

Findings are logged as tickets, assigned to the right person or supplier, chased when overdue and closed only after a confirming rescan.

How we approach the job, from first call to handover

The first round tends to surface years of accumulated problems. After that, the aim is to keep things clean.

01

Scope

A list of addresses, networks, sites and cloud tenants, plus permission and time windows agreed with your host and cloud provider.

02

Baseline and clean-up

A full first pass and assessment. Critical items are handled at once; the rest get a realistic timetable.

03

Routine

Monthly scans, with an extra targeted scan whenever a USOM notice or vendor advisory flags a critical flaw.

04

Reporting

A one-page monthly summary for management and a live findings list for the technical team. Over time, the open count should fall.

What matters is how quickly findings get closed, not how many are found. A report with three hundred entries protects nobody. Closing one internet-facing, actively exploited flaw within a week beats perfecting hundreds of low-risk settings, so we measure progress by time to fix rather than by volume.

Frequently asked questions

Normally not. Scans run outside working hours, and fragile equipment such as older printers, production machines or medical devices is scanned with gentler settings. We identify those devices with you before the first run.

That is agreed at the start. On systems we manage, remediation is ours. For systems looked after by a supplier, we pass on the finding with context and a recommendation, follow it up and verify the fix. Any extra work is charged at €55 per hour plus VAT, estimated beforehand.

Scanning is automated, broad and repeated, searching for known weaknesses across everything in scope. A penetration test is a time-boxed exercise in which a specialist attacks a chosen target the way a real adversary would. One is a routine check-up, the other a detailed examination; neither replaces the other.

Yes. We follow USOM announcements and the security bulletins of major vendors. When a critical flaw affects a product in your scope, we check the relevant systems straight away instead of waiting for the next monthly run.

Find the holes before someone else does

Tell us which systems face the internet and roughly how many devices you have. We will suggest a scan scope and frequency.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.