External · Internal · Web · Cloud

R7G Services

Vulnerability Assessment

A structured technical scan to find exploitable weaknesses across your network, systems, cloud environment, and web applications — ranked by severity and business impact, with a clear remediation plan.

What we find

The vulnerabilities that put small businesses at risk

Most small business compromises are not the result of nation-state hacking. They exploit basic unpatched systems, misconfigured services, and weak credentials — things a vulnerability assessment is specifically designed to surface.

Unpatched systems and software

Outdated OS versions, missing security patches, and end-of-life software that attackers actively target.

Misconfigured services

Default credentials, open admin ports, unnecessary services running on internet-facing systems.

Web application vulnerabilities

SQL injection, XSS, authentication flaws, and exposed admin panels on customer-facing applications.

Weak network configuration

Improper firewall rules, exposed internal services, and lack of network segmentation.

Cloud misconfigurations

Publicly accessible storage, overly permissive IAM roles, and unencrypted data at rest.

Credential and identity exposure

Accounts with no MFA, shared credentials, and unused privileged accounts that widen your attack surface.

Scan options

Four assessment types — choose what fits your situation

External network scan

We scan all your internet-facing IP addresses and domains for open ports, exposed services, and known CVEs.

Internal network scan

From inside your network (on-site or via lightweight agent), we scan for lateral movement risk and internal misconfigurations.

Web application scan

Automated and manual testing of your customer-facing and internal web apps for OWASP Top 10 vulnerabilities.

Cloud configuration scan

Review of your AWS, Azure, or Google Cloud environment for misconfigurations using CIS benchmark checks.

Deliverables

What you receive at the end of every assessment

Executive summary — a one-page plain-language risk overview for leadership

Technical findings report — every vulnerability with CVE reference, CVSS score, and evidence

Risk-ranked remediation plan — highest impact fixes listed first, with step-by-step guidance

Trend comparison — if you have had a previous assessment, we show you what improved and what did not

Remediation verification — optional re-scan to confirm that fixes were applied correctly

How it works

Four steps from scoping to report

1

Scoping call

We agree on the IP ranges, domains, and applications to include, and confirm any scanning restrictions.

2

Credentialed scan

We run both authenticated and unauthenticated scans to find the full range of vulnerabilities.

3

Manual review

We triage every finding to remove false positives and add business context before writing the report.

4

Report delivery

You receive the full report and we walk through the findings on a debrief call.

FAQ

Frequently asked questions

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and ranks weaknesses without actively exploiting them. A penetration test goes further by attempting to exploit vulnerabilities to measure real-world impact. Assessments are a good first step; pen tests are appropriate for organizations that want to validate their defenses.

How long does the process take?

A typical scoped assessment — including scanning, manual review, and report preparation — takes 3–5 business days. Larger or more complex environments may take longer.

Do I need to take systems offline for the scan?

No. Scans run against live systems. We coordinate timing with you to minimize any potential disruption to production workloads.

What happens after we receive the report?

We deliver a risk-ranked findings report and schedule a debrief call to walk through each finding, explain the business impact, and discuss remediation priorities.

Can you re-test after we fix the issues?

Yes. Remediation verification scanning is available as a follow-on engagement to confirm that identified vulnerabilities have been addressed.

Find your vulnerabilities before attackers do

Request a scoped vulnerability assessment and receive a ranked remediation plan within one week.