R7G Services
Vulnerability Assessment
A structured technical scan to find exploitable weaknesses across your network, systems, cloud environment, and web applications — ranked by severity and business impact, with a clear remediation plan.
What we find
The vulnerabilities that put small businesses at risk
Most small business compromises are not the result of nation-state hacking. They exploit basic unpatched systems, misconfigured services, and weak credentials — things a vulnerability assessment is specifically designed to surface.
Unpatched systems and software
Outdated OS versions, missing security patches, and end-of-life software that attackers actively target.
Misconfigured services
Default credentials, open admin ports, unnecessary services running on internet-facing systems.
Web application vulnerabilities
SQL injection, XSS, authentication flaws, and exposed admin panels on customer-facing applications.
Weak network configuration
Improper firewall rules, exposed internal services, and lack of network segmentation.
Cloud misconfigurations
Publicly accessible storage, overly permissive IAM roles, and unencrypted data at rest.
Credential and identity exposure
Accounts with no MFA, shared credentials, and unused privileged accounts that widen your attack surface.
Scan options
Four assessment types — choose what fits your situation
External network scan
We scan all your internet-facing IP addresses and domains for open ports, exposed services, and known CVEs.
Internal network scan
From inside your network (on-site or via lightweight agent), we scan for lateral movement risk and internal misconfigurations.
Web application scan
Automated and manual testing of your customer-facing and internal web apps for OWASP Top 10 vulnerabilities.
Cloud configuration scan
Review of your AWS, Azure, or Google Cloud environment for misconfigurations using CIS benchmark checks.
Deliverables
What you receive at the end of every assessment
Executive summary — a one-page plain-language risk overview for leadership
Technical findings report — every vulnerability with CVE reference, CVSS score, and evidence
Risk-ranked remediation plan — highest impact fixes listed first, with step-by-step guidance
Trend comparison — if you have had a previous assessment, we show you what improved and what did not
Remediation verification — optional re-scan to confirm that fixes were applied correctly
How it works
Four steps from scoping to report
Scoping call
We agree on the IP ranges, domains, and applications to include, and confirm any scanning restrictions.
Credentialed scan
We run both authenticated and unauthenticated scans to find the full range of vulnerabilities.
Manual review
We triage every finding to remove false positives and add business context before writing the report.
Report delivery
You receive the full report and we walk through the findings on a debrief call.
FAQ
Frequently asked questions
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment identifies and ranks weaknesses without actively exploiting them. A penetration test goes further by attempting to exploit vulnerabilities to measure real-world impact. Assessments are a good first step; pen tests are appropriate for organizations that want to validate their defenses.
How long does the process take?
A typical scoped assessment — including scanning, manual review, and report preparation — takes 3–5 business days. Larger or more complex environments may take longer.
Do I need to take systems offline for the scan?
No. Scans run against live systems. We coordinate timing with you to minimize any potential disruption to production workloads.
What happens after we receive the report?
We deliver a risk-ranked findings report and schedule a debrief call to walk through each finding, explain the business impact, and discuss remediation priorities.
Can you re-test after we fix the issues?
Yes. Remediation verification scanning is available as a follow-on engagement to confirm that identified vulnerabilities have been addressed.
Find your vulnerabilities before attackers do
Request a scoped vulnerability assessment and receive a ranked remediation plan within one week.