Continuous vulnerability scanning

Identify vulnerabilities
before attacker

Vulnerability management is the continuous search for gaps in your infrastructure: not a one-off audit that becomes outdated within a week. We scan, prioritise by risk, recommend remediation and verify that the gap has truly been sealed.

secureon@scan:~$ vuln-scan --target firma.cz
[*] Hosts: 38 Services: 211
[!] CRITICAL CVE-2024-3094openssh
[!] HIGH     TLS 1.0 enabled  :443
[!] HIGH     Default credentialsrouter admin
[*] Findings: 3 crit · 11 high · 24 med
[✓] Report CZ → PDF · inspection rescheduled
~70
new CVE vulnerabilities daily
60 %
infiltrations target a known, unrepaired hole
§ 21
Vulnerability management is a requirement of NIS2.
CVSS
prioritisation based on actual risk

Complete overview
on your attack surface

An attacker sees your company from the outside as a list of open doors. We will create this map before they do, and tell you which doors to close first.

🌐

External surface

Scanning everything visible from the internet, servers, VPNs, email gateways, exposed services and ports. We identify forgotten systems, expired certificates and services that no one remembers.

External surveyAttack surfaceTLS/SSL
🖥️

Internal infrastructure

Authenticated scan of servers, workstations and network elements from within. It reveals missing patches, weak configurations and vulnerable software before ransomware exploits a single compromised workstation.

AuthenticatedPatch levelConfiguration audit
🔎

Web applications

Scanning websites and applications for known vulnerabilities, incorrect headers, data exposure, and outdated components. A supplement to in-depth penetration test where routine inspection is sufficient.

Web appHeadersCVE
📊

Prioritisation by risk

A scanner will spit out hundreds of findings, without context they are useless. We prioritise them by CVSS score, accessibility and impact on your business, so you know what to fix today and what can wait.

CVSSRisk-based
📄

Clear report

Report in Czech for management and specific steps for IT. No English scanner output: a deliverable that will stand up to both a NIS2 auditor and the managing director.

CZ reportNIS2-readyPDF
🔁

Rectification and retest

A finding without repair is just paper. We will recommend specific remedial steps and, after the repair, re-verify that the vulnerability has truly been eliminated: not merely marked as "resolved".

RemediationRetest

From a one-off inspection
after continuous supervision

Start with what your company actually needs. Most clients begin with a one-off inspection and, based on the results, switch to an ongoing regime.

Initial step

One-off inspection

Snapshot of your security status as of today.

  • Complete scan of the external surface
  • Report with risk-based prioritisation
  • Recommendations for remediation
  • Basis for deciding what to do next

Ideal first contact: know exactly what you're dealing with, no obligation.

A higher standard

SOC / MDR supervision

Real-time threat detection and response.

  • Continuous monitoring (24/7)
  • Incident detection and response (MDR)
  • Connection to incident response
  • Event correlation (SIEM)

We rely on our own infrastructure and continuous operation, as an internet provider we have our own data centre and technicians on call 24/7. We tailor supervision to your environment; get in touch and we will discuss the specific scope.

Four steps to clarity
about your risks

01

Scope

We will agree on what to scan, external surface, internal network, websites. No surprises and no operational downtime.

02

Scan

We initiate scanning using established tools. We identify known vulnerabilities, weak configurations and exposures.

03

Report

You will receive a clear report in Czech with priorities and specific steps for remediation.

04

Retest

After repair, we will recheck the condition and set up any ongoing monitoring to prevent new leaks from appearing.

Vulnerability management
is also required by law

Vulnerability management is not an extra. It is one of the security measures required by NIS2 (Act No. 264/2025 Coll.) and ISO 27001 standard. Regular scanning also provides easily verifiable proof that you are actively managing risks.

Verifiable record of vulnerabilities and their remediation
Basis for risk analysis in accordance with NIS2
Early detection of leaks before the mandatory 72-hour incident reporting deadline.

Do you not know if NIS2 applies to you?

Start with a free online test, in 10 minutes you will find out whether your company falls under the new cybersecurity law and what it means for you.

Free NIS2 test →

What you ask most often

What is the difference between vulnerability scanning and penetration testing?

Vulnerability scanning is an automated and repeated process that continuously monitors known gaps across the entire infrastructure. A penetration test is an in-depth, one-off simulation of a real attack by a human who also looks for error chaining and logical vulnerabilities. Vulnerability management is continuous, while a pentest is point-in-time, ideally they complement each other.

Does the Cybersecurity Act (NIS2) require vulnerability management?

Yes. Vulnerability management and measures for their timely detection and remediation are among the security measures required by NIS2 and ISO 27001. Regular scanning and recording of vulnerabilities serve as one of the verifiable proofs that a company is actively managing risks.

How often should scanning be performed?

For external surfaces, we recommend at least a monthly scan; for critical systems, more frequently or after every change. New vulnerabilities emerge daily, so a one-off scan becomes outdated within weeks. This is why continuous monitoring makes sense, not just an annual audit.

Will scanning disrupt business operations?

The standard scan is designed to be non-invasive and runs in the background. More sensitive tests are scheduled in advance for a suitable time. The aim is to find vulnerabilities, not to take your systems down.

Find out where your leaks are:
before someone else finds them

We will discuss your company's needs without obligation and propose a tailored scope. No pressure, no standardised offers.