Cybersecurity
Vulnerability assessment
A picture of what is exposed today, read by a specialist.
What this work consists of
We comb through your environment and hand back, in order of severity, what is vulnerable today. It is the right snapshot for anyone who has not tested yet: first you discover what exists and what is exposed, then you measure whether the defense holds against an attack. For those with mature controls who want that proof, the path is the pentest.
The scan itself is designed not to take anything down: no test here exploits the flaw or causes downtime. What changes between the options is who reads the results. The raw snapshot comes out as the tool generates it, in English, and works for teams that can prioritize on their own. With expert analysis, someone separates false positives from real risk and sets the order of attack, in Portuguese or English.
We need the scope of assets to scan and the agreed access to reach them. At the end, you receive the report in the chosen format and, when expert analysis is included, the remediation plan in true priority order.
How we conduct it, stage by stage
The stages and deliverables below describe the Vulnerability analysis modality. The other modalities appear when you request the proposal.
Planning and authorisation
We agree the scope in writing and set the windows, the emergency contacts and the formal authorisations. No test starts without that.
Execution
We run the test cycle within the authorized window and scope, starting with what usually breaks first. Every finding is recorded with the evidence and the step-by-step needed to reproduce it later.
Report
We consolidate the findings into a report where every item comes with severity, evidence and the path to fix it. We write to be read by the people who will act, not to fatten pages.
What is not included
- Exploiting the flaws found, which is what defines a pentest
- Manually confirming that each finding is actually exploitable, which is also pentest work
- Fixing what is flagged, which stays with your team or becomes a separate project
- Tests that take down the environment: the scan is designed not to cause downtime
- Translating or interpreting the report in the scan-only option, which comes out as the tool generates it, in English
- Tracking the remediation queue over time, which is vulnerability management
- Scanning assets you did not list or authorize: the reach is the agreed scope
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.